Creating a Kraken API key safely
BotDaddy LIFE's self-serve Kraken connection isn't switched on yet — from your account, connection management is still marked "coming soon." Everything below is accurate today and is exactly what you'll do once it opens up, so feel free to read ahead — or even create the key now and keep it somewhere safe until the connection screen is live.
BotDaddy LIFE connects to your Kraken account using an API key you create — not a username and password. This means BotDaddy never sees your Kraken login credentials, and the key you create can be limited to exactly the permissions it needs.
Step by step
- Log in to your Kraken account and go to Settings → API.
- Click Add key to create a new API key.
- Grant exactly these permissions: Query Funds, Query Open Orders & Trades, Query Closed Orders & Trades, Create & Modify Orders, Cancel/Close Orders.
- Leave "Withdraw Funds" unchecked. This is the single most important step. With this permission off, BotDaddy — or anyone who somehow obtained your key — could never move funds out of your Kraken account, only place trades within it.
- Kraken will show you the API Key and Private Key once. Copy both somewhere safe right away — Kraken will not show the private key again if you navigate away. Once BotDaddy's connection screen is live, this is what you'll paste in to connect your account.
Common mistakes
- Granting Withdraw permission "just in case." Don't. BotDaddy never needs it, and leaving it off is what makes this connection safe by design, not just by policy.
- Losing the private key before saving it. If this happens, don't worry — just revoke that key on Kraken and generate a new one. Nothing is lost except needing to repeat the setup step.
- Using an existing API key from another tool. Always create a fresh, dedicated key for BotDaddy so you can track and revoke its access independently from anything else connected to your account.
Troubleshooting
- "Connection failed" or "Invalid credentials": double-check you copied the full key and secret with no extra spaces, and confirm the key hasn't been deleted or expired on Kraken's side.
- "Insufficient permissions": go back to Kraken's API settings and confirm all 5 permissions above are checked (except Withdraw).
- Want to disconnect BotDaddy entirely? Simply revoke or delete the API key from Kraken's own API settings page at any time — this immediately and completely cuts off BotDaddy's access, independent of anything on the BotDaddy side.
For full setup detail beyond this page, see the Visitor Guide.
Open the Guide (PDF)