Skip to content

Security and API keys

How Coinrule stores your exchange API keys and what security practices to follow.

Updated 2026-05-29·2 min read

Coinrule stores your exchange API keys encrypted in Postgres using Fernet symmetric encryption — keys are decrypted only by the execution engine at runtime and are never logged or exposed via any API response. This article covers the credential storage model, supported authentication methods, and API key best practices.

How your credentials are stored

Exchange API keys and secrets are stored encrypted in Postgres using Fernet symmetric encryption. The encryption key is managed as an environment secret and is never stored alongside the credential data. Keys are decrypted by the execution engine at runtime for order placement and are never logged or returned via any API response.

Coinrule never stores your exchange password or 2FA codes — connection is always via API key or wallet signature.

Authentication

Coinrule uses Privy for authentication. Supported login methods:

  • Email + passcode (passwordless one-time code)
  • Google OAuth
  • Apple
  • MetaMask or another EVM wallet (used by DeFi / Hyperliquid users)

Session management

Sessions are managed by Privy. To sign out of all devices, sign out from Settings → Account → Sign out.

API key best practices

See API key permissions and security for guidance on scoping keys to minimum permissions, IP restrictions, and rotation schedule.

AI assistant (MCP) access

Connecting an AI assistant such as Claude or ChatGPT uses OAuth, not API keys — the assistant never sees your Coinrule password or your exchange keys, and you grant it read-only or read+write access that you can revoke any time from Settings → Integrations. See MCP scopes, permissions, and security.

Reporting a security issue

See Reporting a security issue.

Was this article helpful?

Coinrule

AI-powered trading automation. Your keys, your coins.
Backed by Y Combinator.

© 2026 Coinrule. All rights reserved.

No information here constitutes investment advice. Coinrule does not take any liability for rule performance. Trade at your own risk. Terms · Privacy

The services, products, and content available on coinrule.com are not intended for, directed at, or marketed to residents of the European Union (EU) or the European Economic Area (EEA). Coinrule does not hold a Crypto-Asset Service Provider (CASP) license under the EU Markets in Crypto-Assets (MiCA) regulation. Any access to our services by users residing within the EU/EEA is done solely at the user's own exclusive initiative and request (passive provision of services/reverse solicitation).