How exchange verification works
If the crypto you’ve been asked to verify is held on an exchange, you prove your balance by connecting a read-only API key. Scrya uses the key to read your balance straight from the exchange. No funds move, and you never share your exchange password.
What’s a read-only API key?
An API key is a set of codes your exchange creates so an app can use your account without your password. It’s usually a key and a secret. OKX adds a third part, a passphrase you choose.
When you create a key, you choose what it’s allowed to do. A read-only key can look at your balances but can’t trade, withdraw or transfer. That’s all Scrya needs.
Never give Scrya a key that can trade, withdraw or transfer. Scrya only ever reads your balance, and choosing read-only is what keeps your account safe. Each exchange guide shows exactly what to tick.
Verify an exchange balance, step by step
- In your portal, find the asset you’ve been asked to verify and click Start Verification.
- Under How would you like to verify your …?, choose Centralised exchange.
- Under Which exchange holds your …?, pick your exchange.
- Follow the Setup Instructions: to create a read-only key. Your exchange guide has more detail.
- Paste the values into API Key and API Secret, plus Passphrase for OKX. The fields show what you paste so you can check nothing was cut off. Click Hide if someone can see your screen.
- Click Connect exchange.
Scrya checks your balance straight away. When it succeeds you’ll see Exchange Connected, then Verified with your Verified balance. Click Close.
What Scrya does with your key
- It checks once, when you connect. Scrya’s servers use the key to ask your exchange for your balances, then record the balance of the asset you’re verifying. Where a price is available, Scrya also notes its approximate US dollar value at that moment. It doesn’t keep checking afterwards.
- It only reads. Scrya never places orders, moves funds or changes your settings.
- It records what it finds, even zero. The business that asked sees the balance Scrya read, so connect the account that actually holds the asset.
- It reads some wallets, not all. Exchanges often split an account into spot, funding, earn and other wallets. Scrya reads only the ones your exchange guide lists, and only for the account the key was created on.
- Stablecoins have one balance. An exchange holds one USDT or USDC balance per account, not one per network, so your request’s network doesn’t matter here.
How your key is stored
- Your key, secret and passphrase are encrypted (AES-256) before they’re saved. They’re only decrypted on Scrya’s servers when a balance check runs.
- Scrya never shows your key or secret again after you submit them.
- Scrya keeps the encrypted copy so you can reuse it. Next time you verify on the same exchange, you may see Use a saved API key or add a new one. Pick the saved key and click Reuse and verify to run a fresh balance check.
- Scrya deletes its encrypted copy 30 days after your verification completes.
Should I restrict my key to an IP address?
No. Leave any IP restriction off. Scrya’s checks don’t come from one fixed address, so there’s nothing you could add. If the key only works from certain addresses, your exchange rejects Scrya’s check, and Scrya asks you to remove the restriction or create a new key without one.
Troubleshooting
- Invalid credentials: Scrya spotted a problem before contacting your exchange. A value looks too short or too long, or contains characters keys don’t use. Copy it again.
- Couldn’t connect to [your exchange]: your exchange refused the key. The message underneath says what to fix. Usually part of a value is missing, the key has no read access, or it’s restricted to certain IP addresses.
- Balance lower than expected: the asset may be in a wallet or sub-account Scrya doesn’t read. Check your exchange guide.
- Something went wrong on our side: this one’s on us. Note the reference (ERR-XXXX-XXXX) and see Error references.
More help: Troubleshooting.
Once you see Verified, you can delete the key on your exchange. See Revoking your API key.
