What to do if a key leaks
Rotate immediately — then know the blast radius: a leaked key can only pollute your visit log, nothing more.
First: rotate
Go to Console → Settings → Stores & API keys → “New API key” for the affected store. The leaked key is revoked the moment the replacement is issued. Then update your deployment with the new key.
What a leaked key could have done
The scope of a store key is writing visit events, nothing else. Someone holding it could submit fake events — inflating or muddying the numbers in your Overview and visit log — but could not read your data, access your Console account, change any setting, or affect your storefront.
Then: check and tidy up
- Skim Console → Agent visits around the time of the leak for rows that look wrong (URLs not on your store’s paths, implausible bursts).
- Remove the old key from wherever it leaked (repository history, shared docs, chat logs).
- If you see suspicious activity or want the polluted rows cleaned up, contact support with the store domain and the time window.