OpenAI added governance controls for API key creation
OpenAI introduced new tools for governing API key creation at the organization and project levels — administrators can allow only service-account keys, only user-owned keys, or completely disable the creation of new keys.
According to its own changelog dated 15 September 2026, OpenAI added new governance controls for API key creation to OpenAI API, available both across the entire organization and at the individual project level. Administrators can choose one of three modes: allow only the creation of service-account keys, allow only user-owned project keys, or completely disable the creation of new API keys.
Organization-level settings take precedence over individual project settings. According to OpenAI, existing API keys that have already been created are unaffected by this change — the restriction applies only to the creation of new keys. The company lists this feature among its recommended practices for production deployments (production best practices).
Why it matters
Administrators of organizations using OpenAI API thus gain a tool to prevent the uncontrolled creation of personal API keys tied to individual users and enforce the use of service-account keys, which are easier to manage and audit. This reduces the risk of access being leaked when an employee leaves or when visibility into who has access to the API is lost.
Two audiences, two different impacts
What this means
For individuals
Developers working with OpenAI API may find that, once their organization introduces restrictions, they can no longer create their own personal API key and will have to use a service-account key assigned by an administrator.
More practical updates →For a business
Companies using OpenAI API can centrally enforce a key management policy (service-account only, user-owned only, or a complete ban on new keys), thereby reducing the risk of uncontrolled access to the API.
Risks and complianceCheck the original
Event sources
clearly official source · 1 publisher, 0 independent. We count feeds from the same owner only once.