AI Governance Institute
← Security
SEC · SecuritySEC-004Low effortAgent-relevant

AI API Credential Management

Added May 2026

Securely manage, regularly replace, and audit API keys and credentials used to access AI services and model providers.

Objective

Prevent unauthorized access to AI capabilities and associated cost liability through disciplined credential hygiene.

Maturity Levels

1

Initial

API keys are shared informally and stored in code repositories or plain text files.

2

Developing

Keys are managed individually but without a centralized store, rotation schedule, or usage auditing.

3

Defined

All AI API credentials are stored in a secrets manager, with documented rotation schedules and access controls.

4

Managed

Credential usage is monitored; anomalous spend or usage patterns trigger alerts.

5

Optimizing

Credentials are limited to specific services and rotated automatically; the time taken to detect and respond to a compromised key is measured.

Evidence Requirements

What an auditor or assessor would expect to see for this control.

  • —Credential inventory listing all AI API keys, storage location, scope, and rotation schedule
  • —Secrets manager access control configuration confirming developers' direct access to production (live) systems is restricted
  • —Rotation completion records showing each credential was rotated on schedule
  • —Spending alert configuration and records of any alerts triggered and investigated
  • —Source code repository scan results confirming no AI API keys are saved in version control

Implementation Notes

Key steps

  • Never write AI API (application programming interface) keys, the passwords software uses to reach an AI service, into application code or save them in source control (the team's shared code store). Instead, keep them in environment variables (settings held outside the code) or a dedicated secrets manager (a secure vault for credentials).
  • Limit each credential to the minimum permissions it needs; many AI providers offer read-only or rate-limited (usage-capped) key types.
  • Set spending limits and usage alerts on AI API accounts, compromised keys are often discovered first through unexpected billing spikes.
  • Rotate keys (replace them with new ones) on a defined schedule and immediately upon any suspected compromise or personnel change.

Example Implementation

Startup using OpenAI, Anthropic, and a vector DB provider across three products

AI API Credential Inventory and Rotation Policy

ProviderKey ScopeStorageRotation ScheduleSpend Alert Threshold
OpenAIProduction (GPT-4o)AWS Secrets Manager90 days$500/day
OpenAIDevelopmentAWS Secrets Manager30 days$50/day
AnthropicProductionAWS Secrets Manager90 days$500/day
PineconeRead + write (prod index)AWS Secrets Manager90 daysN/A

Prohibited storage locations: Source code, environment files committed to git, Slack/email, shared spreadsheets

Compromise response: Immediate rotation + incident report within 1 hour of detection; notify Security Lead

Access control: Secrets Manager access restricted to CI/CD service role and designated engineering leads; no developer direct access in production

Control Details

Control ID
SEC-004
Domain
Security
Typical owner
CISO / Platform Engineering
Implementation effort
Low effort
Agent-relevant
Yes

Tags

API keyscredential managementsecretssecurity hygiene

Get control updates weekly

New and updated controls, maturity guidance, and the regulatory changes behind them. Every Thursday.

Powered by Buttondown.