OKX API Read-Only Access Revoked: Recovery Steps After Abnormal Login

 / 
OKX
 / 
1

API read-only permissions are usually revoked because the account triggered a security risk control—when the system detects an abnormal login, it automatically revokes all API access permissions, including read-only, as a protective measure.

OKX Exchange
A leading global cryptocurrency platform,suitable for both beginners and experienced traders.
New user benefit: 20% off trading fees upon registration!!

Here are 3 steps to restore API permissions and strengthen account security.

Step 1: Check the Status of All API Keys First

The first thing to do after logging in is not to create a new key immediately, but to confirm whether the existing API Key is "revoked" or "deleted".

What to do: Go to the API management page and check the status of your current API Keys.

How to do it:

  • App: [Account] - [API Management]; Web: Click your profile icon in the top right corner, then [Account] - [API].

  • In the API list:

    • If a key status shows "Disabled" or "Expired", it has only been suspended by the system and can be re-enabled (after the account security verification is completed).

    • If the key has disappeared from the list entirely, it has been deleted by the system or manually, and you need to create a brand new set of API Keys.

When is this step complete: You have determined whether the original API Key can be recovered or has been deleted.

Common reason for failure: Assuming that revoked read-only permissions are a minor issue and not checking whether other security settings have also been altered. An abnormal login triggers account-level risk controls, which usually affect more than just the API.

Step 2: Delete Suspicious or Unnecessary API Keys and Create New Ones

If the original key has been deleted, or you plan to create a new set to replace it.

What to do: Delete all API keys not created by you, and create new read-only keys as needed.

How to do it:

  • Delete old/suspicious keys: In the API list, find keys not created by you, click [Actions] - [Delete]. You need to complete identity verification (e.g., Google Authenticator code, email verification) before deletion.

  • Create a new API Key:

    1. Click [Create API], enter a key name and description.

    2. When setting permissions, check only "Read" permission; the system will not require you to bind an IP whitelist.

    3. After creation, the system generates three credentials: API Key, Secret Key, and Passphrase. The Secret Key is only shown once during creation—save it in a secure location immediately.

  • Note: An API Key with trade or withdrawal permissions that is not bound to an IP will be automatically deleted after 14 days of inactivity. Read-only API Keys are not subject to this restriction.

When is this step complete: The new API Key has been created, and you have safely stored the Secret Key and Passphrase.

Step 3: Thoroughly Check Account Security Settings to Prevent Future Risk Control Triggers

After an abnormal login, simply restoring API access is not enough. OKX officially recommends a comprehensive review of account security settings after detecting suspicious activity.

What to do: Go through the following checklist and update security settings.

How to do it:

  • Login password: Change your account login password immediately; avoid using the same password as your email.

  • Two-factor authentication (Google Authenticator): Check for any unauthorized Google Authenticator bindings. If anything looks unusual, reset it immediately. After changing or disabling Google Authenticator, withdrawals will be suspended for 24 hours.

  • Trusted devices: In [Security Center] - [Device Management], remove all unrecognized devices.

  • Third-party login: Check and unbind any third-party login bindings (such as Google, Apple ID, Telegram) not set up by you.

  • Withdrawal address book: Delete any "verified addresses" in the address book not added by you.

When is this step complete: All the above security settings have been reviewed, and all suspicious bindings have been cleaned up.

OKX Exchange
A leading global cryptocurrency platform,suitable for both beginners and experienced traders.
New user benefit: 20% off trading fees upon registration!!

How to Confirm the Recovery Was Successful?

After completing the above steps, use the newly created API Key to call a balance query endpoint (e.g., account balance) and confirm that it returns normal data rather than a 401 error. If the API call succeeds, recovery is complete.

If the abnormal login also caused a temporary account freeze or restriction, you may need to complete a risk control questionnaire via your registered email or submit related materials to lift the restriction.