Next funding settles in --:--:--Same $10,000 MAGIC long, one week: $269 more on Bitget than on OKXOpen OKX →

· four exchange APIs · rebuilt daily

What to Check Before You Open a Derivatives Account — Bitget

Ten minutes of setup before you fund anything saves the two most expensive mistakes new derivatives traders make.

What to Check Before You Open a Derivatives Account

Most guides start at "click sign up". That is the least important step. Here is what actually determines whether the account works out.

Email / Mobileyou@yourmail.comReferral codearrives with the linkI agree to the User AgreementI agree to the Privacy PolicyI am over 18Marketing email — pre-tickedNextorGoogleApple IDTelegramSocial sign-in often drops the referral code.
Password rules8 to 32 charactersAt least one numberAt least one uppercase letterAt least one special characterOnly these special characters are accepted~`!@#$%^&*()_-+={}[]|;:,<>.?/Anything outside this set is rejected without telling you which character failed.

What the screen actually shows (checked 2026-08-28):

- One Email/Mobile field. A phone number goes in without the country code. - Referral code sits in a collapsed row above the checkboxes. It is closed by default and easy to scroll past — open it and check the code is there before continuing. - Three checkboxes are required: User Agreement, Privacy Policy, and being over 18. - A fourth, marketing email, is ticked for you. Untick it if you do not want it; it does not affect the account. - Google, Apple and Telegram sign-in sit under the Next button. Using one frequently drops the referral code, and there is no error when it happens — the account opens normally and the rebate simply never applies. - The password rule is 8-32 characters with at least one number, one uppercase letter and one special character, and the accepted special characters are a fixed list: ~`!@#$%^&*()_-+={}[]|;:,<>.?/ — a character outside it is rejected without saying which one. - An image puzzle follows: pick the tile matching the icon shown in the corner. - Then a six-digit code by email or SMS, with a countdown of under a minute and a resend link. - After signing in, a banner reads Complete identity verification to unlock all features. The account exists but cannot deposit or trade until that is done.

*Interfaces change. This was browsed bitget.com/register, and a published third-party walkthrough reviewed 2026-08-28; UI facts only, wording and images not reused; if what you see differs, trust the exchange.*

1. Check whether the venue is authorised where you live

This is not a formality. Exchanges are licensed jurisdiction by jurisdiction, and using one that is not authorised in your country can mean no legal recourse if something goes wrong, sudden withdrawal restrictions, or the app disappearing from your store overnight. Check the exchange's own terms for restricted jurisdictions, and check your national regulator's register. If your jurisdiction is restricted, stop here. Nothing below is worth the exposure.

2. Decide your loss budget before you see a chart

Write down a number you can lose entirely without changing your life. That number is the account. Not "the amount I'll start with and top up later" — the total. Every sizing decision later refers back to it, and if you skip this step you will size against your net worth by accident.

3. Set up security before you deposit, not after

Where the security settings liveHome›Profile›Security

Three things, once, in this order:

  1. Authenticator-app 2FA, not SMS. SIM-swap attacks are the single most common way retail crypto accounts are drained. An authenticator app removes that path entirely.
  2. Withdrawal address whitelist. Once enabled, withdrawals can only go to addresses you pre-approved, usually with a 24-hour delay on adding new ones. This converts "attacker drains account instantly" into "attacker waits 24 hours while you get an email."
  3. Anti-phishing code. A phrase you choose that appears in every genuine email from the exchange. Any email without it is a phishing attempt, and phishing is how most account compromises begin.
Account securityPasskeyRecommendedNOT SETGoogle AuthenticatorGates withdrawals — set it before you depositNOT SETEmailAlready set at signupSETMobile numberNOT SETYou can deposit and trade with none of these. Withdrawals are what two-factor gates.
Add the key to your authenticatorSetup keyIBBCH·········Copy keyScanning is faster. Copying is what saves you if the phone is lost — support cannot rebuild this key.Turn off cloud sync in the authenticator: codes that can be recovered are also codes a compromised account can produce.

4. Understand what you are being charged before you trade

Two numbers matter and most people never look them up: the taker fee (crossing the spread) and the maker fee (posting a resting order). These are Bitget's own published futures rates: taker 0.03%, maker 0.02%. At 10x, a taker round trip therefore costs 0.6% of your margin before the market has moved at all. Run your own numbers in the fee calculator.

5. Know which product you are opening

Spot, perpetual futures, and copy trading are three different risk profiles sharing one login. Spot cannot liquidate you. Perpetuals can, and will, if you size wrong. Copy trading hands sizing decisions to someone whose drawdown you have not examined. Open the account, but do not assume the default product is the one you want.

What the screen actually shows (checked 2026-08-28):

- The account works before any of this is set up. You can deposit and trade with nothing but a password — withdrawals are what two-factor gates, which is why it is worth doing before you fund the account rather than after. - The profile icon is top-left on the app home. Tapping the arrow beside your username opens Profile, Security and Notifications tabs. - The Security tab shows a Verification method count out of eight. Passkey and Google Authenticator are both marked Recommended and both start unset. - Bitget states plainly what the authenticator code is used for: login, withdrawals, and changing security methods. Losing it locks you out of all three. - Binding runs 1/3 download the app, 2/3 add the key, 3/3 enter a code. Google Authenticator and Microsoft Authenticator are both offered and either works. - Step 2/3 shows a QR code and a Copy key button beside it. Copy that key and store it somewhere that is not the phone. Scanning the QR is faster, but if the phone is lost or wiped, the key is the only way to rebuild the code on a new device — and support cannot recreate it for you. - An email code is required before the binding starts, valid for under a minute with a resend link. - Bitget's own closing note is worth following: turn off cloud sync in Google Authenticator. Sync makes the codes recoverable, which also means a compromised Google account is enough to produce them. - The profile header shows Verified or Unverified, which is how to check whether identity verification actually went through rather than guessing from the absence of a banner.

*Interfaces change. This was a published third-party walkthrough reviewed 2026-08-28; UI facts only, wording and images not reused; if what you see differs, trust the exchange.*

What to do next

Nothing, for 24 hours. Set up security, leave the account unfunded, and come back. The urge to deposit immediately is the same urge that later becomes the urge to average down.

The full Bitget track

1What to Check Before You Open a Derivatives AccountSigned up2Exchange KYC: What It Needs, How Long It Takes, What Gets RejectedIdentity verified3Depositing USDT Without Losing It: Networks, Memos and the Test TransferFirst deposit4Your First Perpetual Trade, Step by StepFirst trade5The Five Mistakes Almost Everyone Makes in Week OneTrading week one