Platform & Security
A trade-only API key is an exchange API key whose permissions allow reading balances and placing, modifying and cancelling orders, but not withdrawing funds or changing account settings; it is the standard way to let a third-party platform trade your account without ever being able to move your money.
An API key is a password for machines. A key created with withdrawal enabled can empty the account from anywhere in the world, which is exactly what has happened in several well-known bot and copier breaches. A trade-only key limits the damage of any compromise to what a trade can do: at worst, someone can open bad positions, which is serious but bounded and visible, rather than transfer the balance out. Most exchanges also let you bind the key to a list of IP addresses, which adds a second, independent barrier.
AlgoVesta only asks for trade-only keys and explains, per exchange, which permission boxes to tick and which to leave off. Keys are stored encrypted at rest with AES-256, and the dashboard shows the fixed IP addresses of the execution servers so you can whitelist them on the exchange; on exchanges that support it, this makes the key useless from any other machine even if it leaked. The platform is non-custodial: your funds stay on your exchange, AlgoVesta never requests withdrawal rights, and you can revoke a key on the exchange at any time to cut the connection immediately. Enabling a key for live trading requires a fresh identity check, and sensitive account actions are protected by 2FA. The list of the 16 supported exchanges and their key setup guides is on the Supported exchanges page; security details are on the Security page.
On Bybit, the user creates a key with "Read-Write" for Contract and Spot trading, leaves "Withdrawal" unticked, restricts the key to the AlgoVesta execution IPs, and pastes the key and secret into the dashboard. The platform verifies the key by reading the balance, confirms the permission scope, and marks the account ready. If the trader later deletes the key on Bybit, every order attempt from AlgoVesta fails immediately and the bot is shown as disconnected.