How to Create a Read-Only Binance API Key (and Why It Matters)
October 10, 2026 · 5 min read
A read-only Binance API key lets an app see your account history without being able to move a single coin. To create one, open API Management in your Binance account, create a “System generated” key, leave only Enable Reading switched on, and restrict the key to the IP address of the service that will use it. The whole process takes about three minutes.
This guide shows each step, explains what every permission means, and covers the mistakes that make a key unsafe.
Why should a payment service only get read access?
To confirm that a customer paid, a service only needs to read your incoming transactions. It never needs to withdraw, trade or move funds between accounts. Following the principle of least privilege, you give it exactly what it needs and nothing more. If the key ever leaked, the worst anyone could do with it is look at your history.
This is also what makes a non-custodial payment gateway possible: payments land in your own account, and the service can only watch them arrive.
Clearqo enforces this. It checks the key’s permissions with Binance before saving it and refuses any key that can withdraw, trade (spot, margin, futures or options), or make internal or universal transfers. It also requires the key to be IP-restricted, stores the secret encrypted, and re-checks the permissions every day.
Before you start
- Your Binance account must be identity verified and have two-factor authentication turned on. Binance requires both before you can create API keys.
- Have the trusted IP address ready. In Clearqo it is shown in Dashboard → Binance, with a copy button.
- Use a computer if you can. The steps are the same in the app, but copying long keys is easier on a desktop.
Step-by-step: create a read-only key
- Open API Management. Log in to Binance, click your profile icon and choose API Management.
- Create the key. Click Create API and choose System generated.
- Name it. Use a label you will recognise later, for example “Clearqo – read only”.
- Verify. Complete the security check: passkey, authenticator code, email or SMS, depending on your settings.
- Copy both values. Binance shows the API Key and the Secret Key. Copy the secret now. Binance does not show it again, and if you lose it you must create a new key.
- Edit restrictions. Click Edit restrictions and make sure Enable Reading is the only permission switched on.
- Restrict by IP. Under IP access restrictions choose Restrict access to trusted IPs only (Recommended), paste the IP address and confirm.
- Save. Click Save and complete the security check again if Binance asks.
Then paste the API key and the secret into Dashboard → Binance in Clearqo and click Save & verify (part of the WooCommerce setup and the Binance Pay website integration). If anything is wrong, the dashboard tells you exactly what, for example “these permissions are ON: Withdrawals”. When it shows Connected to Binance, you are done.
Which permissions should be on?
| Permission | Setting | Why |
|---|---|---|
| Enable Reading | On | Needed to read deposits and Binance Pay history. |
| Enable Spot & Margin Trading | Off | Payment verification never trades. |
| Enable Margin Loan, Repay & Transfer | Off | Not needed and moves funds. |
| Enable Futures / Options | Off | Not needed. |
| Enable Withdrawals | Off | The most dangerous permission. Never needed for receiving payments. |
| Permits Universal Transfer / Internal Transfer | Off | Moves funds between accounts. |
Binance labels can differ slightly by region and app version. The rule stays the same: reading only.
Why the IP restriction matters
An IP restriction means Binance only accepts the key from the listed server address. Even if someone copied the key and secret, Binance would reject their requests. Together with read-only permissions, this makes a leaked key practically useless to an attacker.
If the service’s server IP ever changes, add the new IP to the same key. You don’t need a new key. Clearqo always shows the current IP in Dashboard → Binance.
Common mistakes to avoid
- Turning on extra permissions “just in case”. A payment service never needs them. If one asks for withdrawal or trading rights, stop and ask why.
- Leaving the key unrestricted. Without an IP restriction, the key works from anywhere in the world.
- Sharing the secret in chat or email. Paste it only into the service’s own settings page over HTTPS. A trustworthy service never asks for it any other way.
- Reusing one key everywhere. Create a separate key for each service. If you stop using a service, delete its key in API Management.
How to check or revoke a key later
Open API Management at any time to see each key’s label, permissions and IP restriction. Click Delete to revoke a key instantly. In Clearqo you can also click Disconnect key in the Binance tab. Payments then stop being verified until you connect a key again.
FAQ
Can a read-only API key withdraw my funds?
No. Without the withdrawal permission Binance rejects any withdrawal request made with that key, and Clearqo refuses keys that have it.
Does Clearqo see my balance?
Clearqo only requests the history it needs to confirm payments: incoming Binance Pay transactions, USDT deposits, and the key’s own permission settings. It never calls any endpoint that could move funds.
Should I choose “System generated” or “Self-generated”?
Choose System generated. It creates the standard key and secret pair that Clearqo uses.
What if I lose the secret key?
Delete the old key in API Management and create a new one with the same settings, then reconnect it in the dashboard.
Accept USDT on your website
Paid straight to your own Binance, verified automatically.