Paribu API keys allow you to integrate your account securely with automated systems such as bots, portfolio trackers, or your own applications. API keys are created and managed only via paribu.com; account verification must be completed and two-factor authentication (2FA) must be active on your account.
An API key is a credential pair that lets you grant a permitted copy of your Paribu account to an external software. Each key consists of two parts:
When you create an API key, you can determine which actions it is allowed to perform (permissions), which signature algorithm it uses, which IP addresses it can be used from, and the date range in which it remains valid.
Warning: Never share your secret key with third parties. Anyone who has the secret key can perform actions on your account within the permissions you assigned to the key.
To create an API key, the following conditions must be met on your account:
Note: A passkey may also be required on your account to make transactions with API keys. When this condition is not met, the warning "Passkey required for API operations" appears and you are asked to activate your passkey.
API key creation and management is available only on paribu.com. The Paribu app does not include an interface for API keys; all the steps below are performed via paribu.com.
API keys are managed in the API key window opened from the Security settings page. In the window, you can view your existing keys, create a new key, edit a key's details, or delete a key.
Warning: The secret key is visible only at creation. The warning on the screen states this as well: "You will only see this secret key once. Please copy the key and save it in a secure place." Once you close the window, you cannot view the secret key again.
Permissions are offered in four modes. It is recommended to select the narrowest mode for the scenario the key will be used in.
| Mode | What it does |
|---|---|
| Read-only | Views account and market data; cannot make transactions |
| Trade | In addition to read permissions, creates and cancels orders |
| Full access | Covers all read and write permissions |
| Custom | You select the permissions one by one |
Note: Apply the principle of least privilege. Do not grant withdrawal permission to an app that will only read data; keeping permissions narrow limits the potential loss if the key is compromised.
When you select the Custom mode, permissions are listed in two groups:
If you try to continue without selecting any permission, the warning "You must select at least one permission." appears.
Create withdrawal and cancel withdrawal permissions are not available on every account. If your account is not eligible for these permissions, they do not appear in the permission list; if they are still selected, the warning "Your account tier is not sufficient for this permission." or "Your account cannot use withdrawal permissions on API keys. Remove the withdrawal permissions and try again." is shown. In that case, you can remove the withdrawal permissions and create the key again.
You select the signature algorithm while creating the key. There are two options, and both verify that the data sent has not been altered:
The algorithm you select appears in the key detail as Selected algorithm.
When you turn on the Restrict usage period option, you can set a Start date and an End date for the key. The end date must be at least one day ahead; if you select an earlier date, the warning "The expiration date must be at least 24 hours from now." appears. When the period ends, the key's status becomes Expired.
If you want to use your API key only from specific servers, you can turn on the Allowed IP addresses option and add the addresses you allow. While this list is defined, requests from unauthorized addresses are rejected.
You can see the keys you have created in the list within the API key window. When you click a key in the list, the API key detail opens with the following information:
Note: The secret key does not appear on the detail screen. If you have lost your secret key, you need to delete the existing key and create a new one.
You can update the details of an existing key from the detail screen.
Note: Because withdrawal permissions depend on your account status, an update that includes a withdrawal permission may be rejected. In that case, remove the withdrawal permissions and try the update again.
You can delete a key you no longer use or whose security you suspect.
Warning: The deletion is irreversible and takes effect immediately. You cannot recreate the same key; when needed, you will have to create a new key and update the key details in the app you have integrated with.
Because API keys provide automated access to your account, they are as critical as your password.
You can find technical information about API endpoints, authentication methods, and example requests on the Paribu API documentation.
No. API key creation, viewing, and management can only be performed via paribu.com. The Paribu app does not include an interface for API keys.
The secret key is shown only once at creation and cannot be viewed afterward. If you have lost your key, you need to delete the existing key and create a new one; do not forget to update the new key details in the app you have integrated with.
You can create more than one key on your account and define different permissions for each. Using separate keys for different apps enhances your security; if one key is compromised, the others are not affected.
The API key is critical information that provides automated access to your account. Google Authenticator verification ensures that the key can only be created by the account holder. If 2FA is not active, the flow redirects you to the Google Authenticator setup window.
Yes. The key name, permissions, and allowed IP addresses can be updated with Edit on the detail screen. Because withdrawal permissions depend on your account status, updates that include a withdrawal permission may be rejected; in that case, remove the withdrawal permissions and try again.
This warning shows that key creation has been temporarily paused and does not mean there is an issue with your account. When you try again later, the action is completed.