Connection checks
Before connecting an account, what may this credential do?
Write down the exact account and permitted operations. Reading, trading and moving funds are separate capabilities that require separate checks.
Write down the exact account and permitted operations. Reading, trading and moving funds are separate capabilities that require separate checks.
Start with the task you want the connection to perform, then inspect the provider's permission names for the exact account. A login that works is evidence of authentication. It is not evidence that the application should receive every operation the provider offers. The portal login, the account credential and the accepted trading plan serve different purposes.
Translate permission names into actions
cTrader's authorization documentation distinguishes accounts, which permits viewing account information, from trading, which also permits allowed trading operations. Kraken lists separate permissions for querying open or closed trades, creating or modifying orders, closing orders and withdrawing funds. Permission names and account selection must be read in the current provider interface; a label from another venue is not an equivalent grant.
Use a permission inventory
- Record the provider, account environment and exact account reference in the protected workspace. State whether the connection is intended only to read, or is being considered for separately approved trading.
- List each permitted operation and why it is needed. Include the scope of history and balance access, not just whether the key can send an order.
- Check whether the credential can reach other accounts or funding operations. Do not add withdrawal, account-management or broad shell access to make a read-only check work.
- Record the credential's expiry and the approved revocation or rotation procedure. Keep the value in its dedicated secure credential boundary, never in a proposal, recording or support attachment.
- After a change, obtain fresh account and permission evidence. A previous badge or successful response does not carry authority into a changed credential generation.
Read-only still has a privacy scope
Read permission can expose sensitive financial records. Kraken's current funding documentation explains that newer read-only funding endpoints give Query Funds access to more information than certain legacy endpoints. Review what a service can see as well as what it can change. Store only the evidence needed for the approved connection and keep another customer's account outside its scope.
Plan revocation before activation
Decide how you will stop new application actions, revoke a credential at its issuer and confirm the changed authority. These are distinct tasks. Removing access does not prove that existing positions closed or that protective orders disappeared. Inspect account state through an authorized path; do not request a trading or withdrawal permission merely to obtain a green status.
Source check · 5 October 2026
Scopes: https://help.ctrader.com/open-api/account-authentication/ . Permission inventory: https://docs.kraken.com/api-reference/account-data/get-api-key-info . Read visibility changes: https://support.kraken.com/in/articles/funding-api-v1 . The inventory and revocation checklist are TradeTwin editorial guidance; actual issuer settings remain authoritative.
Questions worth asking
Does read-only access mean the data is public?
No. Read-only limits changes, not sensitivity. Account history and funding information still need a defined private scope and approved handling.
Does approving a strategy also approve a broader credential?
No. Exact plan consent, credential scope, current account authority and protection readiness are separate checks. A broader credential requires its own deliberate decision.
Primary documentation for further reading
- cTrader account authorization scopes
- Kraken API key permission information
- Kraken current funding permission changes
API documentation describes the provider's interface. It does not certify your account or TradeTwin connector as ready to trade.