Security Best Practices
Protecting Your API Keys
Trading permissions only — Never enable withdrawal permissions on Hyperliquid
Unique keys per platform — Create a dedicated API key for HyperSync
Rotate periodically — Regenerate keys every 30-90 days
Monitor activity — Check your Hyperliquid trade history regularly
Revoke unused keys — If you stop using HyperSync, revoke the key immediately
Protecting Your Account
Strong passwords — Use unique, complex passwords for your HyperSync account
Secure connection — Always access HyperSync over HTTPS
Don't share credentials — Never share your login, API keys, or webhook tokens
Log out when done — Especially on shared or public computers
Emergency Procedures
If you suspect your account or API keys are compromised:
Immediately revoke the API key on Hyperliquid's website
Use the Emergency Halt feature in HyperSync Settings to stop all trading
Close all open positions from the Hyperliquid interface directly
Delete the compromised wallet from HyperSync
Generate a new API key with fresh credentials
Review your trade history for any unauthorized activity
Change your HyperSync password if using email login
Why Your Funds Are Safe
No withdrawal access: HyperSync only has permission to trade, never to withdraw
Encrypted storage: Your API keys are encrypted before being stored
Account isolation: Your data is completely separate from other users
You control revocation: You can revoke API access from Hyperliquid at any time, instantly cutting off HyperSync's ability to trade
Last updated
