Create a key
- Open API, choose Create API key, and fill the New API key form.
- Enter a descriptive Name, such as
Portfolio monitor — demoorStrategy controller — production. - Set Expires in days. Choose only the lifetime needed; the maximum is one year.
- Select the required permissions from the table below.
- Select Exchange links. Verify both the linked account and its
demoorliveenvironment. A key can include 1–32 authorized links. - Optionally enter exact Canonical instrument IDs, one per line. Copy them from the selected link’s catalog; do not enter chart aliases. Up to 64 unique IDs are allowed. An empty list permits instruments on the selected links.
- Submit the form and complete fresh password or linked Apple authentication. If account MFA is enabled, complete that verification too.
- Save the one-time secret in a private secret manager. Dismiss the secret after saving it.
Permission switches
Permissions are independent. A write-only trading key can submit an allowed command and inspect its own namespace receipts without
read. Give a controller read when it needs position reconciliation. templates:write does not imply template read access.
Discovery accepts any valid ordinary API credential. Listing linked accounts and all other data reads require read. Receipt detail permits an owning namespace, or a same-account read key whose exact link/instrument restrictions authorize the receipt.
Instrument restrictions and aggregate reads
A key restricted to one instrument cannot read an entire account/link aggregate that would disclose other instruments. For example, balances, positions pages, fee schedules, dashboard history and private aggregate stream subscriptions are unavailable to an instrument-restricted key. Use exact position reads, exact-instrument catalog selection and ticker subscriptions within its scope. Templates are account-owned. Granting template read or write permits the corresponding account template operation; templates do not become isolated to the key’s selected instrument.Send a key
Secret disposal and ambiguous issuance
The UI clears the displayed secret when hidden, on navigation, lock, logout or account change. Copy it before switching away. If issuance times out or its response is lost, inspect the credential list. Do not repeatedly press Create or automatically replay issuance. A committed duplicate can return metadata, but cannot recover the one-time secret; revoke an unusable new credential before explicitly issuing another.Replacement, rotation and revocation
A replacement credential retains the existing integration namespace and its exact policy. This preserves command deduplication and TradingView lifecycle ownership. Changing permissions or scope is a new approved policy, not an unreviewed extension of the old key. After updating the intended client and confirming its use, revoke the old credential. Revoking a key blocks new authorized handoffs; it does not remove existing positions or interrupt protection, termination or recovery already owned by Liftx. Stopping a bot is not the same operation as closing its positions. A confirmed revocation response is200 with revoked:true. REVOCATION_UNCERTAIN means an attempted database update could not be confirmed. Inspect current metadata before an explicit retry; never treat a timeout as successful revocation.
Metadata inspection and revocation remain available in authenticated Settings after entitlement expires. External reads, new issuance and trading handoffs require current entitlement. Streams close when their key or entitlement expires and enforce revocation throughout their lifetime.
Practical key boundaries
Keep independent strategies in separate namespaces when command identity, auditing and permissions must be independent. Ordinary API position authority is bounded by credential scope, not automatically by who opened the position; use dedicated links or a controller ownership policy where stronger strategy isolation is required.