How do I report a leaked or compromised API key?
Last updated: September 17, 2026
Move fast, in this order:
Revoke the key immediately in the dashboard (API keys settings). Revocation is instant.
Create a replacement key and rotate it into your applications.
Check for unexpected usage — the usage endpoint attributes Model API traffic per key, and the billing dashboard shows overall spend.
Tell us at support@baseten.co with the key prefix and timeframe. If unauthorized usage produced charges, include that in the message — we'll investigate.
Prevention: use personal keys only for local development; production systems should use team API keys with the minimum scope (inference-only where possible).