How do I report a leaked or compromised API key?

Last updated: September 17, 2026

Move fast, in this order:

  • Revoke the key immediately in the dashboard (API keys settings). Revocation is instant.

  • Create a replacement key and rotate it into your applications.

  • Check for unexpected usage — the usage endpoint attributes Model API traffic per key, and the billing dashboard shows overall spend.

Tell us at support@baseten.co with the key prefix and timeframe. If unauthorized usage produced charges, include that in the message — we'll investigate.

Prevention: use personal keys only for local development; production systems should use team API keys with the minimum scope (inference-only where possible).