How do I manage my API keys

How do I manage my API keys

Note: You can have a maximum of 50 API keys. This includes keys that are stored as well as keys that are generated in our platform.

Our platform supports the following key types for the Trading API and Custody API.

Key Type

Trading API

Custody API

Key Type

Trading API

Custody API

FIX

HMAC

ECDSA

Note: If you are generating your own API keys, please note that our platform supports ECDSA key. See the format of these key types here.

Adding API Keys

For Trading API keys, you can add HMAC and ECDSA keys.

Add an HMAC Trading Key

If you are a standard user:

  1. Go to Settings in the left-hand navigation.

  2. Navigate to API Keys.

  3. Choose Add API Key and select Trading Key.

If you are an authorised representative of the institution:

  1. Go to Settings in the left-hand navigation.

  2. Navigate to Account Management > API Keys & Users.

  3. Click Details on the user you are generating the API key on behalf of.

  4. Choose Add API Key and select Trading Key.

Then, for both paths:

  1. Select HMAC as the key type and set its permissions. By default, the key will have the Read Info permission.

  2. Optionally, set the range of IP addresses from which the API key is allowed to connect. The IP whitelist ranges can be edited after the key has been created.

  3. Choose Continue.

  4. Enter the key name and the trading accounts it is allowed to access (Institutional customers only), then choose Generate.

  5. Complete the process using your two-factor authenticator (passkey or TOTP).

  6. Copy your API Public Key and API Private Key.


Add an ECDSA Trading Key

If you are a standard user:

  1. Go to Settings in the left-hand navigation.

  2. Navigate to API Keys.

  3. Choose Add API Key and select Trading Key.

If you are an authorised representative of the institution:

  1. Go to Settings in the left-hand navigation.

  2. Navigate to Account Management > API Keys & Users.

  3. Click Details on the user you are generating the API key on behalf of.

  4. Choose Add API Key and select Trading Key.

Then, for both paths:

  1. Select ECDSA as the key type and set its permissions. By default, the key will have the Read Info permission.

  2. Optionally, set the range of IP addresses from which the API key is allowed to connect. The IP whitelist ranges can be edited after the key has been created.

  3. Choose Continue.

  4. Enter the key name and the trading accounts it is allowed to access (Institutional customers only). You can choose to Generate an API key or enter your own.

  5. Choose Continue.

  6. Complete the process using your two-factor authenticator (passkey or TOTP).

  7. Copy your API Private Key and UUID.

     

For Custody API keys, you can add ECDSA keys.

Add an ECDSA Custody Key

If you are a standard user:

  1. Go to Settings in the left-hand navigation.

  2. Navigate to API Keys.

  3. Choose Add API Key and select Custody Key.

If you are an authorised representative of the institution:

  1. Go to Settings in the left-hand navigation.

  2. Navigate to Account Management > API Keys & Users.

  3. Click Details on the user you are generating the API key on behalf of.

  4. Choose Add API Key and select Custody Key.

Then, for both paths:

  1. Select permissions for the new key. By default, the key will have the Read Info and IP Address Whitelist permissions.

  2. In the Add Custody API Key window, enter your IP addresses (Start Range and End Range). To add multiple IP ranges, choose Add IP Range. The IP whitelist ranges may be edited after the key has been created.

  3. Choose Continue.

  4. Enter the key name and the trading accounts it is allowed to access (Institutional customers only). You can choose to Generate an API key or enter your own.

  5. Complete the process using your two-factor authenticator (passkey or TOTP).

  6. Copy your API Private Key and UUID.

The API key is now saved and will appear in the API Keys listing under Settings.

To reset an API key, visit our API documentation.


Editing an API Key

Standard users:

  1. Go to Settings in the left-hand navigation.

  2. Select API Keys.

  3. Click Edit next to the key you want to update.

Authorised institutional representatives:

  1. Go to Settings in the left-hand navigation.

  2. Navigate to Account Management > API Keys & Users.

  3. Click Details on the relevant user.

  4. Click Edit next to the key you want to update.


From here, both paths continue the same way. You can update:

  • The API key name

  • Which trading accounts it can access (institutional accounts only)

  • The permissions assigned to it

  • The IP allowlist:

    • No existing range — select IP Address Whitelist and enter a Start and End Range

    • Add a range — click Add IP Range and enter a Start and End Range

    • Remove a range — click the ✕ next to the range you want to delete

When done, click Continue.


Using your own API key

You can use your own API keys in our trading system if they follow the format listed below.

For example purposes only:

Key type

 

Key format

Example

Key type

 

Key format

Example

ECDSA

Curve

ECDSA R1 (prime256v1 or secp256r1 or P-256)

-----BEGIN PUBLIC KEY-----
MFkwEwYHKoZIzj0CAQYIKoZIzj0DAQcDQgAEYtPSVNz5ZsfxfaYdpRf3e2iv9iAc
goiGiFUG0au5Mvn/MiaSTu2Ji5TyO/+BGYEcxQZ5aUb9QNz+yHTB1/fAxQ==
-----END PUBLIC KEY-----

Key Format

X.509 SubjectPublicKeyInfo format, PEM encoded

Digital assets and related products are high risk. Consult your professional advisor and trade responsibly. Access to our services is prohibited for residents of jurisdictions where trading in virtual assets is restricted or banned, including residents of Mainland China. Visit bullish.com/legal for important information and risk warnings.