> ## Documentation Index
> Fetch the complete documentation index at: https://docs.cdp.coinbase.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Portfolio Isolation and Cross Portfolio Access

> Lock each Coinbase Exchange API key to its own portfolio, and grant cross portfolio access only to the keys that need it.

Portfolio isolation is an opt-in account setting that locks every API key to the portfolio it was created in. Once enabled, a key can't read or act on other portfolios unless it has **cross portfolio access**.

Use it when different clients, desks, or teams each have their own portfolio and one party's key must never see another's balances, orders, transfers, or reports. For example, a broker can give each downstream client its own portfolio and key.

## Terminology

| Term | Meaning |
| :- | :- |
| **Portfolio** | Holds balances, orders, and API keys within an Exchange account. Called a **profile** in the REST API (`profile_id`). See [Account Structure](./structure). |
| **Portfolio isolation** | Account-level setting. When on, every API key is limited to its own portfolio on all REST endpoints. |
| **Cross portfolio access** | Per-key setting. Lets a key read and act on every portfolio in the account, even with isolation on. |
| **Portfolio-scoped key** | A key without cross portfolio access. This is the default. |

<Note>
  Some API responses call a key with cross portfolio access a **Managed** key. The Exchange web interface always uses **Cross Portfolio Access**. They mean the same thing.
</Note>

## How it works

### Isolation off (default)

Order entry, FIX, and WebSocket already limit each key to its own portfolio.

Some REST endpoints don't. They accept a `profile_id` parameter or return account-wide results, so any key can read other portfolios' data:

| Endpoint | Account-wide behavior |
| :- | :- |
| [Get profiles](/api-reference/exchange-api/rest-api/profiles/get-profiles) | Lists every portfolio |
| [Get all orders](/api-reference/exchange-api/rest-api/orders/get-all-orders) | Accepts any `profile_id` |
| [Cancel all orders](/api-reference/exchange-api/rest-api/orders/cancel-all-orders) | Accepts any `profile_id` |
| [Get all transfers](/api-reference/exchange-api/rest-api/transfers/get-all-transfers) | Accepts any `profile_id` |
| [Get all conversions](/api-reference/exchange-api/rest-api/conversions/get-all-conversions) | Accepts any `profile_id` |
| [Get all reports](/api-reference/exchange-api/rest-api/reports/get-all-reports) | Accepts any `profile_id`; reports can span the account |
| [Get a single account's ledger](/api-reference/exchange-api/rest-api/accounts/get-single-account-ledger) | Accepts any `profile_id` |

### Isolation on

* **Portfolio-scoped keys** see only their own portfolio on every REST endpoint. Requests for another `profile_id` return `403 Forbidden`. **Get profiles** returns one portfolio.
* **Keys with cross portfolio access** keep the account-wide behavior above.
* **Order entry, FIX, and WebSocket** don't change.
* **Web sign-in** doesn't change. Isolation applies to API keys only.

<Warning>
  Enabling isolation takes effect immediately. Every existing key becomes portfolio-scoped, and integrations that rely on account-wide reads get `403` until you issue them new keys with cross portfolio access.
</Warning>

### Example

An account has three portfolios: **Default**, **Client A**, and **Client B**. Each client has its own key. The operations team has a key in **Default** with cross portfolio access.

| Request | Client A key | Operations key |
| :- | :- | :- |
| `GET /profiles` | Client A only | All three portfolios |
| `GET /orders?profile_id=<Client B>` | `403 Forbidden` | Client B's orders |
| `GET /orders` | Client A's orders | Default's orders |
| `POST /orders` (no `profile_id`) | Order placed in Client A | Order placed in Default |
| `GET /transfers` | Client A's transfers | All transfers |

## Enable or disable portfolio isolation

1. Sign in to [Coinbase Exchange](https://exchange.coinbase.com).
2. Open your profile menu and select **Settings**.
3. Select **Security**.
4. Turn on **Portfolio isolation** and confirm.

All existing keys become portfolio-scoped immediately. You can't add cross portfolio access to an existing key; create a new one instead.

To turn isolation off, return to **Settings** > **Security** and switch it off. Portfolio-scoped keys regain account-wide access on the endpoints above.

<Tip>
  Suggested rollout: list the integrations that use the account-wide endpoints above, enable isolation, create new keys with cross portfolio access for those integrations, switch them over, then delete the old keys.
</Tip>

## Create a key with cross portfolio access

You can only set cross portfolio access when you create a key, and only while isolation is on. New keys are portfolio-scoped unless you select it.

1. Sign in to [Coinbase Exchange](https://exchange.coinbase.com).
2. Select **API** in the left navigation.
3. Click **New API Key**.
4. Under **Permissions**, select **Cross Portfolio Access** along with any View, Trade, Transfer, or Manage permissions the key needs.
5. Create the key and save the key, secret, and passphrase.

Keys with cross portfolio access show **Cross Portfolio Access** under **Permissions** in **My API Keys**.

You can't change this setting on an existing key. To remove it, delete the key and create a portfolio-scoped one.

<Info>
  Cross portfolio access controls *which portfolios* a key can see. **View**, **Transfer**, **Trade**, and **Manage** control *what* it can do. A key with cross portfolio access and **View** only can list every portfolio's orders but can't place or cancel them. See [API Key Permissions](/exchange/rest-api/authentication#api-key-permissions).
</Info>

## Recommendations

* Give each client, desk, or strategy its own portfolio and a portfolio-scoped key.
* Grant cross portfolio access only to operations, treasury, or reporting keys.
* Review keys with cross portfolio access regularly and delete ones no longer needed.
* Delete a client's or team member's keys when they leave.

## What to read next

* [Account Structure](./structure): how profiles, accounts, and API keys relate.
* [REST API Authentication](/exchange/rest-api/authentication): permissions and request signing.
* [Get profiles](/api-reference/exchange-api/rest-api/profiles/get-profiles): check which portfolios a key can see.
