Skip to content

Crypto.com Is Two Products, and Only One of Them Has API Keys

6 min read · Verified September 2026

Crypto.com is two separate products. API keys live on the Crypto.com Exchange under Settings, API Keys, where Can Read is on by default and Enable Trading stays off. The Crypto.com App holds a different account, and its balances will not import from an Exchange key. A read-only key cannot move funds.

You go looking for the API settings, find a help article describing Settings and an API Keys tab, open your phone, and none of it is there.

Nothing is broken. You are in the wrong product. Crypto.com runs a retail app and a separate trading exchange under one brand, with separate logins, separate balances and a transfer step between them. The tracker instructions you found were written for the Exchange. The account you actually use is probably the app.

This confusion is the single biggest reason Crypto.com users end up with an incomplete portfolio, so it is worth settling before anything else.

Which Crypto.com do I have?

The Crypto.com App is the retail product: buy and sell at a quoted price, Crypto Earn, the Visa card and its cashback, CRO staking for card tiers, recurring buys. If you signed up because of the card or because a friend sent you a referral link, this is what you have.

The Crypto.com Exchange is the order-book venue at a different domain, with maker and taker fees, a spot order book, derivatives in the regions where they are offered, and the API key screen. It has its own account, and moving assets between the two is an explicit internal transfer you perform yourself.

Plenty of people hold both without registering that they are separate. The app shows one total, the exchange shows another, and the tracker connected to one of them reports a number that is correct and incomplete at the same time. Why your exchange app and your tracker disagree covers the general shape of that mismatch; here it has a specific and very fixable cause.

One aside worth stating because the brand is so widely imitated: only ever reach the Exchange from a link you typed yourself or a bookmark you saved. Crypto.com's name appears on more fake apps and phishing domains than almost any other, and an API key handed to a convincing clone is a privacy loss even when it carries no trading permission. Spotting fake crypto apps covers the tells.

Exchange balances synced read-only, app balances added by hand, one total that finally matches.

How do I create a read-only key on the Crypto.com Exchange?

On the Exchange, open Settings and choose the API Keys tab, then create a new API key. Two-factor authentication has to be active on the account first; the create button will not do anything useful without it. Give the key a label naming the service you are connecting, and enter your 2FA code.

The permission model here is refreshingly small. Can Read is enabled by default and is the permission a portfolio tracker actually uses. Enable Trading is a separate switch and stays off, as does any withdrawal permission the Exchange offers your account. There is no situation in which a tracker needs either one. A key issued without them cannot place an order and cannot move funds, whatever any app claims, because the check runs on Crypto.com's side of the connection and the answer comes back as a refusal. You are relying on the exchange to hold a line you drew yourself on the exchange's own page, which is a cheaper kind of trust than believing an app. Read-only API keys explains the mechanism end to end.

Then the IP whitelist. The Exchange expects trusted addresses attached to a key, and every integration guide published by every third-party service tells you to paste in the addresses that service publishes. Do exactly that. Your tracker queries the Exchange from its own infrastructure, so entering your home address produces a key that authenticates correctly and gets refused every single time, with a failure that reads as a broken key rather than a wrong setting.

Copy the secret when it appears. The Exchange shows it once, and the recovery path for a lost secret is deleting the key and making another.

What is the Agent Key in the app, then?

If you went hunting through the app menu, you may have found something called an Agent Key under More. It is real, it is new, and it is not the thing you were looking for.

The Agent Key is an app-side credential built for AI agents acting on your account rather than for portfolio software reading it. Its permission set is unusual: access to portfolio balance is always enabled and cannot be switched off, while access to market data and the ability to execute trades are optional. It carries a weekly trading budget you set within a defined range, and by Crypto.com's own documentation it expires on a default 30-day term and also lapses after 30 days of inactivity, with warnings at seven days and one day out.

Two things follow. The permission that would matter to a tracker, reading your balance, is present. But the 30-day lifetime makes it unsuitable as a set-and-forget portfolio connection, and most trackers are not built to consume it. Treat it as a development to watch rather than a solution today, and check whether your app supports it before assuming it does.

What definitely will not import from an Exchange key?

Everything on the app side. That is the honest answer and it is a longer list than people expect.

Crypto Earn balances, card cashback in CRO, CRO staked for a card tier or fee discount, recurring buys executed in the app, and any holdings you simply left there after buying: an Exchange API key sees none of it, because none of it is in the Exchange account. The Crypto.com DeFi Wallet is further out still, being self-custody software with its own recovery phrase and no connection to either account.

The workable setup is a split one. Connect the Exchange read-only for the balances that sit there and update on their own. For the app side, export your transaction history from the app and enter the positions manually with their real acquisition prices, which keeps your cost basis honest instead of letting the tracker assume you got everything for free. Adding a manual position covers the entry, exporting your data covers getting the history out, and cost basis vs. market value explains why the acquisition price is the field worth being fussy about.

For locked CRO, record it as a manual position and note the date the lock term ends somewhere you will actually see it. Tracking staked and locked assets covers holdings that resist a clean balance read.

None of this requires you to trust the tracker with anything dangerous. A read-only key can answer questions about your Exchange account and nothing else. It cannot buy, it cannot sell, and it cannot send a coin anywhere, and if it ever leaked the exposure would be informational rather than financial. Is it safe to connect an exchange gives that risk its full weight without inflating it.

Do the split once and the Crypto.com number stops being the one you distrust. The thing to watch is the app side: if the Agent Key grows into a proper read-only portfolio credential with a sensible lifetime, the manual half of this setup disappears, and the two halves of Crypto.com finally report as one account.

Common questions

The retail app has never offered a conventional read-only API key of the kind trackers use for exchanges. If you only use the app, your route into a tracker is a CSV export plus manual positions, not a key. The API key screen you have read about belongs to the Crypto.com Exchange, which is a different account.

No, and you should not move funds for a bookkeeping reason. Transfers between the two are a trading decision. Record app holdings as manual positions instead, which keeps your real acquisition price intact and costs you nothing.

It is a newer app-side credential aimed at AI agents rather than portfolio trackers. It carries a portfolio balance permission that is always on, optional trading and market data permissions, a weekly spending budget, and a default 30-day lifetime. Most trackers do not consume it, so check before assuming it substitutes for an Exchange key.

Usually not as an ordinary balance. CRO staked for card tiers or fee discounts is locked for a term and reported separately from spendable holdings, so it tends to need a manual entry if you want it counted in your total.

In practice, yes. The Exchange expects trusted addresses on an API key and every integration guide instructs you to paste in the service's published server addresses. Use theirs, not your home address, because the requests originate from the tracker's servers.

Unlimited manual positions on the free tier, read-only connections across 100+ exchanges, and a cost basis that survives the app-to-exchange split.

Keep reading

← All guides