> ## Documentation Index
> Fetch the complete documentation index at: https://docs.encrata.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Handle a leaked API key

> What to do the moment an Encrata API key is exposed, and how to limit the damage next time.

Treat any key that lands in a commit, a ticket, a log, or client-side code as compromised. An `enc_` key can spend your account's credits until it is revoked, so act fast.

## Contain it now

<Steps>
  <Step title="Revoke the exposed key">
    Revoke it from the dashboard's API Keys page, or with [`revoke-key`](/api-reference/endpoint/revoke-key). Revocation is instant - the next request with that key returns `401`.
  </Step>

  <Step title="Issue a replacement">
    Create a new key from the [dashboard or the API](/authentication), store it in your secret manager, and deploy it. The plaintext key is shown only once.
  </Step>

  <Step title="Check what it did">
    Review the key's usage with [`list-keys`](/api-reference/endpoint/list-keys) - `credits_used` and `last_used_at` show whether it was abused before you revoked it.
  </Step>
</Steps>

<Warning>
  Revoking a key cannot be undone, and any service still using it starts failing with `401`. Deploy the replacement first where you can.
</Warning>

## Limit the blast radius next time

<CardGroup cols={2}>
  <Card title="Cap each key's spend" icon="gauge" href="/authentication#set-a-credit-limit">
    Set a per-key credit limit so a leaked key stops at a ceiling instead of draining your balance.
  </Card>

  <Card title="One key per service" icon="key" href="/authentication">
    Name keys by where they run (`production-backend`) so you can revoke one without disrupting the rest.
  </Card>

  <Card title="Keep keys out of code" icon="lock">
    Store keys in environment variables or a secret manager, never in source control or client-side code.
  </Card>

  <Card title="Watch for abnormal spend" icon="triangle-exclamation" href="/webhooks">
    Subscribe to the `credits.low` and `credits.exhausted` webhooks to catch a runaway key early.
  </Card>
</CardGroup>

## Next steps

<CardGroup cols={2}>
  <Card title="API keys & authentication" icon="key" href="/authentication">
    Create, rotate, and cap keys.
  </Card>

  <Card title="Credits" icon="coins" href="/credits">
    How spend and free repeats work.
  </Card>
</CardGroup>
