Security and API Keys
API key permissions, device security and risk management are critical topics for Sentralyx users. This page explains general security considerations without making unsupported claims.
Desktop application model
Sentralyx is described as a desktop trading terminal. The user runs the application on their own device and configures exchange connection settings through their own account.
API key scope
API keys should be created with only the necessary permissions. Withdrawal permission should not be enabled. It is the user's responsibility to verify the permissions on their exchange account.
Local execution
According to the product documentation, Sentralyx runs locally on the user's machine. Users are responsible for securing their device, access credentials and files.
User responsibilities
- Do not grant withdrawal permission to API keys
- Disable unnecessary permissions
- Monitor stop loss and risk limits
- Do not interpret backtest results as a guarantee of live trading performance
Security settings should be evaluated together with the exchange account, device and user preferences.