{
"$type": "site.standard.document",
"bskyPostRef": {
"cid": "bafyreigb6zir32x3h5ezsme766oihkishprl4447fu6uy5fapq774vvt3u",
"uri": "at://did:plc:lk3jfj3zq4k4wxnk474axylu/app.bsky.feed.post/3mgvrpt3tgpl2"
},
"path": "/t/short-lived-restrictive-api-keys/1376533#post_2",
"publishedAt": "2026-03-13T00:03:23.000Z",
"site": "https://community.openai.com",
"textContent": "Good question, and you’re thinking about the right risks here.\n\nThere isn’t currently a built-in feature for issuing short-lived, scoped API keys directly from OpenAI with restrictions like model-only access, IP binding, or per-session expiration.\n\nAlso, even if a key is short-lived, exposing it on the client side is still risky. If someone grabs it during that window, they can make requests against your account and you’d be billed for that usage. So keeping API keys private is really important for protecting both your usage and your data.\n\n- Sky",
"title": "Short Lived Restrictive API Keys"
}