# Replit — Keeping Your API Keys Safe

- Company: Replit (replit.com)
- Announced: 2023-06-09T13:00:00+00:00
- Category: safety-policy-update
- Coverage: not counted
- Announcement: yes
- Group: announcements
- Source: https://replit.com/blog/keeping-your-api-keys-safe
- Record: https://forck.live/items/18181-keeping-your-api-keys-safe
- Subject: Replit Agent

Replit describes how it protects users' API keys by scanning published Repls for exposed keys from OpenAI, GitHub, npm, PyPI, Discord, and Sendgrid. When an exposed key is found, Replit unpublishes the Repl and revokes the key using a method supported by the third-party service. The post also explains how users should respond to a notification of a revoked key.

## Evidence

Verbatim from https://replit.com/blog/keeping-your-api-keys-safe:

> Whenever a Repl is published to our Community, we automatically scan it to make sure that an API key has not been inadvertently included in the Repl’s code. In addition to API keys from OpenAI, we also scan for API keys from a number of other popular service platforms, including GitHub, npm, PyPI, Discord, and Sendgrid.

---

Record: https://forck.live/items/18181-keeping-your-api-keys-safe
Catalogue: https://forck.live/llms.txt
Current issue: https://forck.live/feed.md
