API key security for AI providers: a short guide
An AI provider API key is two things at once: access to your account's models and data, and a way to spend your money. Anyone who has the key can use it. A few simple habits keep keys from becoming a problem.
Create keys with a purpose
- Use one key per app or purpose, never one key shared by everything.
- Name each key so anyone can tell what it is for.
- Scope keys to a project or workspace where the provider allows it. Avoid keys that reach your whole organisation.
Store them safely
- Keep keys in a secrets manager or your hosting platform's environment settings.
- Never paste keys into code repositories, shared documents or chat.
- If a key is ever exposed, rotate it straight away.
Limit the damage
Set spend limits or alerts in each provider's console where they are available. If a key is misused, an alert turns a surprise bill into a quick fix.
Retire what you do not use
Unused keys are pure risk. Review your keys regularly and retire any that have not been used for 90 days or more. Rotate keys when someone who knew them leaves.
A quarterly key check
- List every active key and what it is for.
- Check its scope and when it was last used.
- Retire or rotate anything stale, too broad or unexplained.
Common questions
How often should we rotate AI API keys?
There is no single right interval. Rotate when a key may have been exposed, when someone who knew it leaves, and on a regular schedule your team can keep to.
Is one shared key for the whole company a problem?
Yes. If it leaks, everything stops at once when you revoke it, and you cannot tell which app caused unusual spend. Use one key per app or purpose.