Docs / Account / API key security

Connecting exchange API keys safely

Account & API Keys · 5 min read

Live data and automated execution both depend on an API key from your own exchange account. Here's how to create one correctly, and how AEON handles it once connected.

AEON account settings showing connected exchange API key status
Exchange key status in Account settings — set, source, and connection state

Trade-only vs withdrawal permissions

When generating an API key on your exchange, you'll be asked which permissions to grant. AEON only ever needs two:

Enable

  • Read / market data
  • Spot & futures trading

Never enable

  • Withdrawals
  • Internal transfers, if offered separately

Withdrawal permission is never required for AEON to function — not for signal viewing, not for Auto-Trade. If an exchange's key-creation form asks, leave it unchecked. This is the single most important step: with trade-only permissions, a compromised key can place orders on your account but cannot move funds out of it.

Creating and connecting a key

  1. Generate the key on your exchange — from your exchange's API management page, not from AEON.
  2. Set permissions to trade-only as described above, and leave withdrawal disabled.
  3. IP-restrict the key if your exchange supports it — an extra layer some exchanges offer to limit which servers can use the key at all.
  4. Paste the key into Account → Exchange Keys in the AEON terminal. It's encrypted immediately on save.
  5. Confirm the status indicator shows the key as connected before enabling live data or Auto-Trade for that exchange.

How AEON stores your key

Once connected, keys are encrypted with AES-256-GCM at rest and are never exposed back to the client — the browser never receives the raw key again after you save it, only a masked status indicator showing whether a key is set and its source.

You are responsible for the permissions you grant a key. AEON is not liable for losses resulting from a key issued with broader permissions than recommended, or from compromise of your exchange account credentials outside AEON's systems. See our Terms and Privacy & Security Policy for full detail.

Billing, trial & cancellation

New accounts get a 7-day free trial with full feature access. A card is required to start the trial (a small verification hold, refunded immediately), but you're not charged the plan price until day 7. You can cancel any time before then to avoid being charged, or cancel a paid subscription at any time — cancellation takes effect at the end of the current billing period. Paid periods are non-refundable. Full detail is in the billing section of our Terms.