Skip to content

How to Track a Gemini Account Without Giving It Trading Access

6 min read · Verified September 2026

Gemini issues API keys with one role attached rather than a list of checkboxes. Choose Auditor, the read-only role, at Settings then API on the Gemini exchange site, and scope the key to the account you want visible. Auditor can read balances and history but cannot trade or withdraw. Unused keys expire after 180 days.

Gemini's API settings look different from every other exchange you have connected, and the difference stops people cold in the first thirty seconds. There are no permission checkboxes. There is a dropdown with three roles, and you pick exactly one.

Once you know what the three roles mean, that design is arguably clearer than the checkbox model. It is just unfamiliar, and unfamiliar is where mistakes happen.

Which Gemini role do I pick, and why is it not a checkbox list?

Gemini attaches a single role to each key: Auditor, Trading, or Fund Management. Auditor is the read-only one. It queries balances, order status, transfer history, active orders, past trades and trade volume. That is the entire list. It cannot place an order, cannot cancel one, cannot generate a deposit address and cannot send a withdrawal, because deposits and withdrawals belong to Fund Management, a role no tracker has any business holding.

The roles are exclusive rather than additive. A key is not "Auditor plus Trading." It is one thing, chosen at creation, and a key issued as Auditor can never be promoted afterwards. That is a genuine security property, not a limitation. A read-only key cannot move funds, and on Gemini the exchange enforces that at the role level before your request is ever evaluated. The broader mechanics are covered in read-only API keys, and the honest answer to the underlying worry is in is it safe to connect an exchange.

Leave trading off. Leave fund management off. Auditor is the whole job.

An Auditor key is read-only by design. Paste it once and your Gemini balances appear alongside everything else you hold.

Should the key cover one Gemini account or the whole group?

The second dropdown asks for scope, and this one catches people who assume a Gemini login means a Gemini account. It does not. A single login can hold several accounts, and the key you create reads one of them or all of them.

Most people have one account, called Primary, and scoping the key to Primary is correct. Anyone who has opened extra accounts to separate long-term holdings from active trading has more than one, and a Primary-scoped key will report a total that is honestly too low. Outside the US, derivatives sub-accounts add another layer.

Scoping to Master covers every account in the group. Master sounds alarming, and in combination with Fund Management it genuinely is, since a Master key with fund management rights can create accounts and move balances between them. Master combined with Auditor is not alarming at all: the role still governs what the key can do, and Auditor cannot move anything anywhere. If you hold across several Gemini accounts, Master plus Auditor is the correct choice and the safe one.

If you are not sure how many accounts you have, check before you create the key. A missing account is the most common reason a Gemini total looks wrong, and it belongs on the same list as every other cause in why your portfolio balance is wrong.

Why did my Gemini key stop working after a few months?

Because Gemini expires keys that go unused for 180 days.

This is the Gemini quirk worth writing on a sticky note. Most exchanges leave a key alive until you delete it. Gemini does not. A key wired into a tracker that syncs several times a day will never come close to the threshold. A key you created during a comparison, tested once, and left sitting in a password manager will be dead six months later, and there is no reactivation flow. You create a new one.

The other timing detail is Trusted IPs. Gemini added the ability to restrict a key to a set of allowed addresses, and from June 2025 it began blocking Trading keys that had not been affirmed either with specific IPs or as explicitly unrestricted. That enforcement applied to Trading keys, so an Auditor key is not caught by it. You can still set Trusted IPs on a read-only key if you want the belt as well as the braces, but be careful what you enter. Your tracker queries Gemini from its own servers, not from your phone. Entering your home address silently blocks every sync and produces a connection that looks broken for no visible reason.

What shows up, and what shows up that you did not expect?

Two surprises, running in opposite directions.

Staking runs first. Gemini's staking products hold assets in a state that is not a plain spot balance, and whether they resolve automatically depends on the key's scope and how the tracker reads the account. Compare the staked figure Gemini shows you against the total in your tracker before you conclude anything. If a staked position never appears, enter it by hand rather than living with a wrong number; tracking staked assets covers the general pattern, and adding a manual position covers the mechanics.

The second surprise runs the other way. If you hold the Gemini credit card, your rewards arrive as crypto, in small amounts, continuously, with no purchase attached. Those are real holdings and they belong in your total. They also produce a long tail of tiny acquisitions at scattered prices, which can make the cost basis on a position look nonsensical until you understand where it came from. Cost basis vs. market value explains how the two numbers diverge.

One historical note, because people still ask: Gemini Earn is finished. There is no Earn balance to import and no API surface to read it from. Anything you are still owed from that programme is a claims matter, not a tracking one.

How do I actually set this up?

  1. Sign in on the Gemini exchange site. Open Settings, then API. Key creation is a web flow; do it on a desktop where you can see the dropdowns clearly.
  2. Create a new key and choose the scope first. One account if everything you hold sits in Primary, Master if you hold across several accounts in the group.
  3. Set the role to Auditor. Confirm the screen says Auditor before you continue. This is the single decision that determines whether the key can touch your funds, and it cannot be changed afterwards.
  4. Decide on Trusted IPs. Unrestricted is fine for an Auditor key. If you restrict, use the address your tracker publishes, never your own.
  5. Copy the key and the secret immediately. The secret is displayed once. Store it the way you store passwords, not in a note or a message to yourself.
  6. Paste both into the tracker and let the first sync finish, then compare the total against what Gemini shows. Chase any gap now, while you still remember what you ticked.

The whole thing takes about four minutes, and the reason to do it properly the first time is that the failure modes are silent. A key with the wrong scope does not throw an error, it just reports a smaller number, forever, until someone notices.

When you have Gemini connected, the useful next step is not another exchange. It is deciding what should reach you when a position moves, so you are not checking a balance you already know. That is a different setup, and it takes about as long.

Common questions

Auditor can read balances, order status, transfer history and past trades, and nothing else. Trading adds the ability to place and cancel orders. The roles are exclusive, so a key is one or the other, and an Auditor key can never gain trading rights later. For tracking, Auditor is the only role you need.

The affirmation deadline that began blocking unaffirmed keys applied to Trading keys. Auditor keys can still use Trusted IPs if you want the extra restriction. If you set one, the address must be the one your tracker publishes, not your home connection, because the request comes from the tracker's servers.

Gemini expires API keys that go unused for 180 days. A key connected to a tracker that syncs regularly stays alive. A key you created, tested once and forgot about will be dead the next time you look. Create a new one and reconnect; there is nothing to recover.

Staked assets sit in a different state from spot balances, and how they surface depends on what the key is scoped to read. Check the staked amount against the figure Gemini shows you before assuming it is missing, and add the difference as a manual position if it never resolves.

Yes, and you should use a separate Auditor key for each. Keys are free to create, revoking one does not affect the other, and if a key ever leaks you know immediately which service leaked it.

Usually credit card rewards. Gemini's card pays out in crypto, which arrives as a stream of tiny deposits with no matching purchase. They are real holdings, but they will inflate your transaction count and can make cost basis look strange until you account for them.

Read-only connections across 100+ exchanges and 15+ chains, with trading and withdrawal permissions never requested.

Keep reading

← All guides