Glossary/Keys & secrets

Revoking an API key

Revoking an API key permanently disables it from the provider's side, usually from the same console page where the key was created. It is the correct response to a suspected leak, since changing where the key is stored does nothing if the value itself is already exposed.

Why it matters

After revoking a key, any tool or project still configured with the old value will start failing, so generate and update the replacement before or immediately after revoking, depending on how much downtime you can tolerate.

Does deleting a key from Claude Keychain revoke it?

No. Deleting it from Claude Keychain removes your local copy. You still need to revoke it with the service that issued it.

How fast does a revoked key stop working?

Usually immediately or within a few minutes, depending on the provider's caching.

Related

Looking for a different way to manage your keys? See the best Claude Code API key manager alternatives, or browse every term in the glossary.