Skip to main content
GET
Check OAuth API key existence

Authentication

OAuth 2.0 Bearer token. Required scope: apikeys.read. The endpoint cannot be reached before the partner holds a token for the user, so a first-time integration calls it only after the authorization code has been exchanged. See Authentication. The endpoint is available on https://whitebit.com only.

Cache

No caching.

Notes

Use the decision matrix below to interpret the (exists, isEnabled) response and choose the next action.
  • For a returning user whose token is still valid, call the endpoint before redirecting again — an existing key is reused rather than recreated, and a second creation attempt is rejected. See Returning users. For a first-time user no token exists yet, so the endpoint is reachable only after the authorization code has been exchanged.
  • Disabled keys are not deletable through the OAuth2 partner endpoint. Disabled keys are removed by the user from the WhiteBIT dashboard.
  • See Retrieve OAuth API key secret for the secret-fetch step and Delete OAuth API key for partner-initiated revocation.
  • The permissions array lists the permission groups the user granted on the consent screen — see Key permissions for the full permission model. When the user granted no permissions at all, the key is still created and the array comes back empty; the user deletes that key and re-runs the flow to grant a usable set.

Used in these guides

  • Copy Trading — mirror a lead trader’s orders into followers’ own accounts via OAuth-issued keys.
  • Fast API Key integration — OAuth-issued API keys created on behalf of end users.

Authorizations

Authorization
string
header
required

OAuth 2.0 Bearer Token authentication. Include the access token in the Authorization header.

Example: Authorization: Bearer YOUR_ACCESS_TOKEN

Response

Successful response

data
object