Guide

Where do crypto-bot API keys and funds live?

“Non-custodial” hides four questions: where your funds sit, where your exchange key sits, whether the tool can trade, and whether it can withdraw.

Four controls, by kind of product

KindFundsExchange keyCan tradeCan withdraw
Cloud bot softwareYour exchange accountStored by the providerYesNo, with a trade-only key
Self-hosted softwareYour exchange accountOn your own machineYesDepends on the key you create
Bots built into an exchangeHeld by the exchangeNone neededYes, the exchange executesNot applicable
Copy tradingHeld by the exchangeNone neededYes, copying the lead traderNot applicable
Fygga (paper only)None heldNever asked forNo; places no ordersNo; never connects to your exchange

The summary above is the pattern across the twelve products read. Each product’s own answer is below.

No withdrawal permission is not no risk

A trade-only key cannot move funds out of your account, but it can still place trades in it. A key stored by a provider is only as safe as that provider’s systems: in late December 2022, 3Commas’ CEO confirmed a leak of users’ API keys (Cointelegraph). Habits that follow from the four controls:

  • One key per tool, so one can be revoked without touching the others.
  • Trading permission only. Never enable withdrawals for a bot.
  • Revoke keys you no longer use, including after a platform migration. When 3Commas moved to v2 in September 2026, keys did not carry over.

Product by product

Prices checked 2 Oct 2026 on the providers’ own pages.

ProductFundsExchange keyCan withdraw
3CommasStarterYour exchange accountStored by the providerNo (trade-only key)
CryptohopperExplorerYour exchange accountStored by the provider, encryptedNo
BitsgapBasicYour exchange accountStored by the provider, encryptedNo (trade-only key)
CoinruleInvestorYour exchange accountStored by the provider, encrypted per userNo
KryllOSWhole productYour exchange accountOn your own machineDepends on the key you create
Pionex built-in botsGrid, DCA, futures and other built-in botsHeld by the exchangeNone needed; runs inside your exchange accountNot applicable; funds stay with the exchange
Binance Trading BotsSpot Grid (product page)Held by the exchangeNone needed; runs inside your exchange accountNot applicable; funds stay with the exchange
OKX Trading BotsSmart Portfolio, Recurring Buy, Spot Grid, Futures GridHeld by the exchangeNone for built-in bots; a custom API route uses keys you createNot applicable; funds stay with the exchange
Bybit Trading BotsSpot and Futures Grid, DCA, Futures MartingaleHeld by the exchangeNone needed; runs inside your exchange accountNot applicable; funds stay with the exchange
Binance Spot Copy TradingSpot Copy TradingHeld by the exchangeNone needed; runs inside your exchange accountNot applicable; funds stay with the exchange
OKX Copy TradingCopy TradingHeld by the exchangeNone needed; runs inside your exchange accountNot applicable; funds stay with the exchange
Bybit Copy TradingClassic Copy TradingHeld by the exchangeNone needed; runs inside your exchange accountNot applicable; funds stay with the exchange

Custody and key models were read on the providers’ pages between 19 September and 2 October 2026; each row’s date is in the full data (CC BY 4.0).

Educational only — not financial advice, and not a recommendation of any product.

More guides