18 March 2026

Read-only API hygiene before a review session

We prefer read-only connections for Desktop setup. Withdrawal-enabled keys are never required for our standard engagements.

Create keys for the session, not forever

Issue a fresh read-only key before onboarding, confirm balances appear correctly, then rotate or delete after you are comfortable the Desktop snapshot matches the venue. Leaving an old “temporary” key alive for months is a common slip.

IP allowlists when the venue offers them

If you work from a stable home or office IP in Seoul, lock the key to that address. Video sessions from hotels or cafés may need a temporary widen — plan that before the call so we are not stuck mid-reconcile.

Export as fallback

Some venues make API creation tedious under extra KYC flags. A CSV or on-screen balance export is enough for a human review; Desktop live sync can wait until the key is ready.

What we never ask for

Password shares, 2FA codes, or withdrawal whitelist changes. If a message claiming to be Scalablenet asks for those, it is not us — write to contact@scalablenet.digital from a known page on this site.

Ready to schedule? Use the contact form and mention which venues need API versus export.