> For the complete documentation index, see [llms.txt](https://docs.fluvion.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.fluvion.io/api-trading/api-keys.md).

# Create & Manage API Keys

Open [Portfolio → API Key](https://fluvion.io/portfolio/api-key), connect your wallet and create a dedicated key for your integration. Approve the wallet authorization when prompted.

Save the creation dialog's three values securely:

* **Account ID**: identifies your trading account; not your wallet address.
* **API key** (`key`): public signing key, usually `ed25519:<base58>`.
* **API secret** (`secretKey`): private signing seed, also displayed as `ed25519:<base58>`.

The prefix does not tell you whether a value is public or secret. Use the field label. Save the secret at creation; do not assume you can retrieve it later. If lost, create a replacement and revoke the old key.

## Permissions

| Scope     | Purpose                                                                                                     |
| --------- | ----------------------------------------------------------------------------------------------------------- |
| `read`    | Private account, holdings, positions and order reads                                                        |
| `trading` | Trading operations such as placing/canceling orders                                                         |
| `asset`   | Asset endpoints that specifically require this scope; additional wallet authorization may still be required |

Scopes are independent. A bot that reads and trades needs `read,trading`. Start with `read`, select a short expiry where available, and restrict IP access when practical. Do not grant asset permissions to a basic trading agent.

Store secrets in an OS keychain, secret manager, or a private local environment. Never put them in chat, screenshots, source control, browser bundles, `VITE_*` variables or public runtime config. Do not pass secrets as command-line arguments.

## Revoke and rotate

Revoke unused or exposed keys in Portfolio. Create and verify a replacement before retiring an active integration's old key. Key revocation prevents further use of that key; it does **not** close positions or cancel existing orders.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.fluvion.io/api-trading/api-keys.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
