enc_ key can spend your account’s credits until it is revoked, so act fast.
Contain it now
1
Revoke the exposed key
Revoke it from the dashboard’s API Keys page, or with
revoke-key. Revocation is instant - the next request with that key returns 401.2
Issue a replacement
Create a new key from the dashboard or the API, store it in your secret manager, and deploy it. The plaintext key is shown only once.
3
Check what it did
Review the key’s usage with
list-keys - credits_used and last_used_at show whether it was abused before you revoked it.Limit the blast radius next time
Cap each key's spend
Set a per-key credit limit so a leaked key stops at a ceiling instead of draining your balance.
One key per service
Name keys by where they run (
production-backend) so you can revoke one without disrupting the rest.Keep keys out of code
Store keys in environment variables or a secret manager, never in source control or client-side code.
Watch for abnormal spend
Subscribe to the
credits.low and credits.exhausted webhooks to catch a runaway key early.Next steps
API keys & authentication
Create, rotate, and cap keys.
Credits
How spend and free repeats work.