When people search for the "CoinTracker API," they're usually not looking for a developer SDK they want to know how to connect their exchange accounts to CoinTracker using an API key so their transactions sync automatically. That's the heart of it: most exchanges let you generate an API key that grants a third-party app like CoinTracker permission to read your transaction history, and CoinTracker uses that to keep your portfolio and tax data up to date.
This guide explains exactly what that involves: the all-important read-only rule, how to create and add a key, which exchanges use sign-in (OAuth) instead, how your keys are kept secure, and how to troubleshoot when syncing stops. There's also an honest note on whether CoinTracker offers a public developer API. (This is general information, not financial or security advice always follow your exchange's official instructions.)
The essentials
- A "CoinTracker API key" is a read-only key from your exchange that lets CoinTracker sync your data.
- CoinTracker only ever needs read/view access never trade or withdrawal permissions.
- Some exchanges (Coinbase, Uphold, CoinJar) use sign-in (OAuth) instead of manual keys.
- Keys are encrypted; CoinTracker can't move your funds and never asks for your seed phrase.
- You can revoke a key anytime from the exchange that issued it.
What "CoinTracker API" actually means
Most cryptocurrency exchanges let you generate an API key to share your transaction data with third-party apps. Unlike a password, an API key is randomly generated and can't be edited once created some are one-time use, others maintain a continuous flow of data between the exchange and the app. When you connect an exchange like Binance or Gemini to CoinTracker, you provide such a key, and CoinTracker uses it to verify ownership and sync your transactions in real time.
So "the CoinTracker API" isn't really CoinTracker's own programming interface it's the mechanism by which CoinTracker reads data from your exchange's API. Understanding that framing makes everything else click: the key belongs to your exchange account, you control it, and CoinTracker is simply a permitted reader of your data.
The golden rule: read-only, always
This is the single most important point on the page. CoinTracker only ever requests read/view access never write, trade, or transfer permissions. The read-only key lets CoinTracker see your transaction history; it does not let CoinTracker (or anyone using it) place trades, move funds, or withdraw anything.
The practical takeaway: when you create an API key for CoinTracker, enable only the read/view permissions and make sure trading and withdrawal permissions are off. This protects you completely even in the unlikely event a key were exposed, a read-only key can't be used to take your crypto.
Be cautious of any app requesting write, trade, or withdrawal permissions. CoinTracker never needs them. A misconfigured key with trade/withdrawal access could put your funds at risk so always create keys with read-only permissions, and never share keys that have anything more.
The ways to connect an exchange or wallet
API keys are one of several connection methods CoinTracker supports. Knowing the full set helps you pick the right one:
| Method | How it works | Best for |
|---|---|---|
| API key | Paste a read-only key & secret from the exchange | Exchanges like Binance, Gemini, KuCoin |
| Sign-in (OAuth) | Log in to the exchange to grant read-only access | Coinbase, Uphold, CoinJar |
| Public address | Paste a wallet's public address or xPub | Self-custody wallets |
| CSV upload | Import a transaction file from the exchange | When auto-sync isn't available |
| WalletConnect | Connect via the WalletConnect standard | Added wallet compatibility |
Automatic sync (API key or sign-in) is the recommended route because it keeps your data flowing without manual work. To start, you simply go to the Wallets page, choose + Add wallet, search for your exchange, and follow the on-screen instructions for that specific platform.
The walkthrough below shows the overall connect-and-track flow in CoinTracker adding accounts is exactly where API keys come in.
Watch: a CoinTracker walkthrough of connecting accounts and tracking your portfolio (third-party demo).
How to create a read-only API key
The exact steps differ by exchange, but the pattern is consistent. In general:
- Log in to your exchange and find its API management area (often under settings or security).
- Create a new API key, giving it a recognizable label like "CoinTracker."
- Enable only read/view permissions. Make sure trade and withdrawal permissions are turned off.
- Complete any verification many exchanges require 2FA or email confirmation to activate the key.
- Copy the API key and secret (and any passphrase, if the exchange generates one).
- Paste them into CoinTracker on the Add wallet page for that exchange.
A few exchange-specific notes that trip people up: some platforms require a unique passphrase for each key (you'll need to enter it in CoinTracker too); some won't sync an empty account (Kraken, for example); and a few only share part of your data via API (for instance, certain exchanges' APIs export trades only, or exclude direct "Buy Crypto" purchases, which you may need to add another way). Always follow the precise instructions shown on CoinTracker's Add wallet page for your exchange.
Create a dedicated API key for CoinTracker rather than reusing one key across multiple apps. Reusing a single key for several services can cause sync errors and a dedicated key is easier to revoke if you ever want to disconnect.
Exchanges that use sign-in instead of keys
Not every exchange uses manual API keys. A few integrate via OAuth, where you simply sign in to grant read-only access no copying keys required. The notable examples are Coinbase (via OAuth2), Uphold, and CoinJar. For these, you click to connect, you're redirected to the exchange's own login page, you authenticate (with 2FA if enabled), and you approve read-only access.
One safety habit here: when you're redirected to sign in, verify the URL is genuinely your exchange's domain before entering credentials. OAuth is convenient and secure, but only if you confirm you're logging in on the real site a good defense against phishing pages that imitate a login screen.
API key vs CSV vs public address: which to use
If your exchange offers more than one method, here's how to choose. API key (or sign-in) is best for ongoing, automatic syncing set it once and new transactions flow in. CSV upload is the fallback when automatic sync isn't available or an integration is missing; it's a manual snapshot you re-upload as needed. Public address is how you connect on-chain wallets, reading activity straight from the blockchain with no key at all.
For most exchange accounts, the API key or OAuth route is the smoothest. For self-custody wallets, public address is the way. And CSV is the universal backstop if an exchange isn't supported for auto-sync, you can still bring your data in by importing a file.
This getting-started tutorial covers connecting accounts and navigating CoinTracker, useful when adding your first API-synced exchange.
Watch: getting started with CoinTracker, including connecting accounts (third-party tutorial).
How CoinTracker secures your API keys
Because API keys are sensitive, security is central. CoinTracker stores API secrets encrypted, and its employees can't view or decrypt them. Combined with the read-only rule, this means the keys you provide can be used only to read your data never to trade or withdraw and they're protected at rest.
You also have ongoing control. You can revoke a key at any time from within the exchange account where it was created, instantly cutting off access. CoinTracker will never ask you for your recovery phrase or seed phrase, and never asks for write/trade/transfer permissions. If anything claiming to be CoinTracker requests those, treat it as a scam.
Store your API key and secret securely (an encrypted file or password manager), enable read-only permissions only, use a dedicated key for CoinTracker, and revoke keys you no longer use. Treat API keys with the same care as passwords.
What CoinTracker reads through the API
It helps to know exactly what a read-only key exposes. Through it, CoinTracker reads your transaction history trades, deposits and withdrawals, transfers, and rewards along with balances, so it can reconstruct your portfolio and calculate cost basis, gains, and losses. That's the data it needs to track your holdings and build your tax reports.
What it does not get is just as important: a read-only key gives no ability to log in to your exchange, change settings, place trades, or withdraw funds. It's a one-way window onto your activity data, not a set of account controls. This is why read-only keys are the standard for tax and tracking tools they provide everything needed for accounting and nothing that could endanger your assets.
Why read-only access can't drain your account
People are understandably nervous about handing any key to a third party, so it's worth being concrete about why read-only is safe. Exchange API keys are scoped by permission: each key carries only the abilities you granted when you created it. A key created with read/view permission simply has no "move funds" capability attached the exchange itself won't honor a withdrawal or trade request from a key that lacks those permissions.
So even in a worst-case scenario where a read-only key were somehow exposed, the most someone could do is see transaction data not take crypto. The funds never leave the exchange or wallet, and CoinTracker never holds them. That permission scoping, plus encryption of stored secrets and your ability to revoke a key instantly, is what makes connecting via a read-only API key a low-risk action when done correctly.
Examples across popular exchanges
To make it concrete, here's how the connection type tends to vary by platform (always follow the current on-screen instructions, as these can change):
| Exchange | Connection | Notes |
|---|---|---|
| Coinbase | Sign-in (OAuth2) | No manual key grant read-only access by logging in |
| Binance / Binance.US | API key | Read-only key & secret; Binance.US uses a "Tax API Key" |
| Gemini | API key | Read/view key verifies ownership and syncs data |
| KuCoin | API key | Often requires a unique passphrase per key |
| Uphold / CoinJar | Sign-in (OAuth) | Connect by signing in, like Coinbase |
Some platforms also share only part of your data via API for example, a "Tax API Key" connection may exclude direct "Buy Crypto" purchases (which you'd add manually), and a few exchange APIs export trades only. When data looks incomplete, that's usually why and a CSV import or manual entry fills the gap.
Common API setup mistakes
Most connection problems come from a handful of avoidable issues:
- Missing read permissions. If required read/view permissions aren't all enabled, syncing can fail or be incomplete.
- Forgetting the passphrase. Some exchanges generate a unique passphrase per key it must be entered in CoinTracker too.
- IP restrictions. If the key has IP restrictions that block CoinTracker, data won't sync follow the exchange's instructions (some let you whitelist a specific address).
- Empty account. Certain exchanges (like Kraken) won't sync an account with no activity via API.
- Typos in credentials. The key, secret, and passphrase must be entered exactly a single wrong character breaks the connection.
- Reusing one key everywhere. Sharing a key across multiple apps commonly causes errors; use a dedicated key.
Troubleshooting a broken sync
If a connected exchange stops syncing, work through these steps:
- Re-authenticate. On the Wallets page, select the exchange, open the
[...]menu, and choose Update account or Update API Key. - Create a new key. Exchanges sometimes revoke third-party access; old keys may not be reusable, so generate a fresh read-only key and update it in CoinTracker.
- Check permissions and credentials. Confirm read permissions are on, there are no blocking IP restrictions, and the key/secret/passphrase are entered correctly.
- Confirm account activity. Make sure the account isn't empty if your exchange won't sync empty accounts.
- Remove and re-add. As a last resort, remove the exchange from CoinTracker and add it again with fresh credentials.
If part of your data is missing rather than all of it, check whether your exchange's API excludes certain transaction types (some exclude direct purchases or only export trades) those may need a CSV import or manual entry to complete the picture.
Keeping API connections healthy
API connections aren't always "set and forget." Exchanges may require you to periodically re-authenticate or update your key access can expire or be revoked by the exchange over time. If you notice your balances looking stale, a quick re-authentication usually restores the flow.
A light habit helps: every so often (and especially before tax season), glance at your connected accounts to confirm they're syncing, and refresh any that have lapsed. Keeping connections current means your portfolio stays accurate and your year-end tax data is complete when you need it.
Does CoinTracker have a public developer API?
This is worth answering honestly. CoinTracker's prominent, documented "API" story is the read-only exchange API-key connection described throughout this page not a public developer API for programmatically pulling your CoinTracker portfolio or tax data into your own apps. If you're a developer hoping to query CoinTracker itself, that's not the platform's main offering.
Where CoinTracker does act as infrastructure is in business and enterprise partnerships for example, powering tax reporting embedded directly inside major exchanges. If you have a programmatic or enterprise integration need, the right move is to check CoinTracker's official documentation or contact the company directly, rather than assume a public consumer API exists. Don't rely on third-party claims about endpoints; verify with the source.
Don't confuse CoinTracker with "CoinTracking"
A frequent mix-up: CoinTracker (cointracker.io) and CoinTracking (cointracking.info) are different companies with similar names. CoinTracking is a separate product that does offer its own developer API with code samples and endpoints. If you've found documentation describing an HMAC-signed REST API with methods like getTrades or getBalance, that's CoinTracking's API not CoinTracker's.
The distinction matters for both functionality and security: instructions, domains, and support channels are not interchangeable between the two. When following any "API" guide, double-check which product it's actually for, and make sure you're on the correct official domain before entering credentials.
Disconnecting and revoking API access
Just as important as connecting is knowing how to cleanly disconnect. There are two layers. In CoinTracker, you can remove a connected exchange from the Wallets page so it no longer syncs. On the exchange side, you can and for a clean break, should revoke or delete the API key in the exchange's API management area, which permanently cuts off access regardless of anything on CoinTracker's end.
Because you created the key, you hold the off switch: revoking it at the exchange instantly ends the data flow, no permission required from anyone else. This is a good habit if you stop using a connection, suspect a key was exposed, or simply want to tidy up. And since the key was read-only the whole time, removing it has zero effect on your actual crypto it only stops the reading of data. Re-connecting later is as simple as generating a fresh read-only key and adding it again.
API best-practices checklist
- Create keys with read-only permissions never trade or withdrawal access.
- Use a dedicated key for CoinTracker, not one shared across apps.
- Enter the key, secret, and any passphrase exactly as generated.
- Avoid IP restrictions that block syncing (or whitelist as instructed).
- Store credentials securely; treat them like passwords.
- Revoke keys you no longer use, from the exchange side.
- Re-authenticate periodically to keep data flowing.
- Never share your seed phrase CoinTracker never asks for it.
Frequently asked questions
What is a CoinTracker API key? A read-only key you generate at your exchange that lets CoinTracker sync your transaction history automatically.
Is it safe to give CoinTracker my API key? Yes, when it's read-only that lets CoinTracker view data but never trade or withdraw. Keys are stored encrypted, and you can revoke them anytime.
What permissions should the key have? Read/view only. Make sure trade and withdrawal permissions are disabled.
Which exchanges don't need a manual key? Coinbase, Uphold, and CoinJar use sign-in (OAuth) to grant read-only access instead.
My exchange stopped syncing why? Often the key was revoked or expired. Re-authenticate or create a new read-only key and update it in CoinTracker.
Does CoinTracker offer a developer API? Its main "API" is the exchange read-only key connection; it isn't a public developer API. For programmatic/enterprise needs, check official docs or contact CoinTracker.
Is CoinTracker the same as CoinTracking? No they're different companies with similar names. CoinTracking has its own developer API; CoinTracker does not market one publicly.
What data does the API key give CoinTracker? Read access to your transaction history and balances enough to track your portfolio and compute taxes. It can't log in, trade, or withdraw.
Why is part of my exchange data missing after connecting? Some exchange APIs share only certain data (for example, excluding direct "Buy Crypto" purchases or exporting trades only). Fill any gaps with a CSV import or manual entry.
The bottom line
For nearly everyone, "CoinTracker API" comes down to a simple, safe idea: you generate a read-only API key at your exchange (or sign in via OAuth for Coinbase, Uphold, and CoinJar), paste it into CoinTracker, and your transactions sync automatically with no ability for anyone to trade or move your funds. Keys are encrypted, revocable, and entirely under your control.
Set keys to read-only, use a dedicated key, enter credentials carefully, and re-authenticate when prompted, and your portfolio and tax data will stay accurate year-round. If you came looking for a public developer API, the honest answer is that CoinTracker's API relevance is the exchange-key connection verify any programmatic needs with official docs, and don't confuse CoinTracker with the similarly named CoinTracking. Ready to connect? Head to the Wallets page, add your exchange, and let the sync do the rest.
Connection methods, supported exchanges, and per-exchange API behavior can change; details reflect 2026. Always follow the official instructions on CoinTracker's Add wallet page and your exchange, use the official site (cointracker.io), and never share write/withdrawal-enabled keys or your seed phrase. This page is general information, not financial or security advice.
Connect your exchange securely
Add a read-only API key (or sign in) and let CoinTracker sync your transactions for accurate tracking and taxes.
Add an exchange