Skip to content
worth noting Security

OpenAI added governance controls for API key creation

clearly official source

OpenAI introduced new tools for governing API key creation at the organization and project levels — administrators can allow only service-account keys, only user-owned keys, or completely disable the creation of new keys.

According to its own changelog dated 15 September 2026, OpenAI added new governance controls for API key creation to OpenAI API, available both across the entire organization and at the individual project level. Administrators can choose one of three modes: allow only the creation of service-account keys, allow only user-owned project keys, or completely disable the creation of new API keys.

Organization-level settings take precedence over individual project settings. According to OpenAI, existing API keys that have already been created are unaffected by this change — the restriction applies only to the creation of new keys. The company lists this feature among its recommended practices for production deployments (production best practices).

What changed

Why it matters

Administrators of organizations using OpenAI API thus gain a tool to prevent the uncontrolled creation of personal API keys tied to individual users and enforce the use of service-account keys, which are easier to manage and audit. This reduces the risk of access being leaked when an employee leaves or when visibility into who has access to the API is lost.

Two audiences, two different impacts

What this means

01

For individuals

Developers working with OpenAI API may find that, once their organization introduces restrictions, they can no longer create their own personal API key and will have to use a service-account key assigned by an administrator.

More practical updates →
02

For a business

Companies using OpenAI API can centrally enforce a key management policy (service-account only, user-owned only, or a complete ban on new keys), thereby reducing the risk of uncontrolled access to the API.

Risks and compliance
What to decide Consider setting up governance controls for API keys at the organization level, especially enforcing the use of service-account keys instead of personal keys.
More business impacts →
API keys security Governance OpenAI Administration

Check the original

Event sources

clearly official source · 1 publisher, 0 independent. We count feeds from the same owner only once.

1
OpenAI API Changelog primary source · first detected Added API key creation governance controls at the organization and project levels. Administrators can allow only service-account keys, allow only user-owned project keys, or…