Giriş yap

How to create and manage API keys

August 24, 2026

Paribu API keys allow you to integrate your account securely with automated systems such as bots, portfolio trackers, or your own applications. API keys are created and managed only via paribu.com; account verification must be completed and two-factor authentication (2FA) must be active on your account.

What is an API key?

An API key is a credential pair that lets you grant a permitted copy of your Paribu account to an external software. Each key consists of two parts:

  • API key: The code generated specifically for you, used to access the Paribu API infrastructure
  • Secret key: The signature that verifies the requests being made are genuinely yours

When you create an API key, you can determine which actions it is allowed to perform (permissions), which signature algorithm it uses, which IP addresses it can be used from, and the date range in which it remains valid.

Warning: Never share your secret key with third parties. Anyone who has the secret key can perform actions on your account within the permissions you assigned to the key.

Prerequisites

To create an API key, the following conditions must be met on your account:

  • Account verification (KYC) must be completed. The API key item appears on the Security settings page only for verified accounts
  • Two-factor authentication (2FA) must be active. Google Authenticator verification is requested while creating a key; if 2FA is not active, the flow redirects you to the Google Authenticator setup window

Note: A passkey may also be required on your account to make transactions with API keys. When this condition is not met, the warning "Passkey required for API operations" appears and you are asked to activate your passkey.

API key creation and management is available only on paribu.com. The Paribu app does not include an interface for API keys; all the steps below are performed via paribu.com.

How do you reach the API key window?

API keys are managed in the API key window opened from the Security settings page. In the window, you can view your existing keys, create a new key, edit a key's details, or delete a key.

  1. Sign in to Paribu.com
  2. Hover over the profile icon at the top right and click Security settings in the menu that appears
  3. In the Other security settings section, click Generate API key
  4. Your existing keys are listed under the Keys heading; if you do not have a key yet, the message "You have not created an API key yet." and the Create API key button are shown

How do you create an API key?

  1. In the API key window, click the + icon at the top right or the Create API key button on the empty list
  2. Enter a name you can recognize the key by in the Key name field
  3. Select the permission mode you want to grant the key in the Permissions section (see the table below)
  4. Select the signature algorithm in the API algorithm field
  5. If you prefer, turn on the Restrict usage period option and set a Start date and End date
  6. If you prefer, turn on the Allowed IP addresses option and enter the IP addresses that can use the key
  7. Click the Continue button
  8. Enter the 6-digit code from the Google Authenticator app on the verification screen that opens
  9. Once verification is complete, the API key and Your secret key are shown one time; copy both to a secure location

Warning: The secret key is visible only at creation. The warning on the screen states this as well: "You will only see this secret key once. Please copy the key and save it in a secure place." Once you close the window, you cannot view the secret key again.

Permission modes

Permissions are offered in four modes. It is recommended to select the narrowest mode for the scenario the key will be used in.

Mode What it does
Read-only Views account and market data; cannot make transactions
Trade In addition to read permissions, creates and cancels orders
Full access Covers all read and write permissions
Custom You select the permissions one by one

Note: Apply the principle of least privilege. Do not grant withdrawal permission to an app that will only read data; keeping permissions narrow limits the potential loss if the key is compromised.

Permissions selected one by one in Custom mode

When you select the Custom mode, permissions are listed in two groups:

  • Read permissions: User information · Balance/asset information · Open orders · Order detail · Trade history · Transfer history · Withdrawal detail · Transfer statements
  • Write permissions: Create order · Cancel order · Create withdrawal · Cancel withdrawal · Create deposit address · Create transfer statement

If you try to continue without selecting any permission, the warning "You must select at least one permission." appears.

Withdrawal permissions depend on your account status

Create withdrawal and cancel withdrawal permissions are not available on every account. If your account is not eligible for these permissions, they do not appear in the permission list; if they are still selected, the warning "Your account tier is not sufficient for this permission." or "Your account cannot use withdrawal permissions on API keys. Remove the withdrawal permissions and try again." is shown. In that case, you can remove the withdrawal permissions and create the key again.

API algorithm

You select the signature algorithm while creating the key. There are two options, and both verify that the data sent has not been altered:

  • HMAC: Uses a secret key and a hash function
  • ED25519: Uses public/private key pairs

The algorithm you select appears in the key detail as Selected algorithm.

Usage date range

When you turn on the Restrict usage period option, you can set a Start date and an End date for the key. The end date must be at least one day ahead; if you select an earlier date, the warning "The expiration date must be at least 24 hours from now." appears. When the period ends, the key's status becomes Expired.

Allowed IP addresses

If you want to use your API key only from specific servers, you can turn on the Allowed IP addresses option and add the addresses you allow. While this list is defined, requests from unauthorized addresses are rejected.

  • You can add up to 20 IP addresses; the description on the screen states this as well: "You can add up to 20 IP addresses. Please separate each address with a comma ','."
  • You need to write the address in a valid format; otherwise the warning "Please enter an IP address in a valid format." appears
  • You cannot add the same address twice; the warning "This IP address is already in the list." is shown

How do you view your API key?

You can see the keys you have created in the list within the API key window. When you click a key in the list, the API key detail opens with the following information:

  • Key name
  • API key
  • Creation date
  • Validity date (if you set a usage period)
  • Permissions — the mode you selected and the Read permissions / Write permissions breakdown
  • Allowed IP addresses (if defined)
  • Status — Active, Inactive, or Expired

Note: The secret key does not appear on the detail screen. If you have lost your secret key, you need to delete the existing key and create a new one.

Editing an API key

You can update the details of an existing key from the detail screen.

  1. In the API key window, click the key you want to edit
  2. On the detail screen that opens, click the Edit button
  3. Update the key name, permissions, or allowed IP addresses on the Edit API key screen
  4. Click the Save button

Note: Because withdrawal permissions depend on your account status, an update that includes a withdrawal permission may be rejected. In that case, remove the withdrawal permissions and try the update again.

Deleting an API key

You can delete a key you no longer use or whose security you suspect.

  1. In the API key window, click the key you want to delete
  2. On the detail screen, click the Delete key button
  3. Read the warning in the confirmation window that opens: "This API key will be disabled immediately and all requests using this key will be rejected."
  4. Click the Yes, delete button

Warning: The deletion is irreversible and takes effect immediately. You cannot recreate the same key; when needed, you will have to create a new key and update the key details in the app you have integrated with.

Security recommendations

Because API keys provide automated access to your account, they are as critical as your password.

  • Principle of least privilege: Grant the key only the permissions the app actually needs
  • Use IP restrictions: If you know the address of the server the key will be used from, define an allowed IP list
  • Set a usage period: Set a date range for temporary projects; when the period ends, the key's status becomes Expired
  • Store the secret key in an encrypted location: Do not write the secret key in the codebase, in screenshots, or in shared chats
  • Review regularly: Delete keys you no longer use and track the validity dates of active keys
  • Delete immediately if leakage is suspected: If you suspect your key has been compromised, delete it right away and create a new one

API documentation

You can find technical information about API endpoints, authentication methods, and example requests on the Paribu API documentation.


Frequently asked questions

Can I create an API key from the mobile app?

No. API key creation, viewing, and management can only be performed via paribu.com. The Paribu app does not include an interface for API keys.

I lost my secret key. How can I view it again?

The secret key is shown only once at creation and cannot be viewed afterward. If you have lost your key, you need to delete the existing key and create a new one; do not forget to update the new key details in the app you have integrated with.

How many API keys can I create at the same time?

You can create more than one key on your account and define different permissions for each. Using separate keys for different apps enhances your security; if one key is compromised, the others are not affected.

Why is 2FA required to create an API key?

The API key is critical information that provides automated access to your account. Google Authenticator verification ensures that the key can only be created by the account holder. If 2FA is not active, the flow redirects you to the Google Authenticator setup window.

Can I change the permissions of my API key later?

Yes. The key name, permissions, and allowed IP addresses can be updated with Edit on the detail screen. Because withdrawal permissions depend on your account status, updates that include a withdrawal permission may be rejected; in that case, remove the withdrawal permissions and try again.

What does the warning "API key creation is temporarily closed" mean?

This warning shows that key creation has been temporarily paused and does not mean there is an issue with your account. When you try again later, the action is completed.


Related articles

Author:

Paribu