---
title: "Is My API Key Safe on Flicker?"
canonical: https://flicker.finance/learn/faq/is-my-api-key-safe-on-flicker
---

# Is My API Key Safe on Flicker?

How Flicker's read-only API keys work, what we can and can't do with them, and why connecting an exchange account can't put your funds at risk.

Short answer: yes. Flicker only ever asks for **read-only** API keys, and read-only keys are physically incapable of moving your money.

## What "read-only" means

Every exchange lets you scope an API key to specific permissions when you create it. Flicker's setup guides walk you through enabling exactly one: **Reading**. Trading, margin, futures, and withdrawal permissions stay switched off — you never enable them, and Flicker never asks you to.

An exchange enforces that scope on its own servers, not Flicker's. Even if a read-only key were somehow leaked, whoever had it could only look at your account — they couldn't place an order or withdraw a single dollar.

## What Flicker can see

With a connected account, Flicker can read:

- Balances and portfolio value
- Open positions and order history
- Trade history
- Which exchanges you've connected

That's it. Nothing beyond what the "Reading" permission exposes on the exchange's own API.

## What Flicker can never do

- Place, modify, or cancel a trade
- Deposit or withdraw funds
- Change your exchange account settings or password
- Access funds outside of what a read-only key can see

This isn't a policy promise — it's enforced by the exchange, since a key without trading or withdrawal permission simply can't authorize those actions.

## How your keys are stored

API keys and secrets are encrypted at rest and only used to make read requests to the exchange's API on your behalf. You can revoke a key at any time — from Flicker or directly on the exchange — and access stops immediately.

## Still not sure?

You can verify this yourself in under a minute: open your exchange's API management page after connecting to Flicker and check which permissions are enabled on the key. If "Trading" or "Withdrawals" show as off, that's the whole story.

## Need Help?

- See our exchange-specific guides for [Binance](/learn/faq/how-to-create-binance-read-only-api-key), [OKX](/learn/faq/how-to-create-okx-read-only-api-key), and [BloFin](/learn/faq/how-to-create-blofin-read-only-api-key)
- [Or contact Flicker support](https://discord.gg/Srzdb73E29)

---

Canonical HTML: https://flicker.finance/learn/faq/is-my-api-key-safe-on-flicker
Machine-readable index: https://flicker.finance/llms.txt · API: https://api.flicker.finance/docs/openapi.json · MCP: https://api.flicker.finance/mcp
