01

What you are doing

You are creating an API key from the dedicated Standard Subaccount so HEDGERON can read account state and place derivative orders.

02

Why it matters

Minimum permissions limit what the integration can do. HEDGERON never needs withdrawal access and refuses credentials that expose it.

03

Before you start

Bybit currently requires API-key creation on its website, not the mobile app. New accounts may have a temporary 48-hour API-creation restriction.

04

Step by step

  1. 01Switch into the dedicated Standard Subaccount and open API Management on the official Bybit website.
  2. 02Create a new personal API key and give it a clear HEDGERON label.
  3. 03Enable read/write trading access, including ContractTrade Order and Position.
  4. 04Leave Wallet Withdraw and every unrelated sensitive permission disabled.
  5. 05If HEDGERON provides a fixed outbound IP, apply that whitelist exactly.
  6. 06Complete Bybit 2FA, copy the key and secret once, and connect them directly in HEDGERON.
05

What you should see

The key is not read-only, belongs to the Standard Subaccount, includes Contract Order and Position, and does not include Withdraw.

06

Security check

SECURITY CHECK FAILED means the credentials will not be stored. Create a dedicated Standard Subaccount key with trading permissions only. HEDGERON will never accept withdrawal access.

07

Common problems

API creation is unavailable

Wait for the restriction period shown by Bybit instead of repeatedly changing account security.

HEDGERON says the key cannot trade

Enable the required Contract Order and Position permissions.

HEDGERON says the key is unsafe

The key is from a Main Account, has Withdraw or includes permissions outside the HEDGERON allowlist. Recreate it.

08

Next step

Create your HEDGERON account and connect the key only through the official domain.

Official sources

Exchange interfaces and rules can change. Verify the current official source before acting.

www.bybit.com bybit-exchange.github.io