Automated HTX API Key Security Review
Every Monday, WebRun signs in to your HTX account, lists the API keys that exist with the permissions each one holds, whether it is bound to an IP address, and when it expires, checks the recent login history for anything unfamiliar, posts the full review to Microsoft Teams, and flags the riskiest findings to you on WhatsApp for you to act on yourself.
How do I review which API keys can access my exchange account?
WebRun signs in to HTX every Monday and reviews the API keys that can reach your account, recording each one's permissions, IP binding, and expiry date. It posts the review to Microsoft Teams and flags keys worth revoking on WhatsApp, without ever trading, withdrawing, or changing a setting.
- Keys with no IP binding are named every week
- A key nearing expiry is seen before a bot stops working
- Nothing is revoked, changed, or traded without you doing it
Built for crypto traders · trading bot operators · treasury managers · security-minded investors
What does WebRun do on every run?
The exact actions WebRun takes, in order - in plain language, so you can adjust anything.
-
WebRun signs in and gets to work
Opens
www.htx.comin a real browser with your saved login - no setup, no API keys. -
1
HTX - read the keys, permissions, and login history
WebRun opens HTX to read the keys, permissions, and login history. - Sign in to your HTX account and open the API key management area
- List each key by its label and creation date, never its secret
- Record the permissions each key holds and whether it is bound to specific IP addresses
- Note each key's expiry date and read the recent login history for unfamiliar times or locations
Done when Every API key is listed with its permissions, IP binding, and expiry.
-
2
Microsoft Teams - post the weekly access review
WebRun opens Microsoft Teams to post the weekly access review. - Post the week's access review to your private Teams channel
- Show each key with its permissions, IP binding, expiry date, and age
- Compare against last week's post and call out any key that is new or now holds wider permissions
Done when The full access review for this week is posted in Teams.
-
3
WhatsApp - flag the risky keys to you
WebRun opens WhatsApp to flag the risky keys to you. - Message yourself the findings that need a decision this week
- Lead with keys expiring soon, keys with no IP binding, and permissions wider than the bot using them needs
- Include any unfamiliar login so you can check it
- Never revoke a key, change a permission, or place a trade. WebRun reports and you decide
Done when You have the shortlist of keys worth revoking or tightening.
How is each run configured?
Secure by default
Connect once, stays signed in
WebRun signs in once and keeps each session in a persistent environment, so every run picks up right where it left off.
Every action is checked against this policy before it runs.
Questions, answered
Can it trade, withdraw, or move funds?
No. WebRun never places an order, never withdraws, and never transfers anything. This workflow reads account settings and reports them, nothing else.
Does it revoke keys or change permissions?
No. Revoking a key and narrowing a permission are decisions you make yourself in HTX. WebRun only tells you which keys look worth reviewing and why.
Does it record my API secrets?
No. Secrets are shown once at creation and are not readable afterwards. WebRun records only the key label, its permissions, its IP binding, and its dates.
Put this on autopilot.
Turn it on in minutes - or have our team set it up for you.