API key management covers the complete lifecycle of keys and tokens used by applications, automation, integrations, and people. The goal is to minimize exposure, privileges, lifetime, and uncertainty.

Inventory keys with business context

Record each key’s issuing service, technical owner, business owner, purpose, environment, consumers, privileges, creation date, expiration, last rotation, and revocation procedure. A secret without an owner or consumer list cannot be managed reliably.

Apply least privilege at both layers

The secret manager controls who can retrieve a key; the issuing service controls what the key can do. Use both. Limit scopes, environments, IP ranges, resources, and expiration wherever the provider supports them.

Keep keys out of uncontrolled locations

Do not make source code, container images, CI logs, chat, tickets, or local configuration the system of record. Use a governed vault and an approved delivery method, then remove old copies and invalidate exposed values.

  • Scan repositories and build output for accidental exposure
  • Redact values from logs and support records
  • Separate production keys from development credentials
  • Avoid one shared key across unrelated applications

Design rotation and incident response together

Rotation succeeds only when all consumers can adopt the new key and the old one can be revoked safely. Test the procedure before an incident. When exposure is suspected, preserve evidence, revoke or restrict the key, update consumers, investigate use at the issuing service, and document the outcome.