Leaked API key — interactive response checklist
Last verified
Work these in order. The first step is the only one that stops the bleeding — everything after it is containment and cleanup.
Your progress is kept in this browser only. Nothing is sent anywhere.
Why the order matters
The instinct is to fix the _cause_ first — delete the commit, rewrite history, work out how it happened. That feels productive and it is the wrong order.
A key remains valid until it is revoked at the provider. Automated scanners find keys in public repositories within minutes of a push, so by the time you have finished a history rewrite, the credential has usually already been harvested. Revoke first; investigate at your leisure.
The full reasoning for each step is in your OpenAI API key leaked — do these 6 things now, with the Anthropic version here.