OpenAI enabled setting expiration dates for API keys and enforcing their maximum lifetime
OpenAI added the option to set an expiration period for API keys when creating them in OpenAI API. Administrators can also enforce a maximum lifetime at the organization or project level in Platform settings.
OpenAI announced a new feature for OpenAI API: developers can set an expiration date when creating API keys. Previously, keys remained valid indefinitely unless the user manually revoked them.
In addition, administrators can enforce a maximum lifetime for keys in Platform settings, either across the entire organization or for an individual project. Newly created keys must then expire within the configured limit. According to OpenAI, this feature is part of the recommended practices (production best practices) for managing and rotating API keys.
Why it matters
The feature makes it easier to enforce security hygiene around API keys, which are frequently leaked (e.g. through public repositories or logs). Company administrators can thus centrally ensure that no key in the organization remains valid indefinitely, without having to manually review and revoke old keys.
Two audiences, two different impacts
What this means
For individuals
Developers working with OpenAI API can set an expiration date when creating a new key, reducing the risk posed by a forgotten key that remains valid for a long time.
For a business
Company administrators can enforce a maximum lifetime for API keys across the entire organization or for a specific project in Platform settings, making it easier to comply with internal security policies and regularly rotate access credentials.
Risks and complianceCheck the original
Event sources
clearly official source · 1 publisher, 0 independent. We count feeds from the same owner only once.