Key management
Day-to-day key hygiene: splitting, rotation, leak handling. Creation steps live in “Create an API key”.
Splitting advice
- One purpose, one key: separate keys for local dev, CI and production minimize blast radius
- One group, one key: groups decide models and ratios; mixing causes “model unavailable / unexpected charges”
- Set quotas or expiry on keys (as the console offers) as insurance for temporary uses
Leak handling
- 1Delete the key in the console immediately (revocation is instant).
- 2Create a new key and update every client / env var using it.
- 3Check usage logs for abnormal calls during the leak window.
Never commit to Git
A leaked
sk- key in a public repo gets exploited by scanners within seconds. Use env vars or a secret manager.