Skip to main content
Portfolio isolation is an opt-in account setting that locks every API key to the portfolio it was created in. Once enabled, a key can’t read or act on other portfolios unless it has cross portfolio access. Use it when different clients, desks, or teams each have their own portfolio and one party’s key must never see another’s balances, orders, transfers, or reports. For example, a broker can give each downstream client its own portfolio and key.

Terminology

Some API responses call a key with cross portfolio access a Managed key. The Exchange web interface always uses Cross Portfolio Access. They mean the same thing.

How it works

Isolation off (default)

Order entry, FIX, and WebSocket already limit each key to its own portfolio. Some REST endpoints don’t. They accept a profile_id parameter or return account-wide results, so any key can read other portfolios’ data:

Isolation on

  • Portfolio-scoped keys see only their own portfolio on every REST endpoint. Requests for another profile_id return 403 Forbidden. Get profiles returns one portfolio.
  • Keys with cross portfolio access keep the account-wide behavior above.
  • Order entry, FIX, and WebSocket don’t change.
  • Web sign-in doesn’t change. Isolation applies to API keys only.
Enabling isolation takes effect immediately. Every existing key becomes portfolio-scoped, and integrations that rely on account-wide reads get 403 until you issue them new keys with cross portfolio access.

Example

An account has three portfolios: Default, Client A, and Client B. Each client has its own key. The operations team has a key in Default with cross portfolio access.

Enable or disable portfolio isolation

  1. Sign in to Coinbase Exchange.
  2. Open your profile menu and select Settings.
  3. Select Security.
  4. Turn on Portfolio isolation and confirm.
All existing keys become portfolio-scoped immediately. You can’t add cross portfolio access to an existing key; create a new one instead. To turn isolation off, return to Settings > Security and switch it off. Portfolio-scoped keys regain account-wide access on the endpoints above.
Suggested rollout: list the integrations that use the account-wide endpoints above, enable isolation, create new keys with cross portfolio access for those integrations, switch them over, then delete the old keys.

Create a key with cross portfolio access

You can only set cross portfolio access when you create a key, and only while isolation is on. New keys are portfolio-scoped unless you select it.
  1. Sign in to Coinbase Exchange.
  2. Select API in the left navigation.
  3. Click New API Key.
  4. Under Permissions, select Cross Portfolio Access along with any View, Trade, Transfer, or Manage permissions the key needs.
  5. Create the key and save the key, secret, and passphrase.
Keys with cross portfolio access show Cross Portfolio Access under Permissions in My API Keys. You can’t change this setting on an existing key. To remove it, delete the key and create a portfolio-scoped one.
Cross portfolio access controls which portfolios a key can see. View, Transfer, Trade, and Manage control what it can do. A key with cross portfolio access and View only can list every portfolio’s orders but can’t place or cancel them. See API Key Permissions.

Recommendations

  • Give each client, desk, or strategy its own portfolio and a portfolio-scoped key.
  • Grant cross portfolio access only to operations, treasury, or reporting keys.
  • Review keys with cross portfolio access regularly and delete ones no longer needed.
  • Delete a client’s or team member’s keys when they leave.