Skip to main content
Trader
Management key

Opens, funds, and labels every subaccount. Can’t place orders.

Subaccount ABalance, positions, orders
Trading key
Subaccount BBalance, positions, orders
Trading key

Each trading key reaches only its own subaccount, and that never changes.

Scopes

Each key has one scope, fixed when you create it.
  • management opens, funds, and labels subaccounts, and creates and revokes keys.
  • management::read lists keys and subaccounts, and reads any balance and ledger.
  • trading places and cancels orders on its subaccount, and reads the catalog.
  • trading::read reads its subaccount’s orders, fills, positions, and balance, and the catalog.
No key can both move money and place orders. A leaked trading key can lose its balance through trades, but it can’t withdraw money or reach another subaccount.

Address a subaccount by its trading key

Routes that act on a subaccount take its trading key ID as {keyId}, as in GET /v3/account/subaccounts/{keyId}/balance.
  • A management key ID isn’t an address, because it doesn’t point at one subaccount. It returns a 400.
  • A revoked trading key’s ID still works as an address. Your management key can still reach the subaccount through it.
  • The subaccount list has one row per live subaccount. Each row’s keyId is that subaccount’s trading key.
  • Use one subaccount per strategy, so a cancel-all stops only that strategy.
  • Use one subaccount per process, so you can revoke a compromised host without stopping the others.
  • Keep your one management key in a secret manager, never in a running process. It’s the only key that moves money.