Kraken sync with read-only keys
Checked against app build 2026-08-26-01-41 on 2026-08-26.
Exchange sync pulls your Kraken history directly, no file export needed. It is built so that trusting it requires reading one page, this one.
What permissions should the Kraken API key have?
Query permissions only, the ones that read balances and trade history, and nothing else.
In Kraken’s security settings, create an API key with Query Funds plus Query Closed Orders and Trades. Grant nothing that can trade, withdraw, or change the account. The app only ever reads, and a key that can only read is a key that cannot hurt you even if it leaked.
Where does my API secret go?
Nowhere. Your browser signs each request itself, using the key’s secret, on your machine, and the secret is never transmitted anywhere.
The signed request then passes through a small relay, because exchanges do not accept direct requests from web pages, and the relay forwards it to api.kraken.com and returns the answer. The relay holds no accounts, stores nothing, logs nothing, and refuses every destination except the two exchange hosts it exists for, its full story is on the relay page.
What comes back from a sync?
Your trades and balances, into the same preview-and-reconcile flow as every other import.
Nothing joins the workspace unseen. Sync again whenever you like, existing rows deduplicate rather than double, the protection described in duplicates.
What if Kraken answers with an error?
The app shows you Kraken’s own message rather than a vague failure, so an invalid key reads as exactly that.
Check the key was copied whole and its permissions are query-only, then try once more. The whole set of sync failures and what each means is in error messages. Binance works the same way, see Binance sync.