- Sign in to Portfobit Web.
- Open API Keys and select Create API Key.
- Give the key a recognizable name for the integration or service account.
- Select only the scopes the integration needs. Enable
activity:write,trade:write, ortransfer:writeonly when the integration deliberately needs that write capability. - Copy the secret when it is shown and store it in the client configuration. It is not a value to paste into prompts or source control.
Current scopes
Scope recommendation
New keys enable the nine core/read scopes by default:account:read, account:write, portfolio:read, portfolio:write, order:read, trade:read, ledger:read, funding:read, and marketdata:read.
Keep all three write scopes disabled unless they are needed. activity:write also requires Plus or Pro and the matching activity read scope. trade:write and transfer:write alone are not enough to execute anything: each protected action also requires an explicit confirmation, current trading OTP, Idempotency-Key, supported CEX provider permission, subscription entitlement, and a passing risk check.
For a direct OpenAPI integration, choose only the scopes required by the endpoints it calls. See Authentication and scopes for the endpoint-level model.