API keys
Report a leaked key
Anyone who finds a key (pk_live_…) in a public place can report it here, without signing in. If the key is active it is blocked at once, the workspace’s owners and admins get an email and a security alert, and every request with it then gets 401 with code: "api_key_blocked". The answer is always the same, so it does not tell whether the key exists.
- Public, no authentication
Body
application/jsonkeystringrequiredThe full key you found.
urlstringoptionalWhere you found it, for example a link to a public repository file or a post.
Response
202 Acceptedapplication/json
okbooleanAlways
true.messagestringA thank-you note for the reporter.
Status codes
- 202Accepted. Always this body, whether or not the key exists or was already blocked.
- 400Bad request.
keyis missing or empty. - 429Too many requests. Too many reports from your IP address. Try again later.