Skip to content

Support binance-cli v2 in the Binance plugin - #682

Open
Xm798 wants to merge 2 commits into
1Password:mainfrom
Xm798:fix/binance-secret-key-env-var
Open

Xm798 wants to merge 2 commits into
1Password:mainfrom
Xm798:fix/binance-secret-key-env-var

Conversation

@Xm798

@Xm798 Xm798 commented Oct 9, 2026

Copy link
Copy Markdown

Overview

binance-cli v2.0.0, a Rust rewrite, reads the API secret from BINANCE_SECRET_KEY instead of BINANCE_API_SECRET. The release notes don't mention the rename, but the README does: compare v1.2.2 with v2.0.0. The latest release, v2.1.1, still uses BINANCE_SECRET_KEY. The plugin only provisioned BINANCE_API_KEY and BINANCE_API_SECRET, so binance-cli v2 got no secret, and every authenticated command failed with Unauthorized access. Authentication required. API-key format invalid.

The secret is now provisioned as both BINANCE_SECRET_KEY and BINANCE_API_SECRET, so the plugin works with v1 and v2 of binance-cli. The importer recognizes both names, trying each naming scheme separately the same way the AWS plugin handles its alternative variable names.

binance-cli v2 also adds the profile and completion subcommands. They manage local profiles and generate shell completion scripts without calling the Binance API, so they no longer require authentication. The existing rules for the v1 market data commands are unchanged. v2's public market data commands still ask for authentication: they share subcommands such as spot with signed commands, and the CLI is generated from Binance's OpenAPI specs with hundreds of commands, so listing them all would go stale with every release.

Ed25519 and RSA API keys are out of scope. binance-cli v2 accepts their private key (a file path or PEM content) in BINANCE_SECRET_KEY, but supporting that would mean changing the API Secret field, which is defined as 64 alphanumeric characters, so this PR doesn't cover it.

Type of change

  • Created a new plugin
  • Improved an existing plugin
  • Fixed a bug in an existing plugin
  • Improved contributor utilities or experience

How To Test

Unit tests:

go test ./plugins/binance/ -v

TestAPIKeyProvisioner checks that the secret is provisioned under both names. TestAPIKeyImporter covers importing from the v1 names, the v2 names, and both at once with different secrets. TestBinanceCLINeedsAuth covers the v1 and v2 commands that skip authentication, and checks that signed commands still require it.

End to end with binance-cli v2 (tested with v2.1.1) and a Binance API Key item:

op plugin init binance-cli
binance-cli spot get-account

Before the change, this failed with API-key format invalid. It should now return the account information.

Changelog

The Binance plugin now provisions BINANCE_SECRET_KEY, so binance-cli v2 can authenticate, and the v2 profile and completion commands no longer require authentication.

Xm798 added 2 commits October 9, 2026 09:07
binance-cli v2.0.0 reads the API secret from BINANCE_SECRET_KEY instead of
BINANCE_API_SECRET. Provision both variables so v1 and v2 work, and import
credentials from either naming scheme.
binance-cli v2 adds the profile and completion subcommands, which only manage
local configuration and shell completion. They don't call the Binance API.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant