---
title: What to do if a key leaks
description: "Rotate immediately, then know the blast radius: a leaked key can access supported integrations for its site."
canonical_url: https://rebilder.com/help/api-keys/key-leaked
---

# [What to do if a key leaks](https://rebilder.com/help/api-keys/key-leaked)

- **Summary:** Rotate immediately, then know the blast radius: a leaked key can access supported integrations for its site.

## First: rotate

Open Console → Settings, find the affected site under Sites, click “Create a new key” and confirm. The leaked key stops working as soon as the new key exists. Then update your deployment with the new key.

## What a leaked key could have done

Someone holding a site key could submit events and orders or retrieve approved answers through the supported APIs. They cannot use that key to sign in to the Console or access another site. Rotate a leaked key promptly and review the affected integrations.

## Then: check and tidy up

1. Open Console → AI visits, choose All visitors and a range that covers the leak, and look for rows that look wrong, such as addresses that are not on your site or sudden bursts.
2. Remove the old key from wherever it leaked (repository history, shared docs, chat logs).
3. If you see suspicious activity or want the polluted rows cleaned up, contact support with the site domain and the time window.