Introduction
API keys are the gateway to automated trading on centralized crypto exchanges. For teams deploying spot market making bots, securely setting up and validating these keys is essential—not just for operational efficiency, but for protecting exchange accounts and ensuring compliance with exchange policies. This guide walks through the steps and considerations for configuring API keys with Atlas LP, a multi-tenant spot market making bot platform, and highlights best practices for secure and reliable API integration.
Why API Key Security Matters in Market Making
Market making bots require ongoing access to exchange accounts to place, manage, and cancel limit orders. API keys provide this access, but if misconfigured or exposed, they can lead to unauthorized trades, data leaks, or even asset loss. Proper API key management is foundational for:
- Account security: Preventing unauthorized access or malicious actions.
- Operational reliability: Ensuring the bot can continuously monitor and quote in the market.
- Regulatory compliance: Avoiding prohibited activities like wash trading or volume manipulation.
Step 1: Create Exchange API Keys with the Right Permissions
When creating API keys on your chosen exchange, always follow these guidelines:
- Enable only necessary permissions:
- Read permission (to fetch balances, open orders, trades, and market data)
- Spot trading permission (to place and cancel limit orders)
- Never enable withdrawal permissions: Atlas LP never asks for or uses withdrawal access. This reduces risk if the key is ever compromised.
- Restrict by IP if possible: Some exchanges allow you to whitelist IP addresses. This adds another layer of protection, though Atlas LP is multi-tenant and may require flexible IP settings depending on your deployment.
| Permission | Required? | Purpose |
|---|
| Read | Yes | Fetch balances, orders, trades, market |
| Spot Trading | Yes | Place/cancel limit orders |
| Withdrawals | No | Not required or recommended |
Step 2: Securely Store and Manage API Keys
Atlas LP is designed with security in mind. When you add API keys to Atlas LP:
- Encryption: API keys and secrets are encrypted with AES-256-GCM before storage.
- Access control: Secrets are only decrypted by the worker that communicates with the exchange. Saved secrets are never displayed again in the interface.
- User control: Users can register multiple exchange accounts and create a separate bot per symbol, keeping operations segmented.
Tip: Always keep a secure backup of your API keys in a password manager or other secure storage, as you won’t be able to retrieve them from Atlas LP after saving.
Step 3: Validate API Key Functionality Before Trading
Atlas LP performs detailed API verification before allowing a bot to start. This includes:
- Checking the ticker and order book for the selected symbol
- Verifying symbol rules (such as minimum order size and notional)
- Fetching balances, open orders, and recent trades
- Optionally, placing a test limit order far from the market price and immediately canceling it to confirm trading permission
If the exchange rejects the credentials at any step, Atlas LP will stop the bot and display an error status, preventing accidental or unauthorized trading.
Step 4: Configure and Validate Bot Settings
Before a market making bot can be started, Atlas LP validates all user-defined settings:
- Spread band: Minimum and maximum spread in basis points (at least 40 bps wide)
- Order levels: Number of bid and ask levels, with customizable spacing (from 0.1 bps)
- Order sizes: Randomized between user-defined minimum and maximum, always meeting exchange minimums
- Tick interval: How frequently the bot updates its quotes (from 0.5 seconds, default 3 seconds)
Settings that do not meet exchange or platform requirements are rejected, reducing the risk of order errors or rejections during live operation.
Step 5: Monitor and Maintain API Key Health
Atlas LP provides tools to help teams monitor their API connections and trading activity:
- Console dashboard: Displays open orders, recent fills (including fees), balances, and bot events in real time
- Daily snapshots: Records account asset value for tracking and analysis
- Telegram alerts: Notifies users if a running bot has had no fills for a user-defined period, helping detect connectivity or market issues
- Manual controls: Users can cancel individual or all open orders directly from the bot page, and stopping a bot immediately halts new order placement
Best Practices for Ongoing API Key Security
- Rotate API keys periodically: If your exchange allows, update keys regularly and remove unused ones
- Audit permissions: Double-check that only the required permissions are enabled
- Monitor exchange account activity: Use exchange tools to review API access logs and spot suspicious activity
- Educate your team: Make sure everyone understands the importance of API key security and the risks of sharing keys
What to Avoid: Prohibited Activities
Genuine market making means placing resting limit orders that any participant can trade against. Activities such as wash trading, self-trading, or volume manipulation are strictly prohibited and can result in exchange penalties or bans. Atlas LP is designed for compliant, transparent liquidity provision.
Supported Exchanges
Atlas LP currently supports spot market making on the following centralized exchanges:
- Binance
- DigiFinex
- LBank
- BingX
- XT.com
- Biconomy
- Toobit
- CoinW
- P2B
- Azbit
- Dex-Trade
For a complete list and details, see [/supported-exchanges].
Conclusion
Setting up and validating exchange API keys is a critical foundation for secure, reliable spot market making. By following best practices and leveraging Atlas LP’s built-in security and validation features, teams can minimize risk and focus on providing genuine liquidity. Remember, Atlas LP does not guarantee returns, prices, trading volume, or listings.
Crypto trading involves risk. Atlas LP is software for placing and managing limit orders; it does not guarantee returns, prices, volume or listings. Follow the rules of each exchange and applicable law.