Understanding API Key Permissions for Exchange Connections
When connecting an exchange to Delta using an API key, the permissions on that key need to be just right.
Delta only needs Read-Only access to import your balances and transaction history. We never need permission to trade, withdraw, or move your funds.
What permissions does Delta need?
When creating your API key, enable the available Read-Only or Query permissions.
The exact names vary between exchanges, but these usually include access to:
Balances – so Delta can see which assets you hold.
Trade and order history – so we can import your buys, sells, and completed orders.
Deposits and withdrawals – so transfers in and out of your exchange can be included.
You should not enable permissions that allow the API key to trade, withdraw, or transfer funds.
“API credentials have insufficient access”
If you see an “API credentials have insufficient access” error, your API key doesn’t have all of the Read-Only permissions Delta needs.
Head back to the API settings on your exchange and check that you’ve enabled all available Read-Only or Query permissions, particularly those covering balances, trade history, and deposits and withdrawals.
Once updated, return to Delta → Settings → Connections, select your connection, enter the updated credentials, and tap Update Connection.
“API credentials have too much access”
If your API key has permissions that could be used to trade or move funds, Delta will decline the connection and let you know that the credentials have too much access.
This can happen if you’ve enabled permissions for things like:
Trading or placing orders
Margin trading
Withdrawals
Transfers
Head back to your exchange’s API settings and remove these permissions, leaving only the Read-Only or Query permissions Delta needs.
You can then return to Delta → Settings → Connections and update the connection with your API credentials.
Don’t delete your connection just to update your API key. Deleting a connection also removes the transaction history previously imported through it. Use Update Connection instead.
What happens to my API key?
Your API key and passphrase are stored locally on your device. They aren’t included with your Delta account data or transferred between your devices.
This means that if you move to a new device or restore Delta using a recovery QR code, your imported transactions can still be restored, but you’ll need to enter your API credentials again before that exchange can continue syncing.
Keeping your API key safe
The Delta team will never ask you to send us your API secret or create an API key that can trade, withdraw, or transfer funds.
If anyone claiming to be from Delta asks you for an API secret or requests permissions beyond Read-Only access, don’t share or enable them.
