# What is a Hyperliquid API wallet? (agent wallet, explained)

Source: https://cold-front.xyz/guides/hyperliquid-api-wallet/
Updated: 28 September 2026

A Hyperliquid API wallet, also called an agent wallet, is a separate signing key that your account authorizes to trade for it. It can place, change and cancel orders on your account, but it can't withdraw, send funds, transfer between accounts or approve other wallets. It lasts up to 180 days, and you can revoke it at any time.

## What it can and can't do

| Action | API wallet | Your account's wallet |
| --- | --- | --- |
| Place, change and cancel orders | Yes | Yes |
| Change leverage and margin on a position | Yes | Yes |
| Withdraw | No | Yes |
| Send funds or transfer between accounts | No | Yes |
| Authorize or remove API wallets | No | Yes |

Hyperliquid enforces these limits itself. No app or extension can change them.

## How to create one

1. Open [app.hyperliquid.xyz/API](https://app.hyperliquid.xyz/API) with your account's wallet connected.
2. Enter a name and press Generate. Copy the private key it shows. That's the API key, and it's shown once.
3. Choose how many days it lasts (up to 180) and press Authorize. Your wallet signs once to approve it.

## What people use it for

Trading bots and scripts use an API wallet so they can trade without holding the main wallet's key. [Coldfront](https://cold-front.xyz/) uses one so a person can trade in the official Hyperliquid app from a cold wallet's account without connecting the cold wallet each time. Coldfront keeps the API key encrypted with your passphrase and gives it to the app only while unlocked.

## If an API key leaks

Someone who has it can't take your funds out, but they can trade on your account, and bad trades can lose money. Revoke the API wallet on the API page as soon as you think it leaked, then authorize a new one.

## Where to keep the API key

Treat it like a password. A bot usually keeps it in a config file on a server. In a browser, Coldfront keeps it encrypted (PBKDF2-SHA256 with 600,000 rounds, then AES-GCM), removes it from the page after the app starts, and locks by itself. Details are on the [security page](https://cold-front.xyz/security/).

## Questions

### Can a Hyperliquid API wallet withdraw funds?

No. An API wallet can place, change and cancel orders. Hyperliquid doesn't let it withdraw, send funds, transfer between accounts or approve other wallets. Those need the account's own wallet.

### How long does a Hyperliquid API wallet last?

Up to 180 days. You choose the length when you authorize it on the API page. After that it stops working, and you authorize a new one with your wallet.

### Is an API wallet the same as an agent wallet?

Yes. Hyperliquid's app calls it an API wallet, and its documentation and code also call it an agent wallet.

### Does an API wallet hold money?

No. It has its own address, and that address holds nothing: its balance is zero on-chain and in every Hyperliquid app. It only signs orders for your account, and your funds stay in your account.

### How do I revoke a Hyperliquid API wallet?

Open app.hyperliquid.xyz/API with your wallet connected and remove the API wallet. It stops working straight away.

### Can I use an API wallet in the Hyperliquid app instead of a bot?

Yes, with Coldfront. It stores the API key encrypted and gives it to the official Hyperliquid app while unlocked, so you trade in the normal app from your cold wallet's account.
