If you want something to act on your Binance account while you are not at the keyboard, the setting that decides everything is what the key you hand over is allowed to do. Which rule, which pairs, how much — all of it matters far less than that one dialog, because the rule you can change your mind about at any time, and the permission you granted is already out there. The screenshots here are the settings worth getting right.

What a key's permissions actually grant
Start with the permission list, before the tool. Roughly, a Binance API key can be allowed to:
- read your account — balances, positions, order history. On its own it cannot trade and cannot move anything.
- trade spot and margin.
- trade futures.
- move funds between your own wallets and accounts.
- withdraw to an external address.

Almost all automation needs exactly one of those: the ability to place and cancel the orders it manages. Everything else is surface you are handing over for no benefit. So read the list as a question — which of these does this tool actually need in order to do its job? — and grant that and nothing more. If a tool's setup guide is vague about why it wants a permission, that vagueness is the answer.
Leave withdrawal permission off

Leave withdrawal off. Not off for now — off. A key that can trade can move your position. A key that can withdraw can move the money out of the account. Those are different kinds of risk, and only one of them is recoverable by the person who still has the passwords.
This is also the cheapest filter you will ever apply to a trading tool. A tool that asks for withdrawal permission is telling you what it is. You do not have to work out whether it deserves the trust, because there is no reason for it to need it in the first place.
Restrict the key to one address
If the key is restricted to a single IP, a leaked key is not enough on its own — whoever holds it also has to be coming from that address. It is one field in the same dialog as the permissions, and it removes an entire class of accident.
It is worth knowing which address you are allowing. If the tool runs on your own machine, that is your connection. If it runs on someone else's server, the address you are allowlisting is theirs, not yours. That is not automatically a reason to refuse — plenty of useful things run on servers — but it is a reason to be able to say what that server is, and to be uneasy if nobody will tell you.
Keep it on a sub-account

Binance sub-accounts each get their own API key and their own wallet, so a tool pointed at one keeps the positions it manages separate from the ones you hold yourself. Fund the sub-account with only what you are willing to have the tool manage, and revoking its key takes the tool out of the picture without touching your main account. How many sub-accounts you can open depends on your account level.
The point is not tidiness. It is that "how much can this thing lose" becomes a number you chose in advance and can read off a balance, rather than something you work out afterwards by looking at what is left.
Worth noticing when you make one: withdrawal does not appear in a sub-account key's permission list at all. That particular risk is not on the table to begin with.
Know what a rule engine can and cannot do
A rule engine executes the rule you gave it. It does not predict anything and it has no view on where the market is going.
What it removes is the gap between the plan and the execution — the level that was meant to hold and got moved, the target that was meant to be taken and got waited on. Most people who trade their own account do not lose to a bad thesis. They lose to doing something different from what they decided, at the moment it got uncomfortable.
That is the only thing automation is good for here. If you want it for the other thing — knowing what to buy — it will not help you, and nothing that claims to is being straight with you.
It also does not decide the size, it does not know when to stop, and it will not notice that the world has changed underneath it. A rule is a fixed answer to a moving question; that is why it is consistent, and it is also the limit of what it can be.
The one I ended up running is called ArkTool. It sits server-side and reaches my own Binance USDT-M account through a trade-only key that I created; revoking that key is what stops it. It does one thing: takes profit on a pullback, rebalances on a rebound, sits idle in between. I picked the pairs and the size for each one, and it has never decided what to trade on its own. I watched it on simulated prices for a while before it went anywhere near a funded account.
What none of that changes
Being non-custodial is a floor, not a guarantee. Any tool you hand an API key to is a tool you are trusting — with a key that can trade, with code you probably have not read, on an account holding real money. Scoping the key tightly narrows what a mistake can cost. It does not make the tool correct, and it does not make the market kinder.
There are no signals here, nothing to follow, and no returns promised. A rule changes the discipline, not the risk. These are leveraged positions, and no automation turns a losing month into a winning one.
Know how to switch it off
A key you cannot revoke quickly is not a key you control. Find the page now, know the two clicks, and revoke it once while the size is tiny — before you need to. If the tool stops, or you revoke the key, an open position does not close itself; from that moment you are managing it by hand. It is much better to find out what that feels like on a small position than on a large one.
A checklist for any tool you are considering
- Does it ask for withdrawal permission? That is not a preference, it is a stop sign.
- Does it ask for your exchange password, a 2FA code, or access to your email? No tool acting through an API key needs any of those.
- Can you revoke its access in one action, from your exchange, without asking the tool first?
- Is it clear what it will do with the key — which endpoints it calls, which pairs it touches, how it sizes them?
- Does it promise returns, or describe a mechanism? Only one of those is an honest description of what software can do.
- What happens on a bad week, not a good one? If the answer is only about the good weeks, you have your answer.
None of this requires trusting a tool's own documentation. Permissions, revocability and the endpoints being called are all things you can check yourself, before anything is funded.
Before you point anything at a real account
Check the permissions twice. Confirm the allowlisted address is really where the tool runs. Fund only what you would accept losing in full. Watch it once on simulated or tiny size before it gets anything real. And be sceptical of anything that tells you the size stops mattering — leverage cuts both ways.
ArkTool is an independent third-party tool. It is not affiliated with, endorsed by, or connected to Binance. Nothing here is financial advice.

