TL;DR — Grant read balances and spot trade only. Never grant withdraw. Use IP allow-listing where available.

Required permissions

Scope Setting
Spot trade ✅ Enable
Margin / futures / options ❌ Do not enable

IP allow-listing

Where supported (e.g. Binance, Kraken), restrict your API key to LunaVector's static outbound IPs. Find the current list in Settings → Security → Outbound IPs.

Rotating keys

Losing access

If you lose access to your exchange account, recover it directly with the exchange. LunaVector cannot recover or reset exchange credentials.