Use a dedicated key
Create a separate key for portfolio viewing. Do not reuse credentials from a trading bot or another service.
This app connects to api.binance.com, not Binance.US. Use the smallest possible permission set: reading on and every asset-moving permission off.
An API key and secret act like credentials. A read-only configuration limits their power, but they still deserve careful handling.
Create a separate key for portfolio viewing. Do not reuse credentials from a trading bot or another service.
A balance tracker needs permission to read account data—not permission to place orders, transfer funds, or withdraw.
Confirm every trading, margin, futures, universal-transfer, and withdrawal switch remains disabled.
Do not email, message, screenshot, or publish the secret. Binance may show it only once during creation.
Remove keys you no longer use and revoke one immediately if you suspect that it was exposed.
Use strong account 2FA, apply an IP allowlist where practical, rotate the key periodically, and verify current Binance.com guidance.
Sign in through the official Binance.com website, open your account settings, and locate API Management. This app does not support the separate Binance.US API.
Choose the standard account API option available to you, complete Binance security verification, and give the key a recognizable name such as Portfolio Tracker.
Enable reading only. Keep Spot and Margin Trading, Futures, Universal Transfer, withdrawals, and any other asset-moving permission disabled.
Copy the values directly into the app. Avoid saving the secret in notes, chat, email, screenshots, or unencrypted documents.
Connect the key and compare the resulting Spot and eligible Simple Earn balances with Binance before relying on the view.
Periodically review and rotate active keys. Use an IP allowlist if it is compatible with the networks your phone uses. Revoke the key when you stop using sync or suspect exposure.
Do not enable trading, margin trading, futures, withdrawals, transfers, or any permission that can place an order or move funds. Crypto Portfolio Tracker only needs the account-reading access required to retrieve supported balances.
Binance is a trademark of its respective owner. This independent guide is not endorsed by or affiliated with Binance. For more detail, read the site’s security page.
Reading only. Trading, margin, futures, transfers, and withdrawals should remain disabled. If an unrelated tracker demands asset-moving permission, do not connect it.
No. Create a separate key with the minimum permissions required for each service. This makes the key easier to audit and revoke without interrupting other tools.
The key may be inactive, expired, revoked, restricted by region or IP settings, or missing read access. Check Binance’s error message and current API settings; never enable trading or withdrawal access as a workaround.
No. It substantially limits what the credential can do, but account and portfolio information is still sensitive. Protect the secret, review permissions, and revoke it if exposed.
How Bitcoin works, why it matters, and how to get started — explained simply.
Read moreGuideCoins, tokens, blockchains, and how crypto actually works — for complete beginners.
Read moreGuideHow the halving works, the full schedule, past dates, and what it means for miners.
Read more