API read-only permissions are usually revoked because the account triggered a security risk control—when the system detects an abnormal login, it automatically revokes all API access permissions, including read-only, as a protective measure.

A leading global cryptocurrency platform,suitable for both beginners and experienced traders.
New user benefit: 20% off trading fees upon registration!!
Here are 3 steps to restore API permissions and strengthen account security.
Step 1: Check the Status of All API Keys First
The first thing to do after logging in is not to create a new key immediately, but to confirm whether the existing API Key is "revoked" or "deleted".
What to do: Go to the API management page and check the status of your current API Keys.
How to do it:
App: [Account] - [API Management]; Web: Click your profile icon in the top right corner, then [Account] - [API].
In the API list:
If a key status shows "Disabled" or "Expired", it has only been suspended by the system and can be re-enabled (after the account security verification is completed).
If the key has disappeared from the list entirely, it has been deleted by the system or manually, and you need to create a brand new set of API Keys.
When is this step complete: You have determined whether the original API Key can be recovered or has been deleted.
Common reason for failure: Assuming that revoked read-only permissions are a minor issue and not checking whether other security settings have also been altered. An abnormal login triggers account-level risk controls, which usually affect more than just the API.
Step 2: Delete Suspicious or Unnecessary API Keys and Create New Ones
If the original key has been deleted, or you plan to create a new set to replace it.
What to do: Delete all API keys not created by you, and create new read-only keys as needed.
How to do it:
Delete old/suspicious keys: In the API list, find keys not created by you, click [Actions] - [Delete]. You need to complete identity verification (e.g., Google Authenticator code, email verification) before deletion.
Create a new API Key:
Click [Create API], enter a key name and description.
When setting permissions, check only "Read" permission; the system will not require you to bind an IP whitelist.
After creation, the system generates three credentials: API Key, Secret Key, and Passphrase. The Secret Key is only shown once during creation—save it in a secure location immediately.
Note: An API Key with trade or withdrawal permissions that is not bound to an IP will be automatically deleted after 14 days of inactivity. Read-only API Keys are not subject to this restriction.
When is this step complete: The new API Key has been created, and you have safely stored the Secret Key and Passphrase.
Step 3: Thoroughly Check Account Security Settings to Prevent Future Risk Control Triggers
After an abnormal login, simply restoring API access is not enough. OKX officially recommends a comprehensive review of account security settings after detecting suspicious activity.
What to do: Go through the following checklist and update security settings.
How to do it:
Login password: Change your account login password immediately; avoid using the same password as your email.
Two-factor authentication (Google Authenticator): Check for any unauthorized Google Authenticator bindings. If anything looks unusual, reset it immediately. After changing or disabling Google Authenticator, withdrawals will be suspended for 24 hours.
Trusted devices: In [Security Center] - [Device Management], remove all unrecognized devices.
Third-party login: Check and unbind any third-party login bindings (such as Google, Apple ID, Telegram) not set up by you.
Withdrawal address book: Delete any "verified addresses" in the address book not added by you.
When is this step complete: All the above security settings have been reviewed, and all suspicious bindings have been cleaned up.

A leading global cryptocurrency platform,suitable for both beginners and experienced traders.
New user benefit: 20% off trading fees upon registration!!
How to Confirm the Recovery Was Successful?
After completing the above steps, use the newly created API Key to call a balance query endpoint (e.g., account balance) and confirm that it returns normal data rather than a 401 error. If the API call succeeds, recovery is complete.
If the abnormal login also caused a temporary account freeze or restriction, you may need to complete a risk control questionnaire via your registered email or submit related materials to lift the restriction.


