Automated Anthropic API Key Access Review
Every Monday, WebRun signs in to the Anthropic Console, lists the API keys across your workspaces with when each was last used, lists the members who still hold access, opens a Trello card for every key or person that looks stale, and sends the summary to WhatsApp.
How do I review which API keys and workspace members still need access?
Every Monday WebRun signs in to the Anthropic Console and reviews access: which API keys exist, when each was last used, and which workspace members still hold console access. WebRun opens a Trello card per item to confirm or revoke and sends the summary to WhatsApp, so old keys do not live forever.
- Keys from finished projects are found instead of living on
- Every stale key or member gets a card and a named decision maker
- Nothing is revoked automatically, so no live integration breaks
Built for engineering leads · platform teams · security engineers · AI product teams
What does WebRun do on every run?
The exact actions WebRun takes, in order - in plain language, so you can adjust anything.
-
WebRun signs in and gets to work
Opens
console.anthropic.comin a real browser with your saved login - no setup, no API keys. -
1
Anthropic Console - list keys and members
WebRun opens Anthropic Console to list keys and members. - Sign in to the Anthropic Console and list the workspaces on the account
- For each workspace, record the API keys, who created them, and when each was last used
- List the members who hold access to each workspace and the role they were given
- Mark keys with no recent usage and members who have not used the console inside your review window
- Never reveal, copy, or write down a key value, and never revoke a key or remove a member
Done when Every key and member is listed with its last used date and marked keep or review.
-
2
Trello - raise a confirm or revoke card
WebRun opens Trello to raise a confirm or revoke card. - Add a card to the access review board for each key or member marked for review
- Put the workspace, the key name or person, the last used date, and the creator in the description
- Assign each card to the engineering lead so a human confirms or revokes it deliberately
Done when Every stale key and member has a Trello card assigned for a decision.
-
3
WhatsApp - send the access summary
WebRun opens WhatsApp to send the access summary. - Message the internal engineering group with the counts: keys in use, keys unused, and members with access
- Name the oldest unused key and anyone whose access has gone quiet the longest
- Include the review window so the numbers are read against a clear rule
Done when The engineering group has this week's access summary in WhatsApp.
How is each run configured?
Secure by default
Connect once, stays signed in
WebRun signs in once and keeps each session in a persistent environment, so every run picks up right where it left off.
Every action is checked against this policy before it runs.
Questions, answered
Will it revoke keys or remove people?
No. WebRun lists what looks stale and raises a card for a human to decide. Revoking a key or removing a member is always done by your engineering lead.
Does it read the API key values?
No. It reads key names, creators, and last used dates only. A key value is never revealed, copied, stored, or sent to any channel.
How long before a key counts as unused?
You set the review window, and 30 days is a common starting point. Anything used inside it is left alone, so active integrations never end up on the list.
Put this on autopilot.
Turn it on in minutes - or have our team set it up for you.