Automated Bybit API Key Auditing
Every Monday, WebRun signs in to Bybit, opens the API management page for the main account and each sub-account, reads every key's permissions, IP allowlist and expiry date, flags keys with more permission than they need or no IP restriction, sends the audit to your WhatsApp, and texts you about anything expiring this week.
How do I audit my exchange API keys for over-broad permissions?
WebRun audits your Bybit API keys every Monday. It opens API management for the main account and each sub-account, reads every key's permissions, IP allowlist and expiry date, flags over-broad or unrestricted keys, sends the audit to WhatsApp, and texts you about anything expiring within a week.
- Keys carrying more permission than they need are named every week
- A key never dies mid-job: expiry is texted seven days ahead
- Unrestricted keys surface before one leaks
Built for crypto traders · trading desks · quant developers · account owners
What does WebRun do on every run?
The exact actions WebRun takes, in order - in plain language, so you can adjust anything.
-
WebRun signs in and gets to work
Opens
www.bybit.comin a real browser with your saved login - no setup, no API keys. -
1
Bybit - audit every API key
- Sign in to Bybit and open API management for the main account and each sub-account
- List every key with its label, permissions, IP allowlist, and expiry date
- Flag keys carrying withdrawal or trade permission they do not need for their stated job
- Flag keys with no IP restriction and keys expiring within thirty days
Done when Every API key has a permission verdict, an IP restriction verdict, and days to expiry.
-
2
WhatsApp - send the audit
WebRun opens WhatsApp to send the audit. - Send the audit to your own chat, grouped by account and sub-account
- Put keys with withdrawal permission and no IP allowlist at the top
- Name the exact change each key needs so the fix takes seconds
Done when You have this week's key audit in WhatsApp.
-
3
Twilio - text expiring keys
WebRun opens Twilio to text expiring keys. - Text your own number when a key expires within seven days
- Name the key label, the account it belongs to, and the expiry date
- Stay silent in weeks with nothing expiring
- Never revoke, edit, or recreate a key: only the account owner does that
Done when You have been texted about every key expiring this week.
How is each run configured?
Secure by default
Connect once, stays signed in
WebRun signs in once and keeps each session in a persistent environment, so every run picks up right where it left off.
Every action is checked against this policy before it runs.
Questions, answered
Can it revoke or change a key?
No. WebRun only reads the API management page and reports. Revoking, editing permissions, or adding an IP restriction stays with you, because a wrong revoke breaks live jobs.
Does it trade or move funds?
No. This workflow never opens positions, places orders, or withdraws anything. It reads key settings only, and the API secrets themselves are never shown after creation.
What makes a key over-permissioned?
Any permission beyond what its job needs, most often withdrawal or trade rights on a key that only reads balances. Those are listed first, with the exact permission to remove.
Put this on autopilot.
Turn it on in minutes - or have our team set it up for you.