API keys vs agents

API-key trading bots versus Hyperliquid agent approvals

The traditional way to let software trade for you is an exchange API key. It works, but the permission model is coarse, off-chain, and only as trustworthy as the key's storage.

In short

An API key is an off-chain credential whose scope depends on the exchange's settings and the operator's honesty in requesting them; a leaked key with withdrawal scope can drain an account. A Hyperliquid agent approval is an on-chain authorisation limited to trading actions by protocol design, and it is revocable directly from your wallet.

At a glance

API-key bots vs Hyperliquid agent approvals
DimensionAPI-key botHyperMirror
Credential sharedExchange API key held off-chainOn-chain agent approval, no key sharing
Scope of permissionDepends on key flags set by youTrade-only at protocol level
Withdrawal riskPresent if withdrawal scope enabledStructurally impossible
RevocationDelete key in exchange settingsOn-chain revoke from your wallet
VerifiabilityOperator-reportedPublic on-chain fills and positions

Scope you can verify versus scope you are told

With API keys, you choose scopes in an exchange dashboard and then trust that both the exchange and the bot respect them. Whether withdrawal permission was requested, and whether the key is stored encrypted, is not something you can independently confirm.

An agent approval's scope is enforced by the protocol: order actions are signable, transfers are not. There is no configuration mistake that turns a trading agent into a withdrawal credential.

Revocation and key hygiene

Revoking an API key means logging into the exchange and hoping the bot has not already acted. Agent revocation is a signed action from your own wallet that takes effect at the protocol level.

  • Never grant withdrawal scope to a trading bot, on any venue.
  • Rotate credentials after any suspected exposure.
  • Prefer permissions whose limits are enforced by the venue, not by the integrator.
  • Confirm what happens to open positions when access is revoked before you need to know.

Where API-key bots still make sense

Cross-venue strategies need credentials on venues that have no agent model at all. If your strategy spans several exchanges, API keys are unavoidable — the mitigation is strict scope and disciplined rotation, not avoidance.

Risk statement

A safer permission model does not make a strategy profitable. Any automated system can place losing trades, and leveraged positions can be liquidated.

Past performance is not indicative of future results. Perpetual futures are leveraged instruments and carry a substantial risk of loss, including the loss of your entire position.

Questions

Frequently asked

Does HyperMirror ever ask for an API key?

No. Access is granted through Hyperliquid's native agent approval and a separate builder-fee approval.

Can I revoke access instantly?

Yes, from your own wallet, without our involvement.

What happens to open positions after revocation?

They stay in your account and become yours to manage or close.

Diversified copy trading. On autopilot.

Score-weighted allocation across up to 10 elite Hyperliquid traders, each isolated in its own sub-account. Your funds never leave your account.

Non-custodial · Agent cannot withdraw · Cancel delegation anytime