This is a pure how-to: the exact screens, buttons, and settings you’ll click through to connect Bitsgap to Bybit, written for someone who wants the walkthrough itself rather than background on why the pairing is worth doing. If you already know you want Bitsgap running bots against your Bybit account and just need the connection steps plus what to do when something doesn’t work, this is that page. We’ll cover account prerequisites, the exact API scopes to select, the connection screen in Bitsgap, and a dedicated troubleshooting section for the errors people actually run into. As you get your accounts linked, the Free BTC AI Predictor is worth having open in another tab so you have a directional reference once you’re ready to configure your first bot.
Recommended exchange
Bybit
800+ coins on spot at 0.10%, USDT perps at 0.02% maker / 0.055% taker, free Grid/DCA/Combo bots, copy trading, TradFi CFDs (SpaceX xStocks, Apple, NVIDIA), and Unified Trading Account. Not available to US, Canada, UK, Singapore, Hong Kong, or Mainland China residents — EEA users use bybit.eu instead.
Before You Start: What You Need
You need an active Bybit account that has completed at least the identity verification tier required to generate API keys — most Bybit accounts enable this after basic KYC. You’ll also want a Bitsgap account, which you can create for free and upgrade later; the 7-day free Pro trial requires no card, so there’s no reason to delay creating one while you sort out the Bybit side. Have a password manager or secure notes app ready, because Bybit shows the API secret exactly once at creation time, and you cannot view it again afterward. Finally, know which permissions you’re going to select in advance — read and trade only, never withdrawal — so you’re not making that decision under time pressure while a Bitsgap tab is waiting.
This walkthrough assumes you’re connecting from a region where Bybit accepts retail accounts. Bybit does not serve the United States, United Kingdom, Canada, Singapore, Hong Kong, mainland China, or Japan, and if you’re in one of those jurisdictions, none of the steps below will work because you won’t be able to complete Bybit’s own account verification or reach the API Management screen in the first place. EU/EEA residents are directed to bybit.eu, a separately licensed MiCA-regulated entity with its own account structure — if that’s your situation, treat this guide as directionally useful but verify the exact screen layout and permission names against bybit.eu’s own interface, since a separately regulated platform can differ in small but meaningful ways from the main Bybit product referenced throughout this walkthrough. If you’re in a restricted region entirely, Coinbase remains a workable alternative exchange to pair with a bot platform instead.
Try it free
Bitsgap
Run GRID, DCA, COMBO, and BTD bots across 15+ exchanges from one dashboard. 7-day free trial, no card needed.
Step 1: Open API Management on Bybit
Log into your Bybit account and look for your profile icon or account menu, typically in the top-right corner of the interface. From there, find API Management — on most versions of the platform this sits under account settings or a dedicated “API” tab. Click Create New Key. Bybit will usually ask you to choose between a “System-generated” key (Bybit generates both the key and secret for you) and a “Self-generated” key (you provide your own public key for advanced use cases like IP-bound signature verification). For a standard Bitsgap connection, choose the system-generated option — it’s simpler and is what nearly every third-party bot platform expects.
Step 2: Set the Exact API Scopes
This is the step to slow down on. Bybit will present a list of permission checkboxes, typically grouped by product (Spot, Derivatives, Wallet, etc.). For a Bitsgap connection, you want:
- Read — enabled, so Bitsgap can pull your balances, open orders, and trade history.
- Trade (sometimes labeled “Orders” or “Trade” per product line) — enabled for whichever markets you intend to bot (Spot, USDT Perpetual, etc.).
- Withdrawal — disabled. Always. There is no configuration of a grid, DCA, or combo bot that requires this permission, and enabling it turns a leaked key into a direct financial loss rather than a contained inconvenience.
If Bybit’s interface separates permissions by product line (for example, separate toggles for Spot Trade and Derivatives Trade), only enable the ones matching the markets you’ll actually bot. If you’re only running spot grid bots, there’s no reason to also enable derivatives trading permission on that key — narrower scope is safer scope. Bybit also typically offers an IP restriction field here; if you’re comfortable finding Bitsgap’s published IP ranges (available in Bitsgap’s own connection help documentation), add them now. This step is optional but meaningfully reduces risk.
A useful mental checklist before clicking the final save button: read is on, trade is on for the products you’ll actually bot, withdrawal is off, transfer (if shown separately) is off, and IP restriction is either applied correctly or intentionally left open because you’re not ready to manage a whitelist yet. Screenshotting this permissions screen for your own records before saving is a small habit that pays off later if you ever need to audit exactly what a given key was authorized to do, particularly if you end up creating several keys for different bot platforms or strategies over time.
Step 3: Generate, Copy, and Store the Key
Click through to generate the key. Bybit displays the API Key and API Secret together, one time only. Copy both immediately — the API Key is typically visible again later in your API Management list, but the API Secret is not; if you leave the screen without copying it, your only option is deleting that key and starting over. Paste both into a password manager entry labeled clearly (e.g., “Bybit — Bitsgap bot key”) so future-you doesn’t have to guess which key belongs to which service if you end up managing more than one.
Step 4: Add Bybit as an Exchange in Bitsgap
Log into Bitsgap and find Add Exchange — typically a button on the main dashboard or under an “Exchanges” tab in account settings. Select Bybit from the exchange list (it’s alphabetically sorted in most versions, so scroll to “B”). Bitsgap will present two fields: API Key and API Secret. Paste in exactly what you copied from Bybit in Step 3 — check for accidental leading or trailing spaces, which is one of the most common causes of a failed connection. Click Connect or Save.
Step 5: Verify the Connection
Bitsgap will attempt to authenticate immediately and, on success, pull your current Bybit balance into its dashboard. This is your confirmation the connection worked: if you see your actual USDT or asset balance reflected accurately, the API key has the correct read permission and the secret was entered correctly. At this point no bot is running — you’ve only established visibility and trade authorization. Nothing moves until you explicitly create and activate a bot.
Recommended exchange
Bybit
800+ coins on spot at 0.10%, USDT perps at 0.02% maker / 0.055% taker, free Grid/DCA/Combo bots, copy trading, TradFi CFDs (SpaceX xStocks, Apple, NVIDIA), and Unified Trading Account. Not available to US, Canada, UK, Singapore, Hong Kong, or Mainland China residents — EEA users use bybit.eu instead.
Troubleshooting Common Connection Errors
“Invalid API key” or “Authentication failed.” This almost always means the key or secret was copied with an extra space, a missing character, or copied from the wrong field. Go back to Bybit’s API Management screen, and if you still have access to the secret (only possible if you haven’t left the screen since creation), re-copy carefully. If the secret is no longer visible, delete the key and generate a fresh one — there’s no way to recover a lost secret.
“Insufficient permissions” or a similar trade-execution error appearing after the connection succeeds. This typically means the key connected with read permission but trade permission wasn’t actually saved on the Bybit side. Return to API Management, open the key’s settings, confirm the trade checkbox is checked and saved, and if it doesn’t hold, delete and recreate the key with permissions selected before the final save click rather than after.
Connection succeeds but balance shows zero or incorrect. Confirm you’re looking at the correct account type inside Bybit — Unified Trading Account balances versus older Funding or Spot wallet balances can display differently depending on where your funds actually sit. Bitsgap typically reads from the Unified Trading Account; if your funds are sitting in a separate wallet within Bybit, transfer them internally first.
IP whitelist errors. If you enabled IP restriction on the API key and then see connection failures, it usually means Bitsgap’s published IP list changed or you copied it incorrectly. Either re-verify the current IP list from Bitsgap’s documentation and update the whitelist on Bybit, or temporarily remove the IP restriction, confirm the connection works without it, and re-add the restriction carefully afterward.
Bot fails to place orders after a successful connection. This is often a minimum order size or minimum notional issue rather than a connection problem — Bybit enforces minimum trade sizes per pair, and a grid or DCA bot configured with too little capital per order can silently fail to execute. Check the pair’s minimum order requirements on Bybit and increase your per-grid or per-order capital allocation accordingly.
Region or account-eligibility errors. If Bybit itself won’t let you complete account verification or generate an API key at all, this is very likely a regional restriction rather than a technical bug — Bybit does not serve retail users in the US, UK, Canada, Singapore, Hong Kong, mainland China, or Japan, and no amount of retrying the connection steps will resolve that.
Connection works, but the bot placed far fewer trades than expected. This is usually not an error at all but a mismatch between your grid or DCA range and actual market behavior — if price hasn’t moved through your defined bounds, the bot simply has nothing to execute yet. Check your chosen range against the pair’s recent 30-60 day price history in Bitsgap’s own charting before assuming the connection itself is broken.
“Rate limit exceeded” errors during setup. Bybit’s API enforces rate limits on how many requests can be made in a given time window. This is rarely an issue during normal Bitsgap usage since Bitsgap manages request pacing internally, but if you’re also using the same API key with another tool or script simultaneously, you can hit limits faster than expected. Keep bot-platform API keys dedicated to a single consumer rather than sharing them across tools.
Key shows as connected in Bitsgap but stops updating balances after a few days. This can happen if the key was deleted or had permissions changed on the Bybit side without updating Bitsgap, or if Bybit required a re-verification step on the account that silently paused API access. Log into Bybit directly, confirm the key still exists and shows recent activity in the API Management list, and recreate the connection in Bitsgap if anything looks stale.
Try it free
Bitsgap
Run GRID, DCA, COMBO, and BTD bots across 15+ exchanges from one dashboard. 7-day free trial, no card needed.
API Scopes Reference: What Each Permission Actually Does
It’s worth understanding exactly what each Bybit API permission controls, since the labels can vary slightly across interface updates. Read grants visibility into account balances, open positions, and order/trade history — it cannot place, modify, or cancel anything on its own. Trade grants the ability to place new orders, modify existing ones, and cancel orders — this is the permission that actually lets Bitsgap’s bots function, since a grid or DCA bot is fundamentally a continuous stream of order placements and cancellations. Withdrawal grants the ability to move funds off the exchange to an external address — this is the permission you never grant to a bot platform, regardless of how convenient it might sound for consolidating funds automatically. Some Bybit interface versions also expose a Transfer permission for moving funds between sub-accounts or wallet types within Bybit itself; treat this with the same caution as withdrawal unless you specifically understand why a bot platform would need it, which for standard grid/DCA use cases, it does not.
It’s also worth understanding the difference between account-level and sub-account-level API keys if your Bybit setup includes sub-accounts. Bybit allows creating API keys scoped to a specific sub-account rather than the master account, which can be useful if you’re running Bitsgap bots on a segregated pool of capital separate from your main holdings. This adds an extra layer of containment: even a fully compromised bot API key with trade permission only affects the sub-account it’s scoped to, not your entire Bybit balance. This is a more advanced setup than most first-time connections need, but it’s worth knowing the option exists once you’re running meaningful capital through automated strategies.
Another scope-related detail worth flagging: Bybit periodically updates its API interface and permission naming as it rolls out new products, so a screen described here as “Derivatives Trade” might appear under a slightly different label depending on when you’re reading this. If a permission name doesn’t match exactly, look for the closest conceptual match (trading versus withdrawing versus transferring) rather than assuming the feature has been removed — exchange interfaces get relabeled far more often than the underlying permission model actually changes.
Fee Context Once You’re Connected
Once the connection is live and you’re ready to deploy a bot, remember that Bybit’s own trading fees apply to every order the bot places — 0.10% maker/taker on spot, 0.02% maker / 0.055% taker on USDT perpetuals, and 0.01%/0.06% on inverse perpetuals — on top of whichever Bitsgap subscription tier you’re on (Basic $29/month, Advanced $69/month, or Pro $149/month, with about 20% off annual billing). None of the connection steps above change that fee structure; you’re simply automating orders that would otherwise incur the exact same fees if placed manually. BIT token holders get a further 10% discount stacked on top of whichever base tier applies, which is worth factoring in if you’re already holding the token or considering it for fee reduction on higher-frequency bot strategies.
A quick sanity check worth running after your first week of live bot activity: pull your trade history from Bybit directly (visible in the same account area as API Management) and compare the cumulative fees shown there against what you’d estimate from the published fee schedule for the number of orders your bot executed. This lets you confirm the connection is behaving exactly as expected — no unexpected fee tier, no unexpected order sizing — before you scale up capital allocation to the bot.
Once your first bot is live, the Free BTC AI Predictor can help you decide whether current momentum favors the range-bound conditions a grid bot needs, or whether a trending market calls for a different approach.
FAQ
Why does Bitsgap ask for an API secret instead of just a password?
API keys and secrets are a standard, more secure way for one platform to authorize another to act on its behalf without sharing your actual account password. The key/secret pair can be scoped to specific permissions (read, trade, no withdrawal) and revoked instantly without affecting your Bybit login credentials.
What do I do if I already lost my API secret?
There’s no way to recover a lost secret — Bybit only displays it once, at creation. Delete the affected API key from your Bybit account and generate a new one, then reconnect it in Bitsgap using the new credentials.
Why does my Bitsgap dashboard show a different balance than what I see on Bybit?
This is usually a wallet-type mismatch — Bitsgap typically reads your Unified Trading Account balance, while older Bybit interfaces sometimes separate Funding and Spot wallets. Check which wallet your funds are actually sitting in and transfer internally within Bybit if needed.
Is it safe to enable IP whitelisting for my API key?
Yes, and it’s recommended as an extra security layer. Just make sure you’re using Bitsgap’s current published IP ranges, since an outdated or incorrect IP list will cause connection failures rather than improving security.
How often should I regenerate my API key?
There’s no fixed rule, but many careful traders rotate keys every few months as routine hygiene, deleting the old key only after confirming the new one connects successfully in Bitsgap.
Does connecting Bitsgap to Bybit cost anything by itself?
No, the connection itself is free. You only pay Bybit’s standard trading fees on executed orders and whatever Bitsgap subscription tier you choose — the API connection has no separate cost.
Can I connect Bitsgap to Bybit from a restricted country using a VPN?
This guide does not recommend attempting to bypass Bybit’s regional restrictions. Bybit does not serve retail users in the US, UK, Canada, Singapore, Hong Kong, mainland China, or Japan, and circumventing those restrictions can violate the exchange’s terms of service and put your account and funds at risk.
What should I do immediately after successfully connecting the two accounts?
Before creating any bot, review your Bybit API Management screen one more time to confirm the permission set matches exactly what you intended — read and trade enabled, withdrawal disabled. Then check Bitsgap’s dashboard balance against your actual Bybit balance to confirm the numbers match, and only then move on to configuring your first bot with a modest starting allocation.
Related on NeuralMindMastery
- Bybit Review 2026: Full Platform Breakdown
- Bitsgap Review 2026: Full Platform Breakdown
- Bybit Grid Bot Guide 2026
- AI Trading Bots Comparison Tool
This is not financial advice. Always verify permission settings carefully before connecting any third-party platform to an exchange API. Bybit is unavailable to residents of the US, UK, Canada, Singapore, Hong Kong, mainland China, Japan, and sanctioned regions; EU/EEA residents must use the separately regulated bybit.eu.