curl --request POST \
--url https://whitebit.com/api/v4/sub-account/api-key/create \
--header 'Content-Type: application/json' \
--header 'X-TXC-APIKEY: <api-key>' \
--header 'X-TXC-PAYLOAD: <api-key>' \
--header 'X-TXC-SIGNATURE: <api-key>' \
--data '
{
"type": 1,
"subAccountId": "8e667b4a-0b71-4988-8af5-9474dbfaeb51",
"title": "Trading Bot Key"
}
'import requests
url = "https://whitebit.com/api/v4/sub-account/api-key/create"
payload = {
"type": 1,
"subAccountId": "8e667b4a-0b71-4988-8af5-9474dbfaeb51",
"title": "Trading Bot Key"
}
headers = {
"X-TXC-APIKEY": "<api-key>",
"X-TXC-PAYLOAD": "<api-key>",
"X-TXC-SIGNATURE": "<api-key>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {
'X-TXC-APIKEY': '<api-key>',
'X-TXC-PAYLOAD': '<api-key>',
'X-TXC-SIGNATURE': '<api-key>',
'Content-Type': 'application/json'
},
body: JSON.stringify({
type: 1,
subAccountId: '8e667b4a-0b71-4988-8af5-9474dbfaeb51',
title: 'Trading Bot Key'
})
};
fetch('https://whitebit.com/api/v4/sub-account/api-key/create', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://whitebit.com/api/v4/sub-account/api-key/create",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'type' => 1,
'subAccountId' => '8e667b4a-0b71-4988-8af5-9474dbfaeb51',
'title' => 'Trading Bot Key'
]),
CURLOPT_HTTPHEADER => [
"Content-Type: application/json",
"X-TXC-APIKEY: <api-key>",
"X-TXC-PAYLOAD: <api-key>",
"X-TXC-SIGNATURE: <api-key>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://whitebit.com/api/v4/sub-account/api-key/create"
payload := strings.NewReader("{\n \"type\": 1,\n \"subAccountId\": \"8e667b4a-0b71-4988-8af5-9474dbfaeb51\",\n \"title\": \"Trading Bot Key\"\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("X-TXC-APIKEY", "<api-key>")
req.Header.Add("X-TXC-PAYLOAD", "<api-key>")
req.Header.Add("X-TXC-SIGNATURE", "<api-key>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://whitebit.com/api/v4/sub-account/api-key/create")
.header("X-TXC-APIKEY", "<api-key>")
.header("X-TXC-PAYLOAD", "<api-key>")
.header("X-TXC-SIGNATURE", "<api-key>")
.header("Content-Type", "application/json")
.body("{\n \"type\": 1,\n \"subAccountId\": \"8e667b4a-0b71-4988-8af5-9474dbfaeb51\",\n \"title\": \"Trading Bot Key\"\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://whitebit.com/api/v4/sub-account/api-key/create")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["X-TXC-APIKEY"] = '<api-key>'
request["X-TXC-PAYLOAD"] = '<api-key>'
request["X-TXC-SIGNATURE"] = '<api-key>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"type\": 1,\n \"subAccountId\": \"8e667b4a-0b71-4988-8af5-9474dbfaeb51\",\n \"title\": \"Trading Bot Key\"\n}"
response = http.request(request)
puts response.read_bodyCreate Sub-Account API Key
The endpoint creates a new API key for a sub-account. Each sub-account supports up to 50 API keys, independent from the main account and from other sub-accounts.
A type: 2 key includes the withdrawal permission group, but its URLs default to enable: false.
Enable the ones the key uses (for example /api/v4/main-account/withdraw) with
Edit Sub-Account API Key; until then
/api/v4/main-account/withdraw returns 401 with {"code":4,"message":"This API Key is not authorized to perform this action."}.
Crypto deposits additionally require deposits to be enabled for the account — disabled by default,
contact your assigned Account Manager or email institutional@whitebit.com.
Rate limit: 1000 requests/10 sec.
The API does not cache the response.
curl --request POST \
--url https://whitebit.com/api/v4/sub-account/api-key/create \
--header 'Content-Type: application/json' \
--header 'X-TXC-APIKEY: <api-key>' \
--header 'X-TXC-PAYLOAD: <api-key>' \
--header 'X-TXC-SIGNATURE: <api-key>' \
--data '
{
"type": 1,
"subAccountId": "8e667b4a-0b71-4988-8af5-9474dbfaeb51",
"title": "Trading Bot Key"
}
'import requests
url = "https://whitebit.com/api/v4/sub-account/api-key/create"
payload = {
"type": 1,
"subAccountId": "8e667b4a-0b71-4988-8af5-9474dbfaeb51",
"title": "Trading Bot Key"
}
headers = {
"X-TXC-APIKEY": "<api-key>",
"X-TXC-PAYLOAD": "<api-key>",
"X-TXC-SIGNATURE": "<api-key>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {
'X-TXC-APIKEY': '<api-key>',
'X-TXC-PAYLOAD': '<api-key>',
'X-TXC-SIGNATURE': '<api-key>',
'Content-Type': 'application/json'
},
body: JSON.stringify({
type: 1,
subAccountId: '8e667b4a-0b71-4988-8af5-9474dbfaeb51',
title: 'Trading Bot Key'
})
};
fetch('https://whitebit.com/api/v4/sub-account/api-key/create', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://whitebit.com/api/v4/sub-account/api-key/create",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'type' => 1,
'subAccountId' => '8e667b4a-0b71-4988-8af5-9474dbfaeb51',
'title' => 'Trading Bot Key'
]),
CURLOPT_HTTPHEADER => [
"Content-Type: application/json",
"X-TXC-APIKEY: <api-key>",
"X-TXC-PAYLOAD: <api-key>",
"X-TXC-SIGNATURE: <api-key>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://whitebit.com/api/v4/sub-account/api-key/create"
payload := strings.NewReader("{\n \"type\": 1,\n \"subAccountId\": \"8e667b4a-0b71-4988-8af5-9474dbfaeb51\",\n \"title\": \"Trading Bot Key\"\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("X-TXC-APIKEY", "<api-key>")
req.Header.Add("X-TXC-PAYLOAD", "<api-key>")
req.Header.Add("X-TXC-SIGNATURE", "<api-key>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://whitebit.com/api/v4/sub-account/api-key/create")
.header("X-TXC-APIKEY", "<api-key>")
.header("X-TXC-PAYLOAD", "<api-key>")
.header("X-TXC-SIGNATURE", "<api-key>")
.header("Content-Type", "application/json")
.body("{\n \"type\": 1,\n \"subAccountId\": \"8e667b4a-0b71-4988-8af5-9474dbfaeb51\",\n \"title\": \"Trading Bot Key\"\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://whitebit.com/api/v4/sub-account/api-key/create")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["X-TXC-APIKEY"] = '<api-key>'
request["X-TXC-PAYLOAD"] = '<api-key>'
request["X-TXC-SIGNATURE"] = '<api-key>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"type\": 1,\n \"subAccountId\": \"8e667b4a-0b71-4988-8af5-9474dbfaeb51\",\n \"title\": \"Trading Bot Key\"\n}"
response = http.request(request)
puts response.read_bodyUsed in these guides
- Embedded Trading sub-account integration — managed sub-accounts, fee-share, and partner onboarding.
Authorizations
The public WhiteBIT API key.
Base64-encoded JSON request body.
HMAC-SHA512 signature of the payload, hex-encoded. Computed as hex(HMAC-SHA512(payload, api_secret)).
Body
Type of API key (1 - info and trading; 2 - info, trading, deposits, withdraws)
1, 2 1
ID of the sub-account to create the API key for
"8e667b4a-0b71-4988-8af5-9474dbfaeb51"
Custom title/name for the API key
"Trading Bot Key"
Response
API key created successfully
Sub-account identifier
"8e667b4a-0b71-4988-8af5-9474dbfaeb51"
API key identifier
"a1b2c3d4-e5f6-7890-abcd-ef1234567890"
API key title/name
"Trading Bot Key"
Whether the API key is enabled
true
API key
"pub-key-abc123"
API secret
"secret-xyz789"
API key type (1 - info and trading, 2 - info, trading, deposit and withdraw)
1
Last activity timestamp
1641081600
Whether access is restricted
false
Permission groups for the key. Each group lists its individual endpoint URLs and whether
each is enabled. On a newly created key every URL defaults to enable: false; enable the
required URLs with Edit Sub-Account API Key
before calling them (for example /api/v4/main-account/withdraw).
Show child attributes
Show child attributes
Was this page helpful?