All templates

Automated Deepgram API Key Access Audits

Every Monday, WebRun opens the Deepgram console, lists every project with its API keys and members, notes each key's permissions and creation date, opens a Trello card for anything that looks stale or over-permissioned, and sends you a WhatsApp summary of what should be revoked this week.

Runs on WebRun · Strict Lockdown policy
Every Monday at 9:00 AM WebRunorchestrates each step
1 Deepgram list keys, members and permissions
2 Trello open a card per key to review
3 WhatsApp summarise what to revoke
In short

How do I audit my Deepgram API keys and project members each week?

WebRun opens the Deepgram console every Monday and lists every project's API keys and members with their permissions and creation dates. It opens a Trello card for each stale or over-permissioned entry and sends a WhatsApp summary, so a forgotten key cannot quietly run up transcription charges.

  • Old keys get revoked instead of sitting live for months
  • Lapsed members lose access the week they lapse
  • A leaked key cannot quietly run up transcription charges

Built for engineering teams · platform owners · security engineers · AI product teams

Step by step

What does WebRun do on every run?

The exact actions WebRun takes, in order - in plain language, so you can adjust anything.

  1. WebRun signs in and gets to work

    Opens console.deepgram.com in a real browser with your saved login - no setup, no API keys.

  2. 1
    Deepgram - list keys, members and permissions
    deepgram.com
    WebRun in Deepgram: list keys, members and permissions
    WebRun opens Deepgram to list keys, members and permissions.
    • Open the Deepgram console and list every project on the account
    • For each project, capture the API keys with their name, permissions, and creation date
    • Capture the project members and the access each one holds
    • Flag keys older than the age limit you set and any member you marked as lapsed
    • Read only. WebRun never deletes a key or removes a member

    Done when Every project's keys and members are listed with dates and permissions.

  3. 2
    Trello - open a card per key to review
    trello.com
    WebRun in Trello: open a card per key to review
    WebRun opens Trello to open a card per key to review.
    • Open a card on your access review board for each flagged key or member
    • Put the project, the permissions held, and the age on the card
    • Label cards by why they were flagged: old key, broad permissions, or lapsed member
    • Close cards from previous weeks whose key or member no longer appears

    Done when The review board has one open card per item still needing a decision.

  4. 3
    WhatsApp - summarise what to revoke
    whatsapp.com
    WebRun in WhatsApp: summarise what to revoke
    WebRun opens WhatsApp to summarise what to revoke.
    • Send yourself a short summary of how many keys and members were flagged
    • List the oldest keys and the broadest permissions first
    • Note anything new since last week's review
    • Leave every revocation to you. WebRun only recommends

    Done when You have this week's access summary in WhatsApp.

Run settings

How is each run configured?

Starting pageWhere Chrome opens at the start of each run
console.deepgram.com
ScheduleRuns automatically on this cadence
Every Monday at 9:00 AM
DeliveryHow each run's result reaches you
Access review · WhatsApp
OutputWhat each run produces - A list of Deepgram API keys and project members with their permissions and age, ranked by how likely they are to need revoking.
Text
Setup & safety

Secure by default

Connect once, stays signed in

WebRun signs in once and keeps each session in a persistent environment, so every run picks up right where it left off.

Your credentials stay in your own private environment - WebRun never stores your passwords.
Strict Lockdown

Every action is checked against this policy before it runs.

Domains ALLOWLIST
Typed input ALLOW
Shell command BLOCK
File uploads BLOCK
Runs in a contained environment More on policies
Good to know

Questions, answered

Will it delete API keys or remove members?

No. WebRun reads the console and opens Trello cards recommending what to review. Every revocation is a manual step you take yourself, so a key in live use is never pulled by an automation.

How does it decide a key is stale?

It compares each key's creation date against the age limit you set and flags anything older, plus any key whose permissions are broader than the rest of the project and any member you marked as lapsed.

Does it ever see the key values?

No. Deepgram shows a key's secret only once at creation, so WebRun works from the key name, permissions, and creation date shown in the console.

Put this on autopilot.

Turn it on in minutes - or have our team set it up for you.