Skip to main content
Treat any key that lands in a commit, a ticket, a log, or client-side code as compromised. An enc_ key can spend your account’s credits until it is revoked, so act fast.

Contain it now

1

Revoke the exposed key

Revoke it from the dashboard’s API Keys page, or with revoke-key. Revocation is instant - the next request with that key returns 401.
2

Issue a replacement

Create a new key from the dashboard or the API, store it in your secret manager, and deploy it. The plaintext key is shown only once.
3

Check what it did

Review the key’s usage with list-keys - credits_used and last_used_at show whether it was abused before you revoked it.
Revoking a key cannot be undone, and any service still using it starts failing with 401. Deploy the replacement first where you can.

Limit the blast radius next time

Cap each key's spend

Set a per-key credit limit so a leaked key stops at a ceiling instead of draining your balance.

One key per service

Name keys by where they run (production-backend) so you can revoke one without disrupting the rest.

Keep keys out of code

Store keys in environment variables or a secret manager, never in source control or client-side code.

Watch for abnormal spend

Subscribe to the credits.low and credits.exhausted webhooks to catch a runaway key early.

Next steps

API keys & authentication

Create, rotate, and cap keys.

Credits

How spend and free repeats work.