All tutorials
Tutorial 02 · Connecting

The key that can trade but never withdraw

This is the step clients worry about most, and the one that takes the least time. You create a key on your exchange, tick two boxes, lock it to our server, and paste it into your dashboard. Ten minutes, and your money never moves.

Elapsed: about 20 minutesVideo included
What you are actually creating

An API key is a pair of codes that lets one program act on your exchange account, limited to exactly the permissions you tick. You are creating one that can read your balance and place trades — and nothing else.

Your login, your password and your two-factor codes are never involved. You do not give them to us, and we never ask for them.

You also lock the key to our server's address, which has a useful side effect: a key restricted that way does not expire, whereas an unrestricted one stops working after 90 days.

API key permissions
ReadTick this
TradeTick this
WithdrawNever
IP restriction
Lock the key to Uriel's server address, shown in your dashboard. Locked this way, it is useless to anyone else — even if it were stolen.
Two boxes ticked, one box left untouched. That single unticked box is what makes your funds unreachable.
1
On the exchange

Create the key

  1. Open your profile, then API Management.
  2. Choose Create New Key, then System-generated (not the self-generated option).
  3. Under permissions, tick Read and Trade for Unified Trading / Contracts. Leave Withdraw untouched.
  4. Under IP restriction, choose Only IPs and paste the Uriel server address shown in your dashboard. The key will not work without it.
  5. Confirm with your two-factor code. The exchange shows the key and the secret once.
The secret is shown once

Copy both values immediately and paste them straight into your Uriel dashboard. If you close the window before copying the secret, nothing is broken — delete the key and create another one.

Never send the secret by email, WhatsApp or text, not even to us. It belongs in one place only: the connection screen in your dashboard.

2
In your dashboard

Connect it

Paste the key and the secret into the last screen of the onboarding wizard, tick the confirmation, and press Connect. We check the key immediately: if the permissions or the IP are wrong, you get a clear error rather than a silent failure.

The same steps, recorded on a real account. The key shown in the video was revoked before publishing.

If it does not connect

"Invalid API key" — usually a stray space copied along with the value, or the key was created on a different account than the one you funded.

"Permission denied" — the Trade permission was not ticked for Unified Trading / Contracts. Edit the key on the exchange rather than creating a new one.

"IP not allowed" — the server address was not saved. Reopen the key on the exchange, check Only IPs is selected, and that the address matches the one in your dashboard exactly.

Turning it off

You can delete the key from your exchange at any moment, without telling us and without any notice period. The moment you do, we can no longer place trades on your account. Your positions stay exactly as they are, and your money never moves. See how to take your money out.

Do it together

If you would rather not do this alone, book fifteen minutes with your adviser and share your screen. It is the fastest way through this step.

Talk to us
Next tutorial
Protecting your account