Verifying with CoinSpot
To verify a balance you hold on CoinSpot, you create a Read Only API key on CoinSpot and paste it into Scrya. An API key is a pair of codes that lets an app look at your account without your password. No funds move.
What permission to choose
CoinSpot offers two kinds of API key: Read Only and Full Access. Choose Read Only. Scrya only reads your balances, so that’s all it needs.
Never create a Full Access key for Scrya. Full Access keys can trade and move funds. Scrya doesn’t need that, and you shouldn’t give it to any verification service.
Create the key on CoinSpot
- Sign in at coinspot.com.au on the web.
- Select the My Account icon (top right), then API. You can also go straight to coinspot.com.au/my/api.
- Select Generate New API Key.
- Give the key a name you’ll recognise, such as “Scrya read-only”.
- Make sure API Key Type is set to Read Only.
- Enter your two-factor code and select Create API Key.
- CoinSpot emails you a link to confirm the new key. Open the email and click the link. You can’t copy the key until you do.
- Copy the API Key. Then select View Secret (One Time Only) and copy the secret. CoinSpot won’t show it again.
Use a new key just for Scrya. If another app, such as a tax tool, also uses the same key, CoinSpot can reject Scrya’s check.
Add the key in Scrya
- Open your verification request in Scrya and select Start Verification next to the asset.
- Choose Centralised exchange, then CoinSpot.
- Paste the key into API Key and the secret into API Secret. Select Show if you want to check nothing was cut off.
- Select Connect exchange.
Scrya encrypts the key and secret before storing them, then checks your balance straight away. It records only the balance of the asset you’re verifying. When the check succeeds you’ll see Monitoring progress, and you can select Close.
Verified with CoinSpot before? You can pick a saved key and select Reuse and verify instead.
Should I restrict the key to an IP address?
No. Leave any IP restriction off. Scrya’s checks don’t come from one fixed address, so there’s nothing you could add, and a key locked to certain addresses will be rejected when Scrya checks your balance.
Troubleshooting
- Invalid credentials (before anything is sent): the key or secret looks too short or contains characters exchange keys don’t use. Copy the full value again.
- Couldn’t connect to CoinSpot: CoinSpot refused the key. Check you clicked the confirmation link in CoinSpot’s email, copied both values in full, and chose Read Only. If the key is shared with another app, create a new one just for Scrya.
- Lost the secret? Delete the key on CoinSpot and create a new one.
- Something went wrong on our side: this one’s on us. Note the reference (ERR-XXXX-XXXX) and see Error references.
More help: Troubleshooting.
Revoke the key
Once your verification is complete, you can delete the key. Go back to coinspot.com.au/my/api, find the key you made for Scrya and delete it.
After that, Scrya can’t reuse the key for a future request, so you’d create a new one. If you made a key that failed to connect, delete that one too. Scrya deletes its own encrypted copy 30 days after your verification completes. See Revoking your API key.
