What Is a Mining Pool API Key? Definition, Uses, and Security Practices
2026-10-09 17:38

A mining pool API key is an account credential that allows an external application—such as a monitoring dashboard, a profitability calculator, or an in-house reporting script—to request account-level data from a mining pool's API on behalf of a pool account or subaccount. It authenticates software, not mining hardware, and it is distinct from the credentials an ASIC uses to connect to the pool's Stratum server.

API credentials and Stratum connection settings serve different purposes. Understanding where each credential belongs reduces configuration errors and limits the exposure of sensitive account data.

What a Mining Pool API Key Is Used For

A pool's API typically exposes account information that would otherwise require logging into the pool's website manually. Depending on the pool and the specific endpoints it offers, an API key can be used to retrieve data such as account-level hashrate, individual worker status, hashrate history, subaccount listings, and payment or reward history. ViaBTC's Pool API, for example, groups its endpoints into categories covering account information, subaccount information, account and miner hashrate, hashrate history, and reward and payment history (ViaBTC Pool API Introduction).

In practice, this is used to feed a monitoring dashboard that alerts an operator when a worker goes offline, to reconcile payouts against an internal accounting system, or to build a custom view across multiple pool accounts. The API key identifies which account the request applies to; it does not perform mining itself and does not alter the pool's payout calculation or a worker's accepted-share record.

API capabilities are not standardized across the industry. Some pools expose a narrow set of read endpoints, while others also support account-management actions. Readers should review the permission scope of any specific pool's API rather than assume a uniform level of access applies everywhere.

API Key vs. Worker Name vs. Wallet Private Key

Mining pool accounts involve several distinct credentials, and conflating them is a common source of confusion. The table below separates them by function.

Credential Purpose Used where Enter into ASIC configuration?
Stratum URL Pool server address and port ASIC or mining software network settings Yes
Worker name Identifies a specific miner, typically formatted as account.worker Attributes submitted shares to the account Yes
Worker password Pool-connection field; use varies by pool Sometimes used for pool-specific worker settings Sometimes
API key Authenticates API requests for the associated account or permitted scope External software, using the pool's documented authentication method No
API secret, where required Confidential value used to sign or authenticate API requests Trusted application code, such as a backend or local script; never public client-side code No
Pool account password Logs a user into the pool's website Website login only No
Wallet private key Cryptographic secret controlling bitcoin at an address Signing Bitcoin transactions Never

For example, ViaBTC's Bitcoin mining instructions direct a miner to configure an ASIC with a Stratum URL and a worker name in the format userID.workerID, noting that the worker password field is optional (ViaBTC BTC Mining Guide). An API key does not appear anywhere in that configuration; it belongs exclusively to software that calls the pool's API.

The underlying mechanics of pooled mining reinforce why these credentials are separate. A mining pool coordinates many devices submitting proof-of-work shares against a pool-assigned target, and the Stratum protocol is what delivers work to and collects shares from each worker (Bitcoin Developer Documentation: Mining). An API key plays no role in that share-submission process; it authenticates requests to the pool's account API, whose available data and actions depend on the pool and the credential's permissions.

How ViaBTC API Authentication Works

ViaBTC's API uses a key pair consisting of an API key and a secret key, generated from the account's API Management page. The API key is included in the X-API-KEY HTTP request header on every call. Certain endpoints also require a request signature: the application combines request parameters with a millisecond-precision timestamp (tonce) and computes an HMAC-SHA256 signature using the secret key, which is then sent in the X-SIGNATURE header (ViaBTC API Authentication). Not every endpoint requires a signature—some account-level queries authenticate with the API key alone—so the exact requirement depends on the endpoint being called.

ViaBTC also requires an IP whitelist to be configured before the API can be used, accepting up to 20 listed IP addresses, entered one per line, through the account's API settings (ViaBTC Help Center: What is API and How to Set Up). This means a request originating from an IP address outside the whitelist will be rejected even if the API key and signature are valid, which is a meaningful control for limiting where account data can be requested from.

One implementation detail worth noting for anyone comparing daily figures pulled from the API against internal records: ViaBTC's documentation states that daily data defaults to Beijing time (UTC+8), with a utc=true parameter available on endpoints that support it. Developers reconciling daily totals across time zones should account for this default rather than assume UTC (ViaBTC API Description).

Protecting a Mining Pool API Key

An API key is not a wallet private key and does not, by itself, let someone sign transactions from an external Bitcoin wallet. However, exposed API credentials may allow unauthorized access to account data. Some pool APIs also support changing payout addresses or requesting withdrawals; where those actions are permitted, misuse could affect pool-held balances or future payouts. The risk depends on the pool's API capabilities, the credential's permissions, and other security controls (Pool API Documentation).

Both the API key and any associated secret key should be kept confidential. Some endpoints require only the API key, so protecting the secret alone is insufficient. ViaBTC's account-information endpoint, for example, requires no signature; requests remain subject to its IP whitelist (ViaBTC Account Information API, ViaBTC API Authentication).

Practical measures worth considering include:

  • Create API credentials only for applications or integrations actually in use, rather than generating keys speculatively.
  • Avoid placing either the API key or its secret in screenshots, support tickets, chat messages, public code repositories, or public client-side website code.
  • Configure an IP whitelist where the integration runs from a stable, known set of outbound addresses, since this limits where valid credentials can be used from even if they are exposed.
  • Reset or delete credentials that are no longer needed, or that may have been exposed, rather than leaving them active indefinitely.
  • Review the permission scope and documentation for each endpoint before granting an application access to it.

ViaBTC's Help Center documents options to create, reset, and delete an API key pair, and advises keeping both the API key and secret key confidential (ViaBTC Help Center: What is API and How to Set Up). More generally, OWASP's guidance on secrets management recommends storing API keys and similar credentials in dedicated secrets-management systems rather than embedding them directly in application code or configuration files committed to version control (OWASP Secrets Management Cheat Sheet).

When You Need an API Key—and When You Do Not

A miner who only wants to point an ASIC or mining rig at a pool does not need an API key. Standard pool setup requires a Stratum URL and a worker name, and in some cases an optional worker password; this applies whether the operator is running a single device or a modest home-mining setup. An API key becomes relevant once there is a separate piece of software—a dashboard, a script, a reporting tool, or a custom application—that needs to pull account data from the pool automatically rather than through manual login.

Operations with many workers across one or more pool accounts are more likely to benefit from API access, since manually checking a web dashboard does not scale well once dozens or hundreds of workers are involved. For an individual or small-scale miner running a handful of devices, the pool's standard web interface is often sufficient, and generating API credentials without an actual integration to use them for adds an unnecessary credential to secure.

FAQ

Is a mining pool API key the same as a worker name?

No. A worker name identifies a specific mining device for the Stratum connection and share attribution, while an API key authenticates a separate application calling the pool's API for account data. They serve different functions and are configured in different places.

Do I need an API key to connect my ASIC to a mining pool?

No. Connecting mining hardware to a pool requires a Stratum URL and a worker name, and sometimes a worker password depending on the pool. An API key is not part of that connection process.

Is an API key the same as a Bitcoin private key?

No. A wallet private key is used to sign Bitcoin transactions. An API key authenticates requests to a pool's account API and does not grant the ability to sign transactions from an external wallet. Depending on permissions, however, some pool APIs can affect pool-held balances or payout settings.

What is the difference between an API key and an API secret?

In a key-pair authentication scheme such as ViaBTC's, the API key identifies the associated account, while the secret key is used to cryptographically sign requests where required. Not every pool uses a separate secret, and not every endpoint requires a signature. Keep both credentials confidential and provide them only to trusted integrations that need them.

What should I do if my API key or secret is exposed?

Revoke or reset the affected credentials through the pool's account settings as soon as possible. On ViaBTC, reset or delete the affected API key pair, then update any integrations that still need access with new credentials. Review account activity and, where relevant, payout settings for unexpected changes. An IP whitelist can limit where exposed credentials can be used, but it does not replace revoking or resetting them (ViaBTC Help Center: What is API and How to Set Up, OWASP Secrets Management Cheat Sheet).

References