Binance sync with read-only keys

Checked against app build 2026-08-26-01-41 on 2026-08-26.

Binance sync works identically to Kraken sync, and the security model is the same on purpose, one mental model for every exchange connection.

How do I create a read-only Binance API key?

In Binance’s API management, create a key with Enable Reading and nothing else, then copy the key and the secret before you leave the page.

Enable nothing that can trade, withdraw, or transfer. The app only ever reads, so a key with only reading permission is a key that cannot hurt you even if it leaked. IP restrictions are optional, the app works with or without them, and a read-only key stays harmless either way. Binance shows the secret once, at creation, so if you navigate away without copying it you will need to make a new key rather than recover the old one.

If a key ever worries you, delete it in Binance’s API management. Nothing in the app depends on it surviving, and the transactions you already imported stay where they are.

How do I connect the key to gains.tax?

Open Import in the sidebar, choose the Binance connection, and paste the key and the secret into the two fields. Both are needed before the connection saves, and the app says so plainly if one is missing.

The connection is stored in your workspace on your machine like everything else, so it travels in your session file and nowhere else. Once saved, sync pulls your trades and balances on demand.

Where does my Binance secret actually go?

Nowhere. Your browser signs each request with the secret on your machine, and only the signed request travels.

The signed request reaches api.binance.com through the same stateless relay Kraken uses, which checks the destination against a two-host allowlist, forwards the call, hands back the answer, and remembers nothing. The relay exists only because exchanges refuse direct requests from web pages, it never sees a secret because signing already happened, and its source is a single small file you can read and deploy to your own account. Details and the run-your-own option are on the relay page, and the relay sits alongside the other optional network features in the privacy model.

What arrives, and what if the sync fails?

Trades and balances land in the standard preview, where you reconcile before anything is added, exactly as a file import does.

Nothing joins the workspace unseen. Sync again whenever you like, existing rows deduplicate rather than double, which is the same protection described in duplicates. If the numbers after import do not match what Binance shows you, the reconciliation count explains how rows become tax events.

When a sync fails, the connection row says “Failed.” and names the exact cause rather than shrugging. “The relay answered N” means the relay was unreachable or blocked. “Binance said X” is Binance’s own message passed through untouched, and an invalid key or missing read permission reads as exactly that, so check the key and secret copied across whole and that Enable Reading is on, then try once more. The complete list of messages is in error messages.

If you would rather not create a key at all, Binance statement files import directly, see supported formats.