2 min read

API key permissions: what Pilotbot needs and what it cannot do

The exact list of exchange API key permissions used by Pilotbot, why it can never withdraw your money, and how your keys are protected.

P

Pilotbot Team

Author

On this page

An exchange API key is not a master password, but a set of restricted permissions that you yourself select when creating it. The exchange verifies these permissions on its own servers, so no application can do more than you have allowed. This article explains in detail exactly what Pilotbot needs and what it will never be able to do.

What Pilotbot needs

To read the market and manage your P2P ads, Pilotbot uses:

  • Read / View access — to see account data, ad prices, market data, and order status.
  • Trade / Ad management access — to update and pause your ads. On Binance, this means enabling Spot & Margin Trading (and Futures); on Bybit — Spot, Contracts, and Block Trade / P2P (Wallet access is not required).

This is the exhaustive list. For detailed steps, see the articles on Binance and Bybit.

What Pilotbot can never do

  • It cannot withdraw funds. Withdrawal is a separate permission that you never enable. Without it, no program, including Pilotbot, can withdraw money from your account.
  • It cannot change your account security settings (password, 2FA, email).
  • It cannot access anything that is not permitted by the key. The exchange blocks such attempts at its server level.

Your money remains in your exchange account at all times. The key only allows recalculating ad prices and reading data.

Additional protection: IP restriction

When creating a key, restrict it by setting trusted IPs only and entering the IP addresses provided by Pilotbot. After this, the key will work only from Pilotbot servers — even if the text of the key is leaked, it will be impossible to use it from anywhere else.

How your keys are stored

Pilotbot stores your API keys in an encrypted form (AES-256). They are used only by the pricing engine to communicate with the exchange — they are never displayed in the interface and are never shared with anyone.

Related articles

    API key permissions: what Pilotbot needs and what it cannot do