Deriv OAuth login explained for BancaBot traders
Deriv OAuth login explained in plain words: what the permission screen asks for, what trading only means, and what BancaBot can never do with your account.
Here is Deriv OAuth login explained in plain words. When you sign in with Deriv on BancaBot, you are taken to a screen hosted by Deriv, you approve one permission called trading, and you come back signed in. BancaBot never sees your password. It can read your account balance and place trades. It cannot withdraw and it cannot move money anywhere.
That is the whole thing. The rest of this post explains what each part of the screen means, what happens if you approve it, and how to take the permission back.
OAuth means you type your password on Deriv, not on BancaBot
OAuth is the method used when one site needs to act on your account at another site without being handed your login details. You click sign in with Deriv, your browser goes to Deriv, and you log in there the way you always do. Deriv asks whether you want to let the app in. If you say yes, Deriv hands BancaBot a token for your account.
The important part is where you typed your password. You typed it on Deriv's own page. BancaBot is not in the middle of that, does not store it and cannot read it. If a tool ever asks you to type your Deriv password into its own form, that is not OAuth and you should close the tab.
Before you approve anything, look at the address bar and check you are on Deriv's domain. That one habit is worth more than any amount of reading about security.
Trading only is the permission you are approving
The permission BancaBot asks for is trading. In practice that covers two things: reading your account so balance and account type can be shown on screen, and placing contracts on the markets you choose.
What trading does not cover matters more:
- It cannot withdraw funds from your Deriv account.
- It cannot transfer money between your accounts or to anyone else.
- It cannot change your Deriv password, email or any account setting.
- It cannot see your password at any point, because your password was never sent to it.
- It cannot verify your identity, open accounts for you or touch your documents.
So the worst a trading permission can do is trade. That is not nothing. A tool with trading access can lose money for you if you point it at the wrong market or leave it running without limits. The permission screen is about who can act on your account. It is not a promise about outcomes, and trading on Deriv loses money for many people.
Real and demo accounts both work, and demo is where to start
After you sign in, you pick which Deriv account the tool acts on. Deriv gives you a demo account alongside any real account, and both appear once you have approved the permission. The demo account trades the same synthetic indices with the same contract types and no real money is at stake.
Start there. Watch a signal, watch what the Auto Trader does with a loss limit and a target set, watch how a bot behaves on a Volatility index for a while. Then decide whether you want to switch the same connection to a real account. If you have not opened or verified your Deriv account yet, the guide on creating a Deriv account covers opening it and switching between real and demo.
What the connection is used for across the BancaBot tools
The same signed in session is what the different parts of BancaBot use, and each one uses it differently.
AI Signals reads the market and shows one call per market with the reasoning behind it. It does not need to place anything. You look at the read and you decide what to do with it.
Auto Trader is the part that actually places trades from those signals. It stops at the limits you set, including a loss limit and a target, and those limits are the reason the permission is worth granting rather than clicking manually. Set them before you start, not after.
Digit Trader and the digit analyzer read the last digits of Deriv's synthetic indices and show one pick for the next tick, with every card that led to it. Bot Forge is the block based builder with a library of free bots you can load, change and run, and it reads bot files from the older builders, so an existing XML file is not wasted.
You can take the permission back at any time
The token is not permanent and it is not yours to lose. Two things end the connection. You can log out inside BancaBot, which drops the session in your browser. You can also go into your Deriv account settings, find the list of connected apps, and revoke the authorisation there. Revoking on Deriv's side is the stronger option, because it ends the permission regardless of what any other device is doing.
It is sensible to look at that list occasionally, the same way you would look at the apps connected to an email account. Anything you no longer use, remove. Nothing breaks when you do, and you can sign in with Deriv again whenever you want.
What to check before you approve the screen
Read the screen rather than clicking through it. Three things are worth a second each.
- The domain in the address bar is Deriv's own.
- The app name shown is the one you meant to connect.
- The permission listed is trading, not something broader.
Then look at the thing the permission is for. A trading connection is only as careful as the limits you set on it. A stop loss and a target are what decide when the trading stops, and that applies to the Auto Trader and to any bot you load. The signals, the analyzer and the free bot library are free to use, and the guides need no account at all, so you can read everything before you connect anything. Paid plans cover the premium bots, and the pricing is on the site.
When you are ready, open the signals screen, sign in with Deriv, and point the connection at your demo account first.
Questions
Can BancaBot withdraw money from my Deriv account?
No. The permission approved on the Deriv OAuth screen is trading only, which allows reading the account balance and placing trades. It does not allow withdrawals or transfers of any kind. Moving money in or out of your Deriv account is something only you can do, inside Deriv.
Does BancaBot see my Deriv password?
No. You type your password on Deriv's own page, not on BancaBot. Deriv then hands back a token that allows trading on the account you chose. The password is never sent to BancaBot and cannot be stored by it.
How do I disconnect BancaBot from my Deriv account?
You can log out inside BancaBot to end the session in your browser. For a full disconnect, open your Deriv account settings, find the list of connected apps and revoke the authorisation there. You can sign in with Deriv again later if you want to.
Can I use a demo account with the Deriv OAuth login?
Yes. Real and demo accounts both work once the permission is approved, and you choose which account the tools act on. A demo account is the sensible place to start, because the markets and contract types are the same while no real money is at stake.
Trading on Deriv puts your money at risk, and automation does not change that. Practise on a demo account first and only trade money you can afford to lose.
Try this on your own account
Every tool in this post is free on a Deriv demo account. Log in with Deriv and nothing else is needed.