Check the basics that prevent leaked keys, surprise bills and account takeovers.
—
Tick the items that are already true.
Need a second opinion? Read the docs or start on the free plan (2 free models, no card).
The AI API Key Security Checklist walks through the controls that keep API keys out of the wrong hands: scoping keys per service, storing them in a secrets manager, rotating them on a schedule, restricting network access, and monitoring usage for anomalies. It is written for developers, platform engineers, and security teams running AI features in production. Work through it before launch and again after an incident or staff change. Plugsky documents authentication and key handling in its docs.
Store keys in a dedicated secrets manager or your platform's encrypted secret store, never in source control, client-side code, or shared documents. Inject them as environment variables at runtime and restrict which services and people can read them.
Rotate on a fixed schedule such as every 90 days, immediately after any suspected exposure, and whenever someone with access leaves the team. Automate rotation so you can issue a new key before revoking the old one without downtime.
Watch provider usage dashboards and billing alerts for sudden volume or unfamiliar addresses, and enable secret scanning in your repositories. Revoke first and investigate second, because an unused key can always be reissued.
Canonical pricing and plans: plugsky.com/#sec-pricing · Terms · SLA · Docs