Guide
Where do crypto-bot API keys and funds live?
“Non-custodial” hides four questions: where your funds sit, where your exchange key sits, whether the tool can trade, and whether it can withdraw.
Four controls, by kind of product
| Kind | Funds | Exchange key | Can trade | Can withdraw |
|---|---|---|---|---|
| Cloud bot software | Your exchange account | Stored by the provider | Yes | No, with a trade-only key |
| Self-hosted software | Your exchange account | On your own machine | Yes | Depends on the key you create |
| Bots built into an exchange | Held by the exchange | None needed | Yes, the exchange executes | Not applicable |
| Copy trading | Held by the exchange | None needed | Yes, copying the lead trader | Not applicable |
| Fygga (paper only) | None held | Never asked for | No; places no orders | No; never connects to your exchange |
The summary above is the pattern across the twelve products read. Each product’s own answer is below.
No withdrawal permission is not no risk
A trade-only key cannot move funds out of your account, but it can still place trades in it. A key stored by a provider is only as safe as that provider’s systems: in late December 2022, 3Commas’ CEO confirmed a leak of users’ API keys (Cointelegraph). Habits that follow from the four controls:
- One key per tool, so one can be revoked without touching the others.
- Trading permission only. Never enable withdrawals for a bot.
- Revoke keys you no longer use, including after a platform migration. When 3Commas moved to v2 in September 2026, keys did not carry over.
Product by product
Prices checked 2 Oct 2026 on the providers’ own pages.
| Product | Funds | Exchange key | Can withdraw |
|---|---|---|---|
| 3CommasStarter | Your exchange account | Stored by the provider | No (trade-only key) |
| CryptohopperExplorer | Your exchange account | Stored by the provider, encrypted | No |
| BitsgapBasic | Your exchange account | Stored by the provider, encrypted | No (trade-only key) |
| CoinruleInvestor | Your exchange account | Stored by the provider, encrypted per user | No |
| KryllOSWhole product | Your exchange account | On your own machine | Depends on the key you create |
| Pionex built-in botsGrid, DCA, futures and other built-in bots | Held by the exchange | None needed; runs inside your exchange account | Not applicable; funds stay with the exchange |
| Binance Trading BotsSpot Grid (product page) | Held by the exchange | None needed; runs inside your exchange account | Not applicable; funds stay with the exchange |
| OKX Trading BotsSmart Portfolio, Recurring Buy, Spot Grid, Futures Grid | Held by the exchange | None for built-in bots; a custom API route uses keys you create | Not applicable; funds stay with the exchange |
| Bybit Trading BotsSpot and Futures Grid, DCA, Futures Martingale | Held by the exchange | None needed; runs inside your exchange account | Not applicable; funds stay with the exchange |
| Binance Spot Copy TradingSpot Copy Trading | Held by the exchange | None needed; runs inside your exchange account | Not applicable; funds stay with the exchange |
| OKX Copy TradingCopy Trading | Held by the exchange | None needed; runs inside your exchange account | Not applicable; funds stay with the exchange |
| Bybit Copy TradingClassic Copy Trading | Held by the exchange | None needed; runs inside your exchange account | Not applicable; funds stay with the exchange |
Custody and key models were read on the providers’ pages between 19 September and 2 October 2026; each row’s date is in the full data (CC BY 4.0).
Educational only — not financial advice, and not a recommendation of any product.