5 min read · Last updated 2026-06-25
Security Model & API Access
How Muckard handles exchange API keys, non-custodial architecture, and steps you should take to protect your account.
Non-custodial by design
Muckard never holds your cryptocurrency. Balances and positions remain in your exchange account under your exchange's terms and security practices.
Our role is to send trading instructions through the API you authorize. If you disconnect the API or delete the key on the exchange, Muckard cannot move funds.
API key permissions
When creating an API key on your exchange, enable only what is required for automated trading — typically read access and trade/order placement. Do not enable withdrawal, transfer, or funding permissions for keys linked to Muckard or any similar service.
Review your exchange's documentation for IP allowlisting or key expiration options if available. Rotate keys if you suspect compromise.
- Trading permission: as required by your setup
- Withdrawal permission: off
- Store keys securely; never share them in chat or email
Platform security practices
We use industry-standard practices to protect account data and stored API credentials, as described in our Privacy Policy. No online system can guarantee absolute security — you share responsibility for securing your exchange account, email, and two-factor authentication.
If something goes wrong
Revoke the API key immediately on your exchange if you notice unauthorized activity. Contact [email protected] for platform support and your exchange for account-level incidents.