Automated OpenAI API Key Inventory Audit
Every Monday, WebRun signs in to the OpenAI Platform, opens the API keys page for each project, records every key by name, creation date and last used date, writes the inventory into Airtable with an owner column, and texts you through Twilio when a key is older than your rotation window or has gone unused for weeks.
How do I keep track of which API keys are still in use?
WebRun audits your OpenAI Platform API keys every Monday. It lists every key by name, creation date and last used date, records the inventory in Airtable with an owner column, and texts you through Twilio when a key is past your rotation window or has sat unused, without ever reading a secret value.
- Every key has a recorded owner and a known age
- Unused keys surface for retirement instead of lingering for years
- Rotation candidates reach you by text while the window still matters
Built for engineering leads · platform teams · security engineers · startup CTOs
What does WebRun do on every run?
The exact actions WebRun takes, in order - in plain language, so you can adjust anything.
-
WebRun signs in and gets to work
Opens
platform.openai.comin a real browser with your saved login - no setup, no API keys. -
1
OpenAI Platform - list keys with age and last use
WebRun opens the OpenAI Platform to list keys with age and last use. - Sign in to the OpenAI Platform and open the API keys page for each project
- Record each key by its name, creation date and last used date
- Never copy, display or store the secret value of any key
- Work out each key's age in days and how long it has been since it was last used
Done when Every key is listed by name with its age and last used date, and no secret value has been captured.
-
2
Airtable - record the key inventory
WebRun opens Airtable to record the key inventory. - Open your engineering inventory base in Airtable
- Add or update a row per key with the project, key name, created date, last used date and owner
- Flag rows with no owner recorded so someone can claim or retire them
- Mark a row Removed when the key no longer appears on the platform
Done when The Airtable inventory matches the live key list, with owners flagged where missing.
-
3
Twilio - text you about stale keys
WebRun opens Twilio to text you about stale keys. - Open Twilio and send an SMS only when a key is past your rotation window or unused beyond your idle limit
- Name the project, the key name and the reason it was flagged
- Send only to your own saved engineering numbers. Never text anyone outside that list
- Never revoke, rotate or create a key. WebRun lists candidates and a person acts in the platform
Done when You have been texted about every flagged key, or nothing was sent because the inventory is clean.
How is each run configured?
Secure by default
Connect once, stays signed in
WebRun signs in once and keeps each session in a persistent environment, so every run picks up right where it left off.
Every action is checked against this policy before it runs.
Questions, answered
Does it store my secret keys anywhere?
No. WebRun records only key names, creation dates and last used dates. Secret values are never copied, never displayed and never written to Airtable or any message.
Will it revoke a key on its own?
No. Revoking a key can break production, so WebRun only lists rotation candidates and texts you. Deleting or rotating a key is always done by a person inside the platform.
How does it decide a key is stale?
By your own limits. You set a rotation window in days and an idle limit for unused keys, and only keys past one of those thresholds are flagged.
Put this on autopilot.
Turn it on in minutes - or have our team set it up for you.