My API key has leaked. What should I do?
Revoke or rotate it at once, check its request log and create a new, restricted key.
Act at once: revoke the key in Account > Developers, or rotate it with a grace period of 0 hours. Revoking is immediate and needs no password. Then check the key's request log and your Wallet for activity you do not recognise, and create a new key with an IP allowlist and a daily spend cap. Keep keys only on servers, never in apps or web pages. See API keys and security.
Was this article helpful?
Thanks! Glad it helped.