Audits › hummingbot/hummingbot › Coinbase
Bot × exchange
Does hummingbot work with Coinbase?
The hummingbot README names Coinbase as a supported exchange (README scanned 2026-09-17). We did not run the bot against Coinbase: this page reports what the public code says and what the exchange itself publishes.
Coinbase facts
- CoinGecko trust score
- 10 / 10 · rank 2
- Country
- United States
- Established
- 2012
- 24h volume (BTC, normalized)
- 0
- Puerto Rico residents
- Not verified: the eligibility page returned an access error (HTTP 403) on the check date (source, 2026-09-17)
- Derivatives
- Regulated futures through Coinbase Financial Markets; global perpetuals since June 2026 (source, 2026-09-17)
- Official API
- Yes (Advanced Trade API); futures access for U.S. territories not confirmed (source, 2026-09-17)
Exchange data: CoinGecko public API and the exchange's own endpoints, 2026-09-17. More on the Coinbase page.
What the audit says about running it live
From the hummingbot audit (2026-09-17), the controls that matter most once a live API key is connected:
| Control | Verdict | Evidence |
|---|---|---|
| API key permissions | Partial | GET /search/code?q="/withdraw" repo:hummingbot/hummingbot path:connector -> total_count 0 (2026-09-17) |
| Orphaned stop-loss | Absent | hummingbot/strategy_v2/executors/position_executor/position_executor.py, constructor: raises ValueError unless triple_barrier_config.stop_loss_order_type == OrderType.MARKET ("Only market orders are supported for time_limit and stop_loss") |
| Websocket and data reconnection | Partial | hummingbot/core/api_throttler/async_throttler.py (AsyncRequestContext.within_capacity, rate-limit waiting); hummingbot/core/web_assistant/connections/ws_connection.py (detects closed socket, raises ConnectionError, handles ping/pong) |
| Order rejection handling | Present | hummingbot/connector/client_order_tracker.py, process_order_not_found() |
| Position reconciliation with the exchange | Partial | hummingbot/connector/client_order_tracker.py, restore_tracking_states() and process_order_not_found() (lost_order_count_limit=3) |
Before you connect a key
- Create the API key with trading enabled and withdrawals disabled, and restrict it to your server's IP if Coinbase allows it.
- Start in paper or dry-run mode if the bot has one (the README mentions it).
- Decide the maximum loss per day before the first order and check the bot can enforce it: see the circuit breaker control. If it cannot, the watchdog enforces it from outside with a read-only key.