Key Info

OpenRouter has launched a gateway Security Center that lets users audit all their API keys in one place, see which keys are safe to remove, browse keys by risk level, and control an IP allowlist. The feature was prompted by an internal audit that found 1,000+ active API keys across 85 employees, many unused for months.

Highlights

  • Users can view every key across workspaces and see which ones are flagged as risky and why
  • Keys can be disabled, archived, or capped in batches of up to 500 at once
  • Includes an IP allowlist control for further hardening
  • Driven by OpenRouter's own audit that uncovered 1,000+ stale keys for 85 staff