Loading documentation
Read-only API keys for Binance and Bybit, step by step, with the exact permissions to enable and nothing more.
CONNECTING YOUR EXCHANGE
Reflekt connects to Binance and Bybit with read-only API keys. Read-only means exactly that: the key lets Reflekt see your trading history and nothing else. It cannot place an order, cannot withdraw, cannot move funds between accounts. That permission never gets created, so there is nothing to misuse.
You will need about two minutes and access to your exchange account.
Binance
Go to API Management in your Binance account and hit Create API.
Choose System generated. That gives you an HMAC key pair, which is what Reflekt uses. Ignore Self-generated.
Name the key whatever you want.
Under API restrictions, tick Enable Reading and nothing else. Leave Spot & Margin Trading, Futures, Withdrawals and the rest off. Reading alone covers everything Reflekt needs, including your perps history.
Under IP access restrictions, leave it Unrestricted. Binance will warn you about this. You do not need to whitelist anything for Reflekt.
Copy the API Key and Secret Key before you leave the page. Binance will not show the secret again.
Back in Reflekt, paste both, name the connection, and continue.
Bybit
Go to API Management in your Bybit account and create a new key.
Choose System-generated API Keys. Same idea as Binance, an HMAC pair.
For API Key Usage, select API Transaction.
Name the key whatever you want.
Under API Key Permissions, select Read-Only.
For IP restriction, select No IP restriction.
Then tick these seven:
Trade, Unified Trading, Contract: Orders and Positions.
Trade, Unified Trading, USDC Contracts: USDC Derivatives Trading.
Trade, Unified Trading, SPOT: Trade.
Assets, Wallet: Account Transfer and Subaccount Transfer.
Assets, Exchange: Convert, Exchange History.
Leave everything else off. No Earn, no Fiat trading, no P2P, no Bybit Pay, no Card, no community posts. Withdrawal is not available under read-only anyway.
Submit, then copy the key and secret before leaving the page.
Back in Reflekt, paste both, name the connection, and continue.
One thing about Bybit keys: a key with no IP restriction expires after three months. When it does, your sync stops and you will need to create a new key and reconnect.
After you connect
Reflekt starts pulling your history straight away. How long it takes depends on how much history you have.
How far back depends on the exchange. Binance gives up everything, back to your first trade. Bybit caps out at two years.
Adding another exchange later
You are not locked to one account. To add another, click the accounts button at the top of the app, the one showing how many you have connected. It opens a list of your connected accounts with Add Account at the bottom.
That brings up the same Connect Exchange picker you saw during onboarding. Choose Binance or Bybit and follow the same steps as above.
Each connection gets its own name, so keep them recognisable if you are running several. The filters at the top of the app let you look at one account at a time or all of them together.