← 1-Year PathQ3 · Algo

Week 34 — Bots & Exchange APIs

How trading bots are architected, and how they talk to exchanges through APIs.

Week 34 of 52 · ~7 hours · 13 slides · exam + project

📖 Study these courses this week

Complete these two courses, then do the Deep Dive below, pass the exam, and finish the project.

Automation Fundamentals

A bot is just your strategy, codified and run without emotion.

What you will learn

  • Understand bot architecture
  • Explain exchange APIs and keys
  • See where bots fail

The bot's loop

SignalEntryManageReviewA systematic, repeatable loop — no emotion, no guessing
The bot's loop

Securing API access

HASH 0transactionsBlock 1HASH 1transactionsBlock 2HASH 2transactionsBlock 3prevprevEach block stores the hash of the previous → tamper-evident chain
Securing API access

Bot architecture

A trading bot is a loop: fetch data (price, orders) → evaluate signals (your strategy) → decide (buy/sell/hold) → execute (place orders via API) → log (record for review). Everything else — indicators, risk checks — slots into this loop.

Exchange APIs

APIs let your bot talk to an exchange programmatically: read prices, check balances, and place/cancel orders. You authenticate with an API key (public ID) and a secret key (never share it). Set permissions to 'read + trade' but never 'withdraw' — that limits what a leaked key can do.

💡 Key security

A leaked API key with withdraw permissions = total loss. A leaked key with only trade permissions = someone can place bad trades, but can't steal funds. Scope your keys tightly, use IP allowlists, and rotate them. API security is custody security.

Where bots fail

Bots don't fail from bad code as often as from bad assumptions: overfit backtests (great in the past, dead in the future), ignoring fees/slippage, no kill-switch, or a strategy that works only in one regime. The bot is only as good as the strategy and the guardrails.

The honest truth about bots

A bot removes emotion and executes 24/7 — real advantages. But it cannot invent an edge. If the strategy loses money manually, it loses money faster automated. Bots amplify good process and bad process equally.

💡 Guardrails that matter

Every bot needs: a max position size, a max drawdown kill-switch, rate-limit handling, error logging, and a paper-trading mode first. Run any strategy on paper for weeks before real capital. The kill-switch is the most important line of code.

❓ Quick check

An API key should NEVER have which permission?

A) Read
B) Trade
C) Withdraw
D) None
(Knowledge check — full exam is next)

Key takeaways

  • Bot = data → signal → decision → execution → log loop
  • Scope API keys tightly (no withdraw), use IP allowlists
  • Bots amplify process — paper-trade first, build a kill-switch

📝 Weekly Exam — pass with 80% to unlock next week

10 questions. Review the Deep Dive and courses before attempting.

1. The core bot loop is:
The automation loop.
2. An API key is:
Programmatic access credential.
3. Never grant an API key which permission?
Withdraw is the danger.
4. A bot's biggest advantage is:
Removes emotion, runs always.
5. Overfitting means:
Curve-fit to history.
6. The most important line of a bot is:
Kill-switch protects capital.
7. A bot should always be run ___ first:
Paper-trade first.
8. If a strategy loses manually, automating it will:
Bots amplify bad process too.
9. Ignoring fees/slippage in a backtest causes:
Costs eat real returns.
10. IP allowlists on API keys:
Extra security layer.
Your score: —

🛠 Weekly Project

Paper-trade a simple rule with a bot mindset.

1
Define one simple rule (e.g., buy when price crosses above the 20-day MA, sell when below).
2
Backtest it by hand on a month of daily closes (10-15 data points).
3
Add a 0.5% fee/slippage per trade and recompute.
4
Write one sentence on whether the edge survived costs.
Open tool →
← Week 33  |  Week 35 →