TickTap

Connect an exchange

Create a read-only API key on OKX or Binance and connect it to TickTap.

Connecting an exchange account lets TickTap show your balance and positions and watch them with account alerts. OKX and Binance are supported; each exchange is an adapter, so more can be added. You can connect several accounts, on one exchange or both.

OKX

  1. In the OKX app or website, open your profile, then API, and create an API key.
  2. Choose a Passphrase and write it down. This is a password you set for this key only. It is not your login or funds password, and OKX never shows it again. If you forget it, delete the key and create a new one.
  3. Grant Read permission only. Do not enable trading or withdrawals.
  4. Leave the IP allowlist empty. TickTap runs on Cloudflare, whose outgoing addresses are not fixed.
  5. Copy the API key and the Secret key. The secret is shown only once.

In TickTap, choose OKX and fill in the API key, Secret key and Passphrase.

Binance

  1. On Binance, open Account → API Management and create an API key (the System generated type).
  2. Keep only Enable Reading. Do not enable spot, margin or futures trading, or withdrawals.
  3. Leave IP access unrestricted, for the same reason as above.
  4. Copy the API key and the Secret key. The secret is shown only once.

In TickTap, choose Binance and fill in the API key and Secret key. Binance has no passphrase.

TickTap reads your spot holdings and your USDⓈ-M futures account. A key without futures access still works; the overview then shows spot only.

Binance does not serve some regions and answers requests from them with HTTP 451. If connecting fails with Binance 451, the request came from a location Binance refuses.

Connect it

In the dashboard, open Settings → Exchange accounts, choose the exchange, give the account a name such as Main, and fill in the fields it asks for.

TickTap checks the key against the exchange before saving it. If something is wrong, the exchange's own error is shown, for example OKX 50105 for a wrong passphrase or Binance -2015 for a wrong key.

How the key is stored

  • The secret (and the passphrase, for OKX) is encrypted with AES-GCM before it is stored, and is never sent back to the browser.
  • The dashboard only ever shows a masked key, like 0acc…2f25.
  • Removing an account deletes its key and every account alert on it.

Only ever connect a key with read permission. A read-only key cannot place orders or withdraw funds, even if it leaks.

On this page