If someone has asked you for an API key from your exchange so they can prepare your tax report, having doubts is the sensible reaction. “What if they get to my funds?” “Can they move my crypto?”
The short answer: no, they cannot. This article explains exactly why.
What an API is, in plain terms
API stands for Application Programming Interface. It sounds technical, but the idea is simple:
An API is a controlled door that lets an outside program talk to your exchange.
Think of a hotel keycard:
- Your room card opens your room only, not every door in the building.
- An API works the same way: it carries specific permissions that you choose when you create it.
Every time you create an API key on an exchange such as Binance, Kraken or Bit2Me, you decide exactly what that connection is allowed to do.
The three permission levels
Every exchange organises API permissions in much the same way. There are generally three levels:
1. Read Only
- What it allows: reading your trade history, viewing balances, downloading movements.
- What it does NOT allow: buying, selling, withdrawing or moving funds.
- The equivalent: handing someone your bank statement. They can read the numbers; they cannot touch a single cent.
2. Trading
- What it allows: everything above, plus placing buy and sell orders inside the exchange.
- What it does NOT allow: withdrawing funds to external wallets.
- The equivalent: letting someone trade on your behalf, without being able to take money out of the account.
3. Withdrawal
- What it allows: everything above, plus sending crypto to external addresses.
- This is the only level that could put your funds at risk.
- The equivalent: handing over the full keys to your account.
What a tax report actually needs: read only
Producing a crypto tax report needs the first level and nothing more.
All that is done with the key is:
- download your buy and sell history
- read your deposits and withdrawals
- see the date and price of each transaction
No trading. No withdrawals. Reading data, and that is all.
Why moving funds with a read-only key is technically impossible
This is not a matter of trust. It is a technical limit enforced by the exchange itself.
When you create a read-only key, the exchange issues credentials (an API Key and a Secret Key) governed by strict server-side rules:
-
The exchange checks permissions on every request. Each time the key is used, the exchange’s server verifies what that key is allowed to do. If anyone tries to place an order or a withdrawal with a read-only key, the exchange rejects it automatically.
-
Permissions cannot be escalated. They are fixed at the moment the key is created. Widening the permissions of an existing key is impossible without signing into your account with your password and two-factor authentication (2FA).
-
Every key has its own pair of credentials. Holding a read-only key gives no access to any other key you may have created with different permissions.
It is like trying to open a safe with your gym membership card: it simply does not work, because the system does not allow it.
The extra safeguards exchanges add
The major exchanges layer further protection on top:
| Safeguard | What it does |
|---|---|
| IP whitelist | Restricts the key so it only works from specific IP addresses |
| 2FA to create keys | Two-factor authentication is required to generate any key |
| Granular permissions | Individual permissions can be switched on or off as you create the key |
| Expiry date | Some exchanges let a key expire automatically |
| Notifications | You get an email every time a new key is created on your account |
Side by side: what each key type can do
| Action | Read only | Trading | Withdrawal |
|---|---|---|---|
| View trade history | Yes | Yes | Yes |
| Check balances | Yes | Yes | Yes |
| Download movements | Yes | Yes | Yes |
| Buy or sell crypto | No | Yes | Yes |
| Place orders | No | Yes | Yes |
| Withdraw to an external wallet | No | No | Yes |
| Send crypto to someone else | No | No | Yes |
What if I want to cut off access?
You can delete the key from your exchange whenever you like. It takes effect immediately: once deleted, the credentials stop working on the spot.
So even if you share a read-only key for a tax report, you can revoke access the moment the work is finished.
In short
- A read-only key cannot move, buy or sell your crypto.
- That is a technical limit set by the exchange, not a promise made by whoever receives the key.
- A tax report only needs to read your history, nothing else.
- You can delete the key at any time once you no longer need it.
- Sharing a read-only key is as safe as showing a bank statement: the numbers are visible, but nobody can touch your money.
Need help with your crypto tax report?
At Cryptoimpuestos a read-only key is all we ask for. We do not request trading or withdrawal permissions, for the simple reason that we do not need them.
If you are unsure how to create your key, we have a step-by-step guide for every exchange.
Victor Lazaro
Tax adviser, Cryptoimpuestos.es