Terminology
Some API responses call a key with cross portfolio access a Managed key. The Exchange web interface always uses Cross Portfolio Access. They mean the same thing.
How it works
Isolation off (default)
Order entry, FIX, and WebSocket already limit each key to its own portfolio. Some REST endpoints don’t. They accept aprofile_id parameter or return account-wide results, so any key can read other portfolios’ data:
Isolation on
- Portfolio-scoped keys see only their own portfolio on every REST endpoint. Requests for another
profile_idreturn403 Forbidden. Get profiles returns one portfolio. - Keys with cross portfolio access keep the account-wide behavior above.
- Order entry, FIX, and WebSocket don’t change.
- Web sign-in doesn’t change. Isolation applies to API keys only.
Example
An account has three portfolios: Default, Client A, and Client B. Each client has its own key. The operations team has a key in Default with cross portfolio access.Enable or disable portfolio isolation
- Sign in to Coinbase Exchange.
- Open your profile menu and select Settings.
- Select Security.
- Turn on Portfolio isolation and confirm.
Create a key with cross portfolio access
You can only set cross portfolio access when you create a key, and only while isolation is on. New keys are portfolio-scoped unless you select it.- Sign in to Coinbase Exchange.
- Select API in the left navigation.
- Click New API Key.
- Under Permissions, select Cross Portfolio Access along with any View, Trade, Transfer, or Manage permissions the key needs.
- Create the key and save the key, secret, and passphrase.
Cross portfolio access controls which portfolios a key can see. View, Transfer, Trade, and Manage control what it can do. A key with cross portfolio access and View only can list every portfolio’s orders but can’t place or cancel them. See API Key Permissions.
Recommendations
- Give each client, desk, or strategy its own portfolio and a portfolio-scoped key.
- Grant cross portfolio access only to operations, treasury, or reporting keys.
- Review keys with cross portfolio access regularly and delete ones no longer needed.
- Delete a client’s or team member’s keys when they leave.
What to read next
- Account Structure: how profiles, accounts, and API keys relate.
- REST API Authentication: permissions and request signing.
- Get profiles: check which portfolios a key can see.