Open Model Gatewaydocs

Key safety

Find Team and Project API keys that need attention, without seeing anyone's personal keys.

Admin › Key safety lists the active Team and Project API keys that need attention. It reads live configuration on every visit; it stores nothing and changes no key.

The page

  • High, Medium and Low tiles count Team and Project keys by their worst finding. A fourth tile counts personal keys that need attention, as a number only.
  • One toolbar row: search by workspace or finding, and a Severity filter.
  • One row per key: "API key in workspace", whether it belongs to a member or a service account, up to three findings, last use, expiry and one fix.

Rows never show a key's name or its holder. Personal keys are never listed, only counted.

Findings

FindingSeverityRule
No expiryHighThe key has no expiry date.
No limitsHighNo budget and no rate limit at any layer that applies.
Holder leftHighA member's key whose holder no longer has a membership in that Team or Project.
Expiry too longMediumA person's key that expires later than the installation's maximum key lifetime allows.
No budgetMediumA rate limit applies, but no budget at any layer.
Not rotatedMediumThe secret is 180 days old or more.
UnusedLowNot used for 30 days or more.
Never usedLowNever used, and at least 7 days old.
All modelsLowNo model restriction, and the workspace has 5 or more usable models.

"Any layer" means the installation, the type default or override, the workspace and the key: a budget anywhere, even of $0, counts. Revoked, expired and disabled keys, and keys of disabled workspaces, are skipped.

Fixes

Each finding offers one fix: Set expiry or Rotate (the rotate dialog), Add budget (the key's Limits tab), Restrict models (create a restricted key, then revoke this one), Disable or Revoke.

A fix opens the key's own page only if you administer that workspace. Otherwise it opens the Team's or Project's page in Admin: a platform role doesn't give authority over a workspace's keys.

The same findings appear to workspace members and admins on their API keys page; see API keys. Key safety raises no notifications; use alerts for that.

On this page