Credential rules
- Keep API keys and wallet credentials private.
- Copy a newly created gHypurr API key immediately. The secret is displayed once and cannot be recovered later.
- Use the narrowest scopes required by your application.
- Add an IP or CIDR allowlist when your client has stable outbound addresses.
- Rotate a key when changing systems and revoke it immediately if exposure is suspected.
- Use a dedicated Hyperliquid API agent for Copy Trade. Never reuse or send its private key through email, support, social media, or chat.
