How to Connect Bybit to BitStat with Read-Only API Access

Create read-only Bybit credentials with the minimum Orders, Positions, and Account Transfer scopes, then sync futures history to BitStat.

How to Connect Bybit to BitStat with Read-Only API Access

Last updated:

This walkthrough connects a Bybit Crypto Futures account to BitStat with a dedicated read-only API key. The setup normally takes about five minutes and gives BitStat access to the trade data needed for journal synchronization without enabling withdrawals.

Security rule: keep the key globally Read-Only and never enable Withdraw. Enter the API Key and Secret Key only in the official BitStat connection form, and revoke the key in Bybit if either value is exposed.

1. Sign in on the Bybit website

Open the official Bybit website and sign in. API keys are created on the website, not in the mobile app. Make sure 2FA is active. Bybit may restrict API key creation for a new account during the first 48 hours after registration.

2. Open API Management

Select the profile icon in the upper-right corner and choose API, or open the Bybit API Management page directly after signing in.

Bybit profile menu with the API item highlighted
Open the profile menu and select API.
Bybit API Management page with Create New Key highlighted
On API Management, select Create New Key.

3. Create a system-generated read-only key

Select Create New Key, choose System-generated API Keys, and give the key a recognizable name such as BitStat. Set the key to Read-Only before selecting individual scopes.

Bybit API Management page ready to create a new key
Start a new key from the API Management page.
Bybit API key type dialog with System-generated API Keys selected
Choose a system-generated API key.

4. Grant only the required scopes

Keep the global permission set to Read-Only. In the trading permissions, enable the scopes BitStat uses to read futures activity:

  • Orders and Positions under Contract Trade.
  • Account Transfer under Assets.
  • Leave Withdraw and unrelated scopes disabled.

Follow the IP option required by the current BitStat connection flow. If a key has no IP binding, Bybit can expose a remaining-valid-days deadline for it, so check the key status and rotate it before expiration.

Bybit API settings with Read-Only, Orders, and Positions selected
Keep the key Read-Only and select the required Orders and Positions scopes.
Bybit Assets permissions with Account Transfer selected and Submit highlighted
Under Assets, keep Account Transfer and leave Withdraw disabled.

5. Confirm with 2FA and copy the credentials

Submit the permission form and complete the requested 2FA confirmation. Copy the API Key and Secret Key immediately because the Secret Key is shown only once. If it is lost, delete the key and create a new read-only key.

6. Connect Bybit in BitStat

In BitStat, open Accounts, select Crypto Futures, and choose Add Account. Select Bybit, enter an account name, paste the API Key and API Secret, and select Connect Account.

BitStat dashboard before opening Accounts
Start from the BitStat dashboard.
BitStat Accounts page with Crypto Futures and Add Account highlighted
Open Accounts, choose Crypto Futures, then Add Account.
BitStat Bybit connection form with account name and API credential fields
Select Bybit, enter the account name and credentials, then connect.

BitStat will begin synchronizing the available Bybit futures history after the connection succeeds. The first import can take a few minutes.

Final security check

  • The key is globally Read-Only.
  • Orders, Positions, and Account Transfer are enabled.
  • Withdraw and unrelated scopes are disabled.
  • The credentials were entered only on the official BitStat form.
The essentials, answered

Frequently asked questions

Which Bybit API scopes does BitStat need?
Keep the key globally Read-Only. Enable Orders and Positions under Contract Trade and Account Transfer under Assets, while leaving Withdraw and unrelated scopes disabled.
Why is Bybit not letting me create an API key?
API keys can be created only on the Bybit website, not in the mobile app. Bybit may also restrict new accounts from creating a key during the first 48 hours after registration.
Can a Bybit key without an IP restriction expire?
Yes. Bybit exposes a remaining-valid-days value for keys without an IP binding or after a password change. Check the key status periodically and rotate it before it expires.
What should I check if synchronization fails?
Confirm that the key is Read-Only, Orders, Positions, and Account Transfer are enabled, Withdraw is disabled, the key has not expired, and any configured IP restriction matches the connection requirements.