# [What to do if a key leaks](https://rebilder.com/help/api-keys/key-leaked)

- **Summary:** Rotate immediately, then know the blast radius: a leaked key can access supported integrations for its store.

## First: rotate

Go to Console → Settings → Stores & API keys → “New API key” for the affected store. The leaked key is revoked the moment the replacement is issued. Then update your deployment with the new key.

## What a leaked key could have done

Someone holding a store key could submit events and orders or retrieve approved answers through the supported APIs. They cannot use that key to sign in to the Console or access another store. Rotate a leaked key promptly and review the affected integrations.

## Then: check and tidy up

1. Skim Console → Agent visits around the time of the leak for rows that look wrong (URLs not on your store’s paths, implausible bursts).
2. Remove the old key from wherever it leaked (repository history, shared docs, chat logs).
3. If you see suspicious activity or want the polluted rows cleaned up, contact support with the store domain and the time window.