Type/to search
Getting Started
Welcome to FMZ Quant Trading Platform
Quick Start
Key Security
Platform Basics
Account and Billing
Live Robot Billing and Top-up
Sub-accounts
Exchange
General Protocol
Local Credential Files
Exchange-Specific Notes
Securities and Futures
Crypto
Docker
Strategy Library
Live Trading
Writing Strategies
Development Tools
Backtesting System
Advanced Topics
Data and Research
Integrations

A leaked exchange key costs you the assets in that exchange account. Before configuring an exchange account, go through this checklist:

  • Trade permission only: enable only read and trade permissions for the API key, and never enable withdrawal.
  • Bind an IP whitelist: on the exchange, bind the API key to the outbound IP of the server running your docker. If the server has several IPs, pin the outbound IP with the docker's -I option (see Platform Basics → Docker → Command-Line Options).
  • Keep private keys local: if the exchange supports asymmetric keys such as RSA, prefer them, and keep the private key as a credential file on the docker's machine so that the platform stores only the file path (see Platform Basics → Exchange → Local Credential Files).
  • Start small: run a new strategy against the exchange's demo trading or a small sub-account first.
  • Do not publish secrets: if the strategy code, parameters or description contain keys, account names or similar information, do not publish or sell the strategy.

How the platform stores keys: encrypted fields such as keys on the exchange configuration page are encrypted in the browser with your platform account password before upload, so the platform never stores them in plain text; only a docker started with that account password can decrypt them locally. Changing the platform account password therefore invalidates existing exchange configurations; see Platform Basics → Live Trading → Common Causes of Live Trading Errors and Abnormal Exits for what to do.