Skip to content
important Tools and apps

OpenAI enabled setting expiration dates for API keys and enforcing their maximum lifetime

clearly official source

OpenAI added the option to set an expiration period for API keys when creating them in OpenAI API. Administrators can also enforce a maximum lifetime at the organization or project level in Platform settings.

OpenAI announced a new feature for OpenAI API: developers can set an expiration date when creating API keys. Previously, keys remained valid indefinitely unless the user manually revoked them.

In addition, administrators can enforce a maximum lifetime for keys in Platform settings, either across the entire organization or for an individual project. Newly created keys must then expire within the configured limit. According to OpenAI, this feature is part of the recommended practices (production best practices) for managing and rotating API keys.

What changed

Why it matters

The feature makes it easier to enforce security hygiene around API keys, which are frequently leaked (e.g. through public repositories or logs). Company administrators can thus centrally ensure that no key in the organization remains valid indefinitely, without having to manually review and revoke old keys.

Two audiences, two different impacts

What this means

01

For individuals

Developers working with OpenAI API can set an expiration date when creating a new key, reducing the risk posed by a forgotten key that remains valid for a long time.

What to do Set an expiration period when creating new API keys.
More practical updates →
02

For a business

Company administrators can enforce a maximum lifetime for API keys across the entire organization or for a specific project in Platform settings, making it easier to comply with internal security policies and regularly rotate access credentials.

Risks and compliance
What to decide Consider enforcing a maximum lifetime for API keys at the organization or project level in Platform settings.
More business impacts →
API security Best practices key management OpenAI API

Check the original

Event sources

clearly official source · 1 publisher, 0 independent. We count feeds from the same owner only once.

1
OpenAI API Changelog primary source · first detected You can now set expiration dates when creating project API keys. Administrators can also enforce a maximum key lifetime at the organization or project level in Platform settings…