How to Complete Security Initialization After Opening an OKX Institutional Account via Referral Link?
After completing registration via the institutional referral link, security initialization is the first step to enabling your account. The core operations are: immediately configure the "Master Account + Sub-Account" permission system after completing KYB (Know Your Business) verification, and bind two-factor authentication such as Google Authenticator.
A leading global cryptocurrency platform,suitable for both beginners and experienced traders.
New user benefit: 20% off trading fees upon registration!!
This is not a "fill in the forms and you're done" process. The capital scale and compliance requirements involved in an institutional account are far higher than those for a personal account. Inadequate security configuration can lead to functional restrictions in mild cases, or asset risks in severe cases.
Prerequisites: Institutional Account Registration Process Completed
Before starting security initialization, you need to have completed the following steps:
Completed registration through the institutional referral link (filled in email, mobile number, set password)
Selected the institutional type (private company, fund, trust, family office, etc.) and submitted KYB materials, including certificate of incorporation, memorandum and articles of association, list of directors and ultimate beneficial owners, proof of address, etc.
Signed relevant agreements, including the account opening authorization letter and the signing process of the Membership Agreement
If the above steps have not been completed, first contact your OKX account manager to finish the account opening process, then proceed with the security configuration below.
Step 1: Complete Institutional KYB Verification and Information Confirmation
What to do: Ensure the institutional account has passed KYB review and the account status is normal.
How to do it:
Log in to your OKX institutional account, go to [User Center] → [Identity Verification], and check the verification status
If the status is "Verified", proceed to the next step. If it's "Pending Review" or "Additional Documents Required", submit the missing documents according to the instructions
Confirm that the registered institutional type matches your actual business (e.g., funds need to provide fund documents, trusts need to provide trust deeds)
What indicates completion: The account verification status shows "Verified", and the trading functions can be accessed normally on the page.
Step 2: Bind Google Authenticator as Two-Factor Authentication (Core)
What to do: Bind two-factor authentication (2FA) for the institutional master account. This is a prerequisite for all subsequent operations.
How to do it:
Log in to the OKX App or website, go to [User Center] → [Security Settings]
Select [Google Authenticator], and follow the instructions to download the Google Authenticator or Microsoft Authenticator app
Scan the QR code provided by OKX, and enter the generated 6-digit dynamic verification code on the OKX page to complete binding
It is recommended to use an authenticator app (such as Google or Microsoft Authenticator) rather than SMS verification — the former offers higher security
Back up the recovery key provided during binding (QR code or a string of characters) and store it in a secure, offline location — it will be needed when changing phones
What indicates completion: Google Authenticator has been successfully bound, and the system requires a dynamic verification code during login or critical operations.
Step 3: Configure Master Account and Sub-Account Permission System
What to do: Institutional accounts usually require multi-account management. Properly configuring permissions can isolate risks and control the scope of operations.
How to do it:
Go to the [Sub-Accounts] page, and choose to create [Standard Sub-Account] or [Managed Sub-Account (MSA)]
Standard Sub-Account: Suitable for daily trading. Each sub-account can operate independently. Asset withdrawals can only be made through the master account, providing an additional layer of fund security
Managed Sub-Account (MSA): Suitable for scenarios where a delegated trading team manages funds. The trading team's UID must be bound first, and it is limited to institutional users with VIP level ≥ 1
Set independent permissions for each sub-account (e.g., trade only, view only) to ensure that a sub-account's operations will not affect the assets of the master account or other sub-accounts
What indicates completion: Sub-accounts have been created and configured with reasonable permission levels, and members of the asset management team can operate through their own sub-accounts.
Step 4: Set Up Withdrawal Address Whitelist
What to do: Restrict fund withdrawals to pre-approved addresses only, preventing unauthorized withdrawal operations.
How to do it:
Go to [Assets] → [Withdraw] → [Address Book]
Add trusted withdrawal addresses (e.g., company cold wallet, partner custodian address)
Each newly added address requires email confirmation to ensure the authenticity of the operation
Regularly review saved addresses and delete entries that are no longer in use
What indicates completion: At least the destination addresses used for daily withdrawals have been added, and withdrawal operations must be conducted through whitelisted addresses.
Step 5: Set Up Anti-Phishing Code
What to do: Distinguish genuine emails from fake ones to prevent phishing attacks.
How to do it:
Go to [Security Settings] → [Anti-Phishing Code]
Set a custom string of characters (e.g., your institution's English abbreviation + a string of numbers)
Every email sent by OKX will contain this anti-phishing code. Emails lacking this code can be identified as phishing emails
What indicates completion: The anti-phishing code has been set, and team members know how to identify official OKX emails using this code.
Step 6: Review Connected Devices and APIs
What to do: Ensure only authorized devices and APIs can access the account.
How to do it:
Go to [Security Center] → [Device Management] to view all devices that can access the account
Remove any unauthorized or no-longer-used devices
Go to [API Management] and confirm whether there are any API keys created without authorization. If so, delete them immediately
What indicates completion: All entries in the device list and API list have been confirmed with no abnormal entries.
Step 7: Complete Signing and Submission of Account Ownership and Source of Funds Declaration
What to do: Complete the final signing steps required for compliance to ensure the account is formally activated.
How to do it:
Some institutional accounts, after passing KYB verification, also need to sign and upload the account opening authorization letter (or board resolution)
Sign and submit the FCCQ Wolfsberg AML questionnaire or equivalent AML policy documents (for entities such as funds)
After submission, the OKX team will arrange the signing of the Membership Agreement
What indicates completion: All required documents have been signed and submitted, and account functions are fully unlocked.
Common Reasons for Failure
Submitted KYB materials are inconsistent with registration information: Company name, registration number, or other information is incorrectly filled and does not match the documents, leading to rejection of the review.
Ignoring the submission of director and ultimate beneficial owner information: Institutional verification requires identity information of company executives, directors, ultimate beneficial owners, and authorized users. Missing or incomplete materials will result in review failure.
Phone/email verification delay causing 2FA binding failure: Verification code timeout or network issues cause binding interruption, requiring a retry.
Accounts added to a risk unit include unsupported types: Such as DMA broker sub-accounts, accounts already in other risk units, etc. Account grouping needs to be adjusted.
Risk Reminders
Password Strength: It is recommended to use a combination of at least 8 characters, including uppercase and lowercase letters, numbers, and special symbols. Do not reuse the same password as your email or other platforms.
2FA Recovery Key: Must be backed up offline. If lost, a complex identity verification process is required to reset it.
Withdrawals Restricted for 24 Hours After Changing 2FA: After a security setting change, withdrawals will be disabled for 24 hours. This is the platform's protection mechanism for asset security.
Asset withdrawals from sub-accounts can only be processed through the master account. Sub-accounts cannot withdraw funds independently. This mechanism provides an additional layer of fund security.
A leading global cryptocurrency platform,suitable for both beginners and experienced traders.
New user benefit: 20% off trading fees upon registration!!
How to Confirm Initialization is Complete
After completing the above steps, open the [Security Settings] page and confirm that the status of the following items is enabled or shows "Configured":
Google Authenticator (Bound)
Anti-Phishing Code (Set)
Withdrawal Address Whitelist (At least 1 address added)
Sub-Accounts (Created and permissions assigned)
No abnormalities in the Device Management list
At the same time, enter the institutional account home page to ensure all functions (spot trading, withdrawals, transfers, etc.) are accessible normally, indicating that the account has been officially activated.
