Atlas LP
  1. Home
  2. Blog
  3. How to Set Up and Validate Exchange API Keys for Secure Market Making

Exchange API

How to Set Up and Validate Exchange API Keys for Secure Market Making

Learn the essential steps and best practices for securely configuring and validating exchange API keys for spot market making bots using Atlas LP.

Published

Introduction

API keys are the gateway to automated trading on centralized crypto exchanges. For teams deploying spot market making bots, securely setting up and validating these keys is essential—not just for operational efficiency, but for protecting exchange accounts and ensuring compliance with exchange policies. This guide walks through the steps and considerations for configuring API keys with Atlas LP, a multi-tenant spot market making bot platform, and highlights best practices for secure and reliable API integration.

Why API Key Security Matters in Market Making

Market making bots require ongoing access to exchange accounts to place, manage, and cancel limit orders. API keys provide this access, but if misconfigured or exposed, they can lead to unauthorized trades, data leaks, or even asset loss. Proper API key management is foundational for:

  • Account security: Preventing unauthorized access or malicious actions.
  • Operational reliability: Ensuring the bot can continuously monitor and quote in the market.
  • Regulatory compliance: Avoiding prohibited activities like wash trading or volume manipulation.

Step 1: Create Exchange API Keys with the Right Permissions

When creating API keys on your chosen exchange, always follow these guidelines:

  • Enable only necessary permissions:
    • Read permission (to fetch balances, open orders, trades, and market data)
    • Spot trading permission (to place and cancel limit orders)
  • Never enable withdrawal permissions: Atlas LP never asks for or uses withdrawal access. This reduces risk if the key is ever compromised.
  • Restrict by IP if possible: Some exchanges allow you to whitelist IP addresses. This adds another layer of protection, though Atlas LP is multi-tenant and may require flexible IP settings depending on your deployment.
PermissionRequired?Purpose
ReadYesFetch balances, orders, trades, market
Spot TradingYesPlace/cancel limit orders
WithdrawalsNoNot required or recommended

Step 2: Securely Store and Manage API Keys

Atlas LP is designed with security in mind. When you add API keys to Atlas LP:

  • Encryption: API keys and secrets are encrypted with AES-256-GCM before storage.
  • Access control: Secrets are only decrypted by the worker that communicates with the exchange. Saved secrets are never displayed again in the interface.
  • User control: Users can register multiple exchange accounts and create a separate bot per symbol, keeping operations segmented.

Tip: Always keep a secure backup of your API keys in a password manager or other secure storage, as you won’t be able to retrieve them from Atlas LP after saving.

Step 3: Validate API Key Functionality Before Trading

Atlas LP performs detailed API verification before allowing a bot to start. This includes:

  • Checking the ticker and order book for the selected symbol
  • Verifying symbol rules (such as minimum order size and notional)
  • Fetching balances, open orders, and recent trades
  • Optionally, placing a test limit order far from the market price and immediately canceling it to confirm trading permission

If the exchange rejects the credentials at any step, Atlas LP will stop the bot and display an error status, preventing accidental or unauthorized trading.

Step 4: Configure and Validate Bot Settings

Before a market making bot can be started, Atlas LP validates all user-defined settings:

  • Spread band: Minimum and maximum spread in basis points (at least 40 bps wide)
  • Order levels: Number of bid and ask levels, with customizable spacing (from 0.1 bps)
  • Order sizes: Randomized between user-defined minimum and maximum, always meeting exchange minimums
  • Tick interval: How frequently the bot updates its quotes (from 0.5 seconds, default 3 seconds)

Settings that do not meet exchange or platform requirements are rejected, reducing the risk of order errors or rejections during live operation.

Step 5: Monitor and Maintain API Key Health

Atlas LP provides tools to help teams monitor their API connections and trading activity:

  • Console dashboard: Displays open orders, recent fills (including fees), balances, and bot events in real time
  • Daily snapshots: Records account asset value for tracking and analysis
  • Telegram alerts: Notifies users if a running bot has had no fills for a user-defined period, helping detect connectivity or market issues
  • Manual controls: Users can cancel individual or all open orders directly from the bot page, and stopping a bot immediately halts new order placement

Best Practices for Ongoing API Key Security

  • Rotate API keys periodically: If your exchange allows, update keys regularly and remove unused ones
  • Audit permissions: Double-check that only the required permissions are enabled
  • Monitor exchange account activity: Use exchange tools to review API access logs and spot suspicious activity
  • Educate your team: Make sure everyone understands the importance of API key security and the risks of sharing keys

What to Avoid: Prohibited Activities

Genuine market making means placing resting limit orders that any participant can trade against. Activities such as wash trading, self-trading, or volume manipulation are strictly prohibited and can result in exchange penalties or bans. Atlas LP is designed for compliant, transparent liquidity provision.

Supported Exchanges

Atlas LP currently supports spot market making on the following centralized exchanges:

  • Binance
  • DigiFinex
  • LBank
  • BingX
  • XT.com
  • Biconomy
  • Toobit
  • CoinW
  • P2B
  • Azbit
  • Dex-Trade

For a complete list and details, see [/supported-exchanges].

Conclusion

Setting up and validating exchange API keys is a critical foundation for secure, reliable spot market making. By following best practices and leveraging Atlas LP’s built-in security and validation features, teams can minimize risk and focus on providing genuine liquidity. Remember, Atlas LP does not guarantee returns, prices, trading volume, or listings.

Crypto trading involves risk. Atlas LP is software for placing and managing limit orders; it does not guarantee returns, prices, volume or listings. Follow the rules of each exchange and applicable law.

← Back to blog

Frequently asked questions

What permissions should my exchange API keys have for Atlas LP?

API keys should have read and spot trading permissions only. Withdrawal permissions are not required and should not be enabled for security reasons.

How does Atlas LP keep my API keys secure?

Atlas LP encrypts API keys and secrets with AES-256-GCM before storage. Secrets are only decrypted by the worker that communicates with the exchange and are never displayed again.

How does Atlas LP validate my API keys?

Atlas LP checks the ticker, order book, symbol rules, balances, open orders, and trades. It can also place and cancel a test limit order to verify trading permissions. If credentials are rejected, the bot stops with an error.

Can I use the same API key for multiple bots or exchanges?

You can register multiple exchange accounts in Atlas LP and create a separate bot per symbol. For best security and operational clarity, use unique API keys for each account.

Does Atlas LP support futures or margin trading?

No, Atlas LP currently supports spot trading only. Futures and margin trading are not supported.

Related articles

Run your spot liquidity bot with clear controls

Connect an exchange API key, set your spread band and order levels, and monitor orders, fills and balances from one console.

Create an account