The core of safely connecting a third-party trading tool to OKX is: use an API Key instead of handing over your account password; grant only trading permissions, never withdrawal; and bind the IP whitelist to the tool's server address. If your tool supports OKX's Fast API (OAuth authorization mode), use that method first. It will automatically bind the IP whitelist for you, so you don't need to manually copy and paste keys.

A leading global cryptocurrency platform,suitable for both beginners and experienced traders.
New user benefit: 20% off trading fees upon registration!!
First, understand the two connection methods
There are two ways for third-party tools to connect to OKX, and they are managed in completely different places.
Broker connection (such as Fast API) is authorized within the third-party tool. You log in to your OKX account and click "Approve". The tool automatically generates an API Key that is bound only to its server IP. You do not need to manually copy any keys. This is the safest method because even if the key is leaked on the tool's side, an attacker cannot use it from a non-whitelisted IP.
API Key connection requires you to manually create a key in your OKX account and then paste the Key, Secret, and Passphrase into the tool. This is a more universal method, but you need to control the permissions and IP whitelist yourself.
How to choose permissions when creating an API Key
There is only one core principle: give the tool the minimum permissions it needs to do its job, and nothing more.
If the tool only helps you place and manage orders, check only "Trade". Do not enable "Withdraw" permission—placing and canceling orders does not require withdrawal permission, and enabling it only increases your risk exposure.
"Read" permission is usually also needed because the tool needs to view your balance and positions to work properly. But "Read" itself does not involve moving funds, so the risk is manageable.
If you are not sure which permissions a tool needs, start by granting only "Read" and "Trade", and test whether the tool works normally. If the tool reports an error saying it lacks a permission, go back and add it. Do not turn on all permissions from the beginning.
When creating an API Key, you also need to set a Passphrase, which is a required parameter for calling the API. It is as important as the API Secret, and it cannot be viewed again after creation—if you forget it, you will have to delete and recreate the key.
IP whitelist: why it is required and how to bind it
The IP whitelist is the most effective line of defense for protecting an API Key. An API Key with trading or withdrawal permissions that does not have an IP whitelist bound will be automatically deleted after 14 days of inactivity. This is both a security mechanism and a possible reason why your tool suddenly stops working.
Binding rules: Each API Key can be associated with up to 20 IP addresses, separated by commas or spaces. You should fill in the exit IP of the third-party tool's server, not your own computer's IP.
Tools usually state the IP address they use in their documentation or settings page. If you cannot find it, you can ask the tool's customer support, or connect the tool once without binding an IP and then check the request source IP in OKX's API activity log.
There is a common mistake to avoid: do not use 0.0.0.0/0 to "allow all IPs". That makes the whitelist meaningless, and any IP could use your key.
Troubleshooting order when a tool cannot connect
When a third-party tool reports an error, check in the following order to solve most problems.
Error 50119 (API key doesn't exist): Usually the API domain for your region is incorrect. If you are in the EEA (European Economic Area), the request domain should be eea.okx.com; US users should use us.okx.com. If the tool does not support regional domains, contact the tool provider to confirm.
Error 50110 (failed to bind third-party software): The current API Key type may be incompatible. OKX recommends applying for a new Trade type API Key, without binding an IP list first, and then trying to connect the tool.
Tool shows zero balance: Check whether your funds are in the trading account. A third-party tool can only see the balance of accounts it has access to. If your funds are in the funding account or another sub-account, the tool will not see them. Also, unfilled orders and positions occupy margin, so the available balance may be much smaller than the total balance.
Tool says "trading pair unavailable": This is usually because the trading pair identifier sent by the tool does not match OKX's actual identifier. The tool may display a simplified label (such as "BTC USDT"), but OKX's actual identifier may carry a product type suffix. Re-select the pair in the tool's trading pair selector instead of manually typing the label.
Revoking and rotating keys
When you stop using a tool, suspect a key leak, or need to switch tools, delete the corresponding API Key directly in your OKX account. After deletion, the tool immediately loses access to your account.
If you only suspect that a key may have been exposed but have not confirmed it, delete it first and then recreate it. Do not try to "wait and observe"—deletion is irreversible, but it is the safest approach. After recreating, configure the new key in the tool.
The management entry is under Profile > API in OKX. There you can view all created keys, edit permissions and IP whitelists, or delete keys you no longer need.
Completion standard
A secure connection is in place only when the following conditions are met: the tool uses a separate API Key, permissions are limited to Read and Trade, the IP whitelist is bound to the tool server's actual address, and the Passphrase and Secret are stored in a password manager rather than in chat records. If you use the Fast API authorization mode, confirm that the authorization page shows OKX as the connection target, and that the tool can only use the generated key through its server IP.

A leading global cryptocurrency platform,suitable for both beginners and experienced traders.
New user benefit: 20% off trading fees upon registration!!
References
- OKX·How do I connect a third-party trading terminal or bot to my OKX account, page publication or update date: not indicated; verification date: 2024-07-01.
- MarketZones·Almost API Launch, page publication or update date: not indicated; verification date: 2024-07-01.
- MarketZones·API FAQ, page publication or update date: not indicated; verification date: 2024-07-01.
- OKX·API FAQ, page publication or update date: not indicated; verification date: 2024-07-01.
- OKX·API FAQ, page publication or update date: not indicated; verification date: 2024-07-01.
- GitHub·Jesse project OKX API setup guide, page publication or update date: not indicated; verification date: 2024-07-01.
- OKX·API FAQ for EEA users, page publication or update date: not indicated; verification date: 2024-07-01.
- OKX·API FAQ, page publication or update date: not indicated; verification date: 2024-07-01.


