CryptoBoost AI

What permissions does a Hyperliquid trading bot need?

A trading bot on Hyperliquid needs permission to trade, and nothing more. This guide explains what that permission covers, what no bot should ever ask for, and how to check and revoke access yourself.

[ Security ] Published 6 min read

The two permissions a bot can ask for

Hyperliquid lets you give an app limited access to your account without handing over your wallet. There are two kinds of approval, and each is signed once by your own wallet.

1. API wallet — permission to trade

An API wallet is a separate key that the bot holds. When you approve it, Hyperliquid accepts trading actions signed by that key as if they came from your account. This is the only permission a trading bot needs to run.

Hyperliquid's own API page says API wallets "can perform actions on behalf of an account without having withdrawal permissions."

2. Builder fee — permission to charge a fee on orders

A builder fee approval lets an app add a small fee to the orders it sends for you. You approve a maximum rate, and Hyperliquid caps it at 0.1% on perps and 1% on spot. It does not let the app trade or move funds. Not every bot uses one.

What an API wallet can and cannot do

An API wallet can

  • Place, modify and cancel orders, including TWAP orders
  • Open and close positions on any market
  • Change leverage and add or remove isolated margin
  • Move collateral between balances inside your own account

An API wallet cannot

  • Withdraw funds from Hyperliquid
  • Send USDC or tokens to another address
  • Approve other API wallets or builder fees
  • Stake, delegate, or move funds into vaults

These limits are enforced by Hyperliquid, not by the bot. Withdrawals, transfers to other addresses and new approvals must all be signed by your own wallet, and Hyperliquid rejects them from an API wallet.

What the permission does not limit

An API wallet is all-or-nothing for trading. Hyperliquid does not let you restrict it to one market, one position size or one strategy. Any such limits are rules in the bot's own software.

The main risk is not theft. It is unwanted trading. If a bot's key leaked or the bot misbehaved, it could open losing trades or raise leverage on your account. It still could not take your funds out.

To keep that risk small:

  • Use a dedicated wallet for bot trading and keep only the capital you want the bot to trade in it.
  • Prefer an expiry date. An API wallet can be approved with an expiry up to 180 days ahead. After that, it stops working until you approve again.
  • Remove approvals you no longer use. An old API wallet from a bot you stopped using is still active until it expires or you remove it.

What a bot should never ask for

No legitimate Hyperliquid bot needs any of the following. If one asks, do not continue.

  • Your seed phrase or private key, in any form, including "importing" your wallet into their site.
  • A deposit to the bot's own address. A non-custodial bot trades in your account, so your funds never need to leave it.
  • A signature for a withdrawal or transfer during setup. Setup should only ask you to approve an API wallet, and possibly a builder fee.
  • A signature you do not understand. Read what your wallet shows before signing. An API wallet approval names the API wallet address it authorises.

How to check which bots have access

  1. Open the API page. Go to app.hyperliquid.xyz/API, or choose More → API in the Hyperliquid app, and connect the wallet you trade with.
  2. Review the list. The table shows each API wallet's name, address and Valid Until date. Match the address with the one shown in your bot's settings.
  3. Check builder fees. Open app.hyperliquid.xyz/builderCodes (More → Builder Codes) to see which apps can charge a fee on your orders.

If you see an API wallet you don't recognise, remove it straight away.

How to revoke a bot's access

  1. Stop the bot in its own app first, if you can. That lets it finish or cancel what it was doing cleanly.
  2. Remove the API wallet. On the API page, use the button in the Action column next to the API wallet and confirm in your wallet. From then on, Hyperliquid rejects anything that API wallet signs.
  3. Remove any builder fee approval for that app on the Builder Codes page.
  4. Review your positions and open orders. Revoking stops new actions, but positions and orders already on the book stay in your account. Close or cancel what you no longer want.

How CryptoBoost uses these permissions

CryptoBoost trades through an API wallet that you approve from your own Hyperliquid account, and it only trades BTC perpetuals. It never asks for your seed phrase or private key, and your funds never leave your account. For the details, read what permissions CryptoBoost gets on your Hyperliquid wallet.

Common questions

Can a Hyperliquid API wallet withdraw my funds?

No. Withdrawals and transfers to other addresses must be signed by your own wallet. Hyperliquid does not accept them from an API wallet.

Do Hyperliquid API wallets expire?

They can. An API wallet can be approved with an expiry date up to 180 days ahead, shown in the Valid Until column of the API page. Some are approved without one and stay active until you remove them.

How many bots can I connect to one Hyperliquid account?

An account can have one unnamed API wallet and up to three named ones, plus two named API wallets per sub-account. Approving a new unnamed API wallet replaces the old unnamed one.

What happens to my open trades when I revoke a bot?

Revoking stops the bot from sending new actions. Positions and any orders already on the book stay in your account, so review them and close or cancel what you no longer want.

Is a builder fee approval the same as an API wallet?

No. A builder fee approval only lets an app add a capped fee to orders it sends for you: at most 0.1% on perps and 1% on spot. It cannot place trades or move funds, and you can remove it on Hyperliquid's Builder Codes page.

Sources

Keep your keys.
Let the bot trade.

Activate your AI →

Perpetual futures carry substantial risk of loss · This article is general information, not financial advice