All templates

Automated Anthropic API Key Access Review

Every Monday, WebRun signs in to the Anthropic Console, lists the API keys across your workspaces with when each was last used, lists the members who still hold access, opens a Trello card for every key or person that looks stale, and sends the summary to WhatsApp.

Runs on WebRun · Strict Lockdown policy
Every Monday at 9:00 AM WebRunorchestrates each step
1 Anthropic Console list keys and members
2 Trello raise a confirm or revoke card
3 WhatsApp send the access summary
In short

How do I review which API keys and workspace members still need access?

Every Monday WebRun signs in to the Anthropic Console and reviews access: which API keys exist, when each was last used, and which workspace members still hold console access. WebRun opens a Trello card per item to confirm or revoke and sends the summary to WhatsApp, so old keys do not live forever.

  • Keys from finished projects are found instead of living on
  • Every stale key or member gets a card and a named decision maker
  • Nothing is revoked automatically, so no live integration breaks

Built for engineering leads · platform teams · security engineers · AI product teams

Step by step

What does WebRun do on every run?

The exact actions WebRun takes, in order - in plain language, so you can adjust anything.

  1. WebRun signs in and gets to work

    Opens console.anthropic.com in a real browser with your saved login - no setup, no API keys.

  2. 1
    Anthropic Console - list keys and members
    console.anthropic.com
    WebRun in Anthropic Console: list keys and members
    WebRun opens Anthropic Console to list keys and members.
    • Sign in to the Anthropic Console and list the workspaces on the account
    • For each workspace, record the API keys, who created them, and when each was last used
    • List the members who hold access to each workspace and the role they were given
    • Mark keys with no recent usage and members who have not used the console inside your review window
    • Never reveal, copy, or write down a key value, and never revoke a key or remove a member

    Done when Every key and member is listed with its last used date and marked keep or review.

  3. 2
    Trello - raise a confirm or revoke card
    trello.com
    WebRun in Trello: raise a confirm or revoke card
    WebRun opens Trello to raise a confirm or revoke card.
    • Add a card to the access review board for each key or member marked for review
    • Put the workspace, the key name or person, the last used date, and the creator in the description
    • Assign each card to the engineering lead so a human confirms or revokes it deliberately

    Done when Every stale key and member has a Trello card assigned for a decision.

  4. 3
    WhatsApp - send the access summary
    whatsapp.com
    WebRun in WhatsApp: send the access summary
    WebRun opens WhatsApp to send the access summary.
    • Message the internal engineering group with the counts: keys in use, keys unused, and members with access
    • Name the oldest unused key and anyone whose access has gone quiet the longest
    • Include the review window so the numbers are read against a clear rule

    Done when The engineering group has this week's access summary in WhatsApp.

Run settings

How is each run configured?

Starting pageWhere Chrome opens at the start of each run
console.anthropic.com
ScheduleRuns automatically on this cadence
Every Monday at 9:00 AM
DeliveryHow each run's result reaches you
Access review · WhatsApp
OutputWhat each run produces - Each run produces a Trello card per stale key or member with its last used date, plus a WhatsApp summary of keys and access across the workspaces.
Text
Setup & safety

Secure by default

Connect once, stays signed in

WebRun signs in once and keeps each session in a persistent environment, so every run picks up right where it left off.

Your credentials stay in your own private environment - WebRun never stores your passwords.
Strict Lockdown

Every action is checked against this policy before it runs.

Domains ALLOWLIST
Typed input ALLOW
Shell command BLOCK
File uploads BLOCK
Runs in a contained environment More on policies
Good to know

Questions, answered

Will it revoke keys or remove people?

No. WebRun lists what looks stale and raises a card for a human to decide. Revoking a key or removing a member is always done by your engineering lead.

Does it read the API key values?

No. It reads key names, creators, and last used dates only. A key value is never revealed, copied, stored, or sent to any channel.

How long before a key counts as unused?

You set the review window, and 30 days is a common starting point. Anything used inside it is left alone, so active integrations never end up on the list.

Put this on autopilot.

Turn it on in minutes - or have our team set it up for you.