Skip to content

API keys

Report a leaked key

Anyone who finds a key (pk_live_…) in a public place can report it here, without signing in. If the key is active it is blocked at once, the workspace’s owners and admins get an email and a security alert, and every request with it then gets 401 with code: "api_key_blocked". The answer is always the same, so it does not tell whether the key exists.

POST/api/security/report-leaked-key
  • Public, no authentication

Body

application/json
  • keystringrequired

    The full key you found.

    Example
    pk_live_…
  • urlstringoptional

    Where you found it, for example a link to a public repository file or a post.

    Example
    https://github.com/example/app/blob/main/.env

Response

202 Acceptedapplication/json

  • okboolean

    Always true.

  • messagestring

    A thank-you note for the reporter.

Status codes

  • 202Accepted. Always this body, whether or not the key exists or was already blocked.
  • 400Bad request. key is missing or empty.
  • 429Too many requests. Too many reports from your IP address. Try again later.