DocsFeaturesKey management

Key management

Day-to-day key hygiene: splitting, rotation, leak handling. Creation steps live in “Create an API key”.

Splitting advice

  • One purpose, one key: separate keys for local dev, CI and production minimize blast radius
  • One group, one key: groups decide models and ratios; mixing causes “model unavailable / unexpected charges”
  • Set quotas or expiry on keys (as the console offers) as insurance for temporary uses

Leak handling

  1. 1
    Delete the key in the console immediately (revocation is instant).
  2. 2
    Create a new key and update every client / env var using it.
  3. 3
    Check usage logs for abnormal calls during the leak window.
Never commit to Git
A leaked sk- key in a public repo gets exploited by scanners within seconds. Use env vars or a secret manager.

Related