Bitsgap logo
 Search
How to Revoke a Trading Bot's API Access

How to Revoke a Trading Bot's API Access

Deleting an API key cuts off a bot instantly, on every exchange. Here's why that's enough — and what to double-check before you assume it worked.

Deleting the API key on your exchange account is the entire process. The moment it's gone, any bot using it — Bitsgap or otherwise — loses access immediately. Nothing needs to happen on the bot platform's side first, and nothing needs to propagate: the exchange enforces the cutoff the instant the key no longer exists.

Why deletion is instant, not eventual

Every request a trading bot sends to an exchange is cryptographically signed using that specific API key — Bitsgap, for example, signs its own developer-API requests with an Ed25519 key pair, and standard exchange APIs work on the same principle: the signature only validates against a key the exchange currently recognizes as active. Delete the key, and the exchange's own systems reject every subsequent signed request instantly, regardless of what the bot platform thinks its own connection status is. This is also why you never need the bot platform's cooperation to disconnect — the exchange, not the bot, is the actual gatekeeper.

The general steps, on any exchange

  1. Log into your exchange account directly — not the bot platform
  2. Find the API management section, typically under account security or a dedicated API tab
  3. Locate the key connected to your trading bot — most exchanges let you label a key when you create it, or list its active permissions so you can identify it by what it's scoped to do
  4. Delete or disable that key

Where that section has historically lived on each exchange:

How to Revoke a Trading Bot's API Access-1

If you can't identify which key belongs to your bot, delete any key you don't recognize using and regenerate access from scratch for anything you still want connected. A stray, unused key is a loose end worth closing regardless of whether it's the one you were looking for.

If you're running bots on more than one exchange

Revoking access is per-exchange, per-key — there's no single switch that disconnects Bitsgap everywhere at once, because each exchange enforces its own keys independently. If you're stopping all bot activity entirely, work through each connected exchange's own API management page one at a time. This is also worth doing methodically if you're closing a Bitsgap account altogether: revoke every exchange key first, then close the account, rather than assuming account closure alone severs the exchange-side connections — it's the exchange, not the account closure, that actually cuts off access.

What happens to the bot after you revoke access

The bot stops being able to place, adjust, or cancel orders the instant the key is gone. Positions already open on the exchange stay open, governed by whatever stop-loss or take-profit orders were already placed — revoking the key doesn't close anything for you automatically. If you want positions closed too, do that manually on the exchange, or through the bot platform, before or immediately after revoking the key. This is a common hesitation worth addressing directly: revoking access is not the same action as closing positions, and doing one doesn't force the other — you can safely disconnect a bot while leaving its open trades to run their course, or close everything out first and disconnect after, whichever order fits your situation.

For the underlying question of what a bot's key could actually do while it was active — worth knowing before deciding whether revoking is even necessary — see what data a trading bot can access through an API key. And if you're revoking because you suspect the key was compromised rather than simply disconnecting a bot you no longer want, the sequence and priorities are slightly different — see API key compromised: what to do immediately.

Confirming it actually worked

After deleting a key, the fastest confirmation is checking the bot's status directly on the bot platform — a bot with a revoked key typically shows a connection or authentication error within one trading cycle. If you want certainty immediately, the exchange's own API management page should simply no longer list the key at all.

Control over the connection sits with you, on the exchange you already trust — not with whatever platform you connected.

FAQ

Does deleting my API key immediately stop a trading bot? Yes. Every request a bot sends is signed with that key, and the exchange rejects signed requests the moment the key no longer exists — no waiting period, no action needed from the bot platform.

Will revoking my API key close my open positions? No. Open positions stay open, governed by whatever orders were already placed on the exchange. Close them manually if you want them closed — revoking and closing positions are two separate actions.

Can I revoke access without logging into the bot platform at all? Yes. Since the exchange controls the key, you only need to log into your exchange account to disconnect any bot using it.

Does revoking access on one exchange disconnect my bots everywhere? No. Each exchange enforces its own API keys independently, so revoking access is per-exchange. If you're running bots on multiple exchanges, revoke each connection separately.

What if I can't tell which API key belongs to my trading bot? Check the label or permissions on each key in your exchange's API management page. If you're still unsure, delete any key you don't recognize using and set up a fresh one for anything you want to keep connected.

Want more profit with crypto?

Bitsgap’s automated bots help crypto traders effortlessly make profits 24/7.

Start free trial

*7-days PRO plan trial. No credit card required

Try Bitsgap’s PRO plan free for 7 days, pick a plan later

Done in 3 steps and trades for you.

All your data is secured with high-end encryption