- Use separate keys for each application and environment.
- Deploy a new key before revoking the old one during rotation.
- Grant production keys only the models they require.
- Revoke a key immediately when usage looks suspicious.
Platform
API key management
Create, restrict, and rotate keys
Create and revoke keys in Key management. Model allowlists and blocklists can limit which models each key may use.
