Hyperliquid does not issue a classic exchange key. You authorize an agent. That agent signs. The master wallet keeps the funds.
TrustAlgo executes on that signature. The node is a seat on your account, not a wallet we hold. Collateral stays where you deposited it.
On app.hyperliquid.xyz/API, name the wallet, generate it, and copy the private key before you authorize. Hyperliquid shows it once. Default validity is 90 days. The maximum is 180.
The API wallet cannot withdraw and cannot move collateral. Revoke it on the same API page. If the key is lost, generate a new wallet. Do not reuse a deregistered agent address.
Info requests still use the master address. The agent address is only the signer.