How to Connect a Binance API Key Safely
A trading bot needs limited API access to read market/account information and place Spot orders. It does not need permission to withdraw funds.
Create a dedicated key
Create a separate system-generated API key only for TradePilot. Do not reuse a key from another app, share it in chat, email it, or store it in screenshots.
Enable only what is required
Enable reading and Spot trading. Leave withdrawals, margin borrowing, futures and transfer permissions disabled unless a documented feature specifically requires them. TradePilot currently does not.
Restrict the IP address
After your worker is deployed, whitelist the public IPv4 address of that VPS. Requests from other addresses should then be rejected by Binance.
Start with strict limits
Set a small capital ceiling, a daily-loss limit and Moderate risk first. Verify balances and order behavior before increasing capital.
Rotate compromised credentials
If a key appears in a message, screenshot, public repository or unknown device, delete it in Binance immediately and create a new one.
Ready to set your boundaries?
Create an account, choose a plan and connect a restricted Binance Spot key.