Platform & Security
API permission scope is the set of actions an exchange API key is allowed to perform, chosen when the key is created: read balances, trade spot, trade futures, transfer between wallets, withdraw; a key created with only the permissions a task needs limits what anyone holding that key can do.
An API key is a credential that works from anywhere, so its scope is the damage ceiling if it leaks or if the platform holding it is compromised. A withdrawal-enabled key can empty the account; a transfer-enabled key can move funds into a wallet the platform does not watch; a trade-only key can at worst open bad positions, which is bounded and visible. Scope also causes ordinary failures: a key with spot permission only will have every futures order rejected, which looks like a platform bug until the permissions are checked.
AlgoVesta asks for trade-only keys and never for withdrawal or transfer rights, and the exchange setup guides show, per exchange, which boxes to tick. When a key is added, the platform verifies it by reading the balance and, where the exchange reports it, checks that the required trading permission for the bot's market is present, so a spot-only key is flagged before a futures bot is started. Keys are stored encrypted at rest with AES-256, can be restricted on the exchange to the platform's fixed execution IP addresses, and can be revoked by you on the exchange at any time. Enabling a key for live trading requires a fresh identity check, and sensitive actions in the dashboard are protected by two-factor authentication. See trade-only API key, Supported exchanges and the security page.
A user creates a Binance key with "Enable Reading" and "Enable Spot & Margin Trading" but not "Enable Futures", then starts a futures bot. The preflight check reports that the key lacks futures permission and the bot is not started; the user edits the key on Binance, adds futures trading, keeps withdrawals off, and the bot starts on the next attempt.