What a read-only API key is
An API key is a pass that lets an app talk to your account without your password. A read-only one can look, never touch, which is all Allown ever asks for.
A pass, not your password
Exchanges and brokers let you create API keys: a pair of codes an app uses to reach your account. Unlike your password, a key can be limited to exactly what the app needs, and deleted any time without changing anything else.
Read-only means look, don't touch
When you create a key you choose what it may do: read balances and history, trade, or withdraw. A read-only key can only read. Even if someone stole it, they couldn't trade or move a cent.
Allown checks every key when you connect it and refuses any that can trade or withdraw.
Why the secret is shown once
The second code, the secret, signs every request so nobody can forge one. The exchange shows it only once and doesn't keep a readable copy. Allown stores it encrypted and never shows it again.