Create ApiKey
On the Account Settings → API KEY page (/m/account#apikey), click "Create New ApiKey" to get an AccessKey and a SecretKey. The SecretKey carries every permission of the key; keep it secret. The same page lets you change the permissions of existing keys, or disable and delete them.
Permissions
When creating or editing a key, enter a comma-separated list in the "API Permissions" field:
*: allow all extended API methods.- Method names: allow only the listed methods, e.g.
GetRobotList,GetRobotDetail,CommandRobot. !MethodName: exclude a method, usually together with*, e.g.*,!DeleteRobot,!DeleteNode.
The same API KEY can also be used for AI Integration (the MCP service, see Integrations → AI Integration). Besides tool names, MCP tools can be authorized by permission category: read, backtest, write, trade, danger (see the AI Integration page), and !name excludes as well. Categories only apply to MCP tools; the extended API only recognizes method names and *.
With an empty permission list the extended API does not restrict methods (MCP allows every tool except danger). Grant only what each use needs, e.g. a key used only for TradingView alerts should get CommandRobot and nothing else.