
Connect Your Exchange Safely: The Bring-Your-Own-Key Guide
How to create exchange API keys for CoTrading with withdrawals disabled, testnet first.
New to CoTrading? Read Get Started in 5 Minutes first for the basics.
CoTrading is bring-your-own-key (BYO). You connect your own exchange API credentials, and they stay on your machine — never uploaded, never logged. This guide covers how to create those keys safely.
Principle 1: Testnet before live
Always start on testnet. Testnet keys and live keys are stored in separate slots inside CoTrading, so they can never be mixed up. Practice the full workflow — chart analysis, plan review, approval — with play money until it feels routine.
Principle 2: Disable withdrawals on the API key
This is the single most important safety step. When you create an exchange API key, grant only the permissions CoTrading needs:
- Read account and market data
- Place and cancel orders (spot and/or derivatives, as you use)
And explicitly do not grant:
- Withdrawal permission
CoTrading enforces this: before you can switch a key to live trading, it verifies that withdrawals are disabled on that key. If the exchange reports the key can withdraw, the live switch is blocked. A key that cannot withdraw means that even in a worst case, funds cannot leave your account through CoTrading.
Never share your secret
Treat the API secret like a password. CoTrading stores it locally and never transmits it. If you ever paste a key somewhere online, revoke it immediately.
Principle 3: Bind to IP where possible
Many exchanges let you restrict an API key to specific IP addresses. If you use CoTrading from a stable network, adding an IP allowlist is a cheap extra layer: even a leaked key is useless from an unapproved address.
Step by step
- Log in to your exchange and open the API management page.
- Create a new API key labeled clearly, e.g.
cotrading-testnet. - Enable read and trade permissions; leave withdrawals off.
- Optionally add an IP allowlist.
- Copy the key and secret into CoTrading's testnet slot.
- Verify data loads and place a testnet order through an approved plan.
- When ready for live, repeat with a live key (withdrawals off) in the live slot and pass the confirmation gates.
Why the AI never touches your keys
The AI process in CoTrading has no order-placing permission and no access to your raw credentials for execution. It proposes plans; the app — under your approval and the deterministic risk layer — handles order placement. Your keys sit behind that boundary.
Trading involves risk. Keeping withdrawals disabled protects your funds but does not protect against market losses. CoTrading is a decision-support tool, not investment advice.
More Posts

Reading an AI Trade Plan Card
What every field on the plan card means, and how to approve with discipline.


What is CoTrading
A local-first AI desktop workbench where AI proposes and you decide every order.


From Testnet to Live: A Safe Switch Checklist
The confirmation gates and checks to clear before you trade real money.

Newsletter
Join the community
Subscribe to our newsletter for the latest news and updates