No keys in the APK
User Coinbase API credentials are not bundled into the app package. They are imported locally by the user after installation.
Security / local-first
Citrine is built around a simple principle: users import their own Coinbase API credentials after installation, and the automation runtime operates on the Android device.
User Coinbase API credentials are not bundled into the app package. They are imported locally by the user after installation.
Citrine Edge does not need to receive or store user API keys for the Android runtime to operate.
Citrine expects Android lockscreen security and uses biometric/app-lock protection for access to the terminal.
Model comparison
This is a fair comparison, not a scare tactic. Cloud bots can be legitimate products; Citrine is simply designed for users who prefer local control and no cloud key custody.
User responsibilities
Keep your phone secure, keep notifications visible, keep the app allowed to run in the background, and revoke API keys directly at Coinbase if your device is lost or compromised.
Create keys with only the permissions needed for your intended workflow. Avoid withdrawal or transfer permissions.
If anything looks wrong, stop automation, check your Coinbase account directly, and revoke the key from official Coinbase settings.
Use Android lockscreen security, biometrics, operating system updates, and careful device handling.
Local automation depends on battery state, connectivity, notification permission, and Android background behavior.
Launch access
Review the setup guide before joining the launch list.