Automated Deepgram API Key Access Audits
Every Monday, WebRun opens the Deepgram console, lists every project with its API keys and members, notes each key's permissions and creation date, opens a Trello card for anything that looks stale or over-permissioned, and sends you a WhatsApp summary of what should be revoked this week.
How do I audit my Deepgram API keys and project members each week?
WebRun opens the Deepgram console every Monday and lists every project's API keys and members with their permissions and creation dates. It opens a Trello card for each stale or over-permissioned entry and sends a WhatsApp summary, so a forgotten key cannot quietly run up transcription charges.
- Old keys get revoked instead of sitting live for months
- Lapsed members lose access the week they lapse
- A leaked key cannot quietly run up transcription charges
Built for engineering teams · platform owners · security engineers · AI product teams
What does WebRun do on every run?
The exact actions WebRun takes, in order - in plain language, so you can adjust anything.
-
WebRun signs in and gets to work
Opens
console.deepgram.comin a real browser with your saved login - no setup, no API keys. -
1
Deepgram - list keys, members and permissions
WebRun opens Deepgram to list keys, members and permissions. - Open the Deepgram console and list every project on the account
- For each project, capture the API keys with their name, permissions, and creation date
- Capture the project members and the access each one holds
- Flag keys older than the age limit you set and any member you marked as lapsed
- Read only. WebRun never deletes a key or removes a member
Done when Every project's keys and members are listed with dates and permissions.
-
2
Trello - open a card per key to review
WebRun opens Trello to open a card per key to review. - Open a card on your access review board for each flagged key or member
- Put the project, the permissions held, and the age on the card
- Label cards by why they were flagged: old key, broad permissions, or lapsed member
- Close cards from previous weeks whose key or member no longer appears
Done when The review board has one open card per item still needing a decision.
-
3
WhatsApp - summarise what to revoke
WebRun opens WhatsApp to summarise what to revoke. - Send yourself a short summary of how many keys and members were flagged
- List the oldest keys and the broadest permissions first
- Note anything new since last week's review
- Leave every revocation to you. WebRun only recommends
Done when You have this week's access summary in WhatsApp.
How is each run configured?
Secure by default
Connect once, stays signed in
WebRun signs in once and keeps each session in a persistent environment, so every run picks up right where it left off.
Every action is checked against this policy before it runs.
Questions, answered
Will it delete API keys or remove members?
No. WebRun reads the console and opens Trello cards recommending what to review. Every revocation is a manual step you take yourself, so a key in live use is never pulled by an automation.
How does it decide a key is stale?
It compares each key's creation date against the age limit you set and flags anything older, plus any key whose permissions are broader than the rest of the project and any member you marked as lapsed.
Does it ever see the key values?
No. Deepgram shows a key's secret only once at creation, so WebRun works from the key name, permissions, and creation date shown in the console.
Put this on autopilot.
Turn it on in minutes - or have our team set it up for you.