A bot is just your strategy, codified and run without emotion.
What you will learn
Understand bot architecture
Explain exchange APIs and keys
See where bots fail
The bot's loop
The bot's loop
Securing API access
Securing API access
Bot architecture
A trading bot is a loop: fetch data (price, orders) → evaluate signals (your strategy) → decide (buy/sell/hold) → execute (place orders via API) → log (record for review). Everything else — indicators, risk checks — slots into this loop.
Exchange APIs
APIs let your bot talk to an exchange programmatically: read prices, check balances, and place/cancel orders. You authenticate with an API key (public ID) and a secret key (never share it). Set permissions to 'read + trade' but never 'withdraw' — that limits what a leaked key can do.
💡 Key security
A leaked API key with withdraw permissions = total loss. A leaked key with only trade permissions = someone can place bad trades, but can't steal funds. Scope your keys tightly, use IP allowlists, and rotate them. API security is custody security.
Where bots fail
Bots don't fail from bad code as often as from bad assumptions: overfit backtests (great in the past, dead in the future), ignoring fees/slippage, no kill-switch, or a strategy that works only in one regime. The bot is only as good as the strategy and the guardrails.
The honest truth about bots
A bot removes emotion and executes 24/7 — real advantages. But it cannot invent an edge. If the strategy loses money manually, it loses money faster automated. Bots amplify good process and bad process equally.
💡 Guardrails that matter
Every bot needs: a max position size, a max drawdown kill-switch, rate-limit handling, error logging, and a paper-trading mode first. Run any strategy on paper for weeks before real capital. The kill-switch is the most important line of code.
❓ Quick check
An API key should NEVER have which permission?
A) Read
B) Trade
C) Withdraw
D) None
Withdraw permission = catastrophic if leaked.
(Knowledge check — full exam is next)
Key takeaways
Bot = data → signal → decision → execution → log loop
Scope API keys tightly (no withdraw), use IP allowlists
Bots amplify process — paper-trade first, build a kill-switch
📝 Weekly Exam — pass with 80% to unlock next week
10 questions. Review the Deep Dive and courses before attempting.
1. The core bot loop is:
The automation loop.
2. An API key is:
Programmatic access credential.
3. Never grant an API key which permission?
Withdraw is the danger.
4. A bot's biggest advantage is:
Removes emotion, runs always.
5. Overfitting means:
Curve-fit to history.
6. The most important line of a bot is:
Kill-switch protects capital.
7. A bot should always be run ___ first:
Paper-trade first.
8. If a strategy loses manually, automating it will:
Bots amplify bad process too.
9. Ignoring fees/slippage in a backtest causes:
Costs eat real returns.
10. IP allowlists on API keys:
Extra security layer.
Your score: —
🛠 Weekly Project
Paper-trade a simple rule with a bot mindset.
1
Define one simple rule (e.g., buy when price crosses above the 20-day MA, sell when below).
2
Backtest it by hand on a month of daily closes (10-15 data points).
3
Add a 0.5% fee/slippage per trade and recompute.
4
Write one sentence on whether the edge survived costs.