API keys
Connect your exchanges, wallets and brokers with read-only API keys so their balances sync automatically. Keys are stored encrypted and are write-only. Once saved they're never shown again; the app only shows whether a key is set. Banks connect differently, through a secure bank login with no keys to manage. See Bank connection setup.
How to use
- Create a read-only API key with your provider:
- Binance: enable only Reading.
- Coinbase: a read-only Advanced Trade key (enter the key name and its private key).
- Kraken: only the Query Funds permission.
- Bitstamp: only Account balance access.
- Bitvavo: only the View right.
- Bitpanda: any API key (Bitpanda's is read-only by nature).
- Bybit: a read-only key with Wallet and Earn read access.
- Zerion: a standard Zerion API key.
- Spiko: your investor API client ID and secret.
- Trading 212: a read-only key from the Trading 212 app.
- Interactive Brokers: a Flex Web Service token and Flex Query ID.
- Open Settings, go to Connected Sources, and add a connection. If the keys aren't set yet, the key fields appear right in the form, and saving stores them (encrypted) and creates the connection.
- Balances sync right after, so wrong keys show up immediately.
- To change or remove keys later, use the key button on the connection's card.
Import transactions (Kraken, Spiko)
Balance sync records quantity changes without knowing why they happened. For providers whose API exposes real events, switch the connection's toggle to Transactions mode on its card: pick a start date (leave it blank for all available history) and events become proper ledger rows instead of anonymous balance adjustments:
- Kraken, the account ledger: trades become real transactions (fees folded in), staking/Earn rewards become value-at-receipt adjustments tagged reward, spot↔Earn moves become transfers excluded from tax so their cost basis carries over, and deposits/withdrawals stay simple quantity changes.
- Spiko, orders and yield accruals: deposits and withdrawals move the position at their real dates, and every yield accrual lands as an adjustment tagged interest, valued in your base currency on its day.
Press Refresh on the card to fetch. Nothing posts to your ledger directly. Events land in the History → Review queue, where you keep, dismiss, merge or re-tag each row first. Events already staged are recognised (each sync remembers what it fetched, so re-running is safe), and events on positions you haven't linked yet show a "Link to holding…" box right in the queue.
Once in Transactions mode, new activity arrives on its own: the nightly job stages the connection's fresh events (rescanning a week back for safety) so trades and yields keep landing in Review without lifting a finger. If a connection can't update during that run (an expired key, a provider outage), you'll see a notice on your next visit and the details under Settings → Connected sources, so a silently broken key can't go unnoticed; the notice clears by itself on the next clean sync.
The result shows up everywhere: History shows real trades instead of "refresh" rows, the Tax tab gets accurate cost bases and pre-tagged income, and Kraken's key needs the extra Query Ledger Entries permission for the import (balances alone don't).
Good to know
- Never grant trade or withdrawal permissions. The app only ever reads balances, so a read-only key keeps your funds safe even if it leaks.
- Long histories import in chunks. One sync fetches up to ~1,000 Kraken ledger entries. Press Refresh again to continue further back.
- Keys are write-only. After saving they're never shown again; the app only tells you whether a key is set.
- Removing a key turns that connection's sync off until you add one again.
- A linked holding that drops to zero on the exchange (you sold it all, or moved it off) shows up in the review as a "No longer reported" row with a balance of 0, so you can see the pending zeroing and either keep the link (let the sync zero it) or clear it to stop tracking that line.
- Bank accounts don't use API keys. They connect through a secure bank login. See Bank connection setup.