All templates

Automated OpenAI API Key Inventory Audit

Every Monday, WebRun signs in to the OpenAI Platform, opens the API keys page for each project, records every key by name, creation date and last used date, writes the inventory into Airtable with an owner column, and texts you through Twilio when a key is older than your rotation window or has gone unused for weeks.

Runs on WebRun · Strict Lockdown policy
Every Monday at 9:00 AM WebRunorchestrates each step
1 OpenAI Platform list keys with age and last use
2 Airtable record the key inventory
3 Twilio text you about stale keys
In short

How do I keep track of which API keys are still in use?

WebRun audits your OpenAI Platform API keys every Monday. It lists every key by name, creation date and last used date, records the inventory in Airtable with an owner column, and texts you through Twilio when a key is past your rotation window or has sat unused, without ever reading a secret value.

  • Every key has a recorded owner and a known age
  • Unused keys surface for retirement instead of lingering for years
  • Rotation candidates reach you by text while the window still matters

Built for engineering leads · platform teams · security engineers · startup CTOs

Step by step

What does WebRun do on every run?

The exact actions WebRun takes, in order - in plain language, so you can adjust anything.

  1. WebRun signs in and gets to work

    Opens platform.openai.com in a real browser with your saved login - no setup, no API keys.

  2. 1
    OpenAI Platform - list keys with age and last use
    platform.openai.com
    WebRun in OpenAI Platform: list keys with age and last use
    WebRun opens the OpenAI Platform to list keys with age and last use.
    • Sign in to the OpenAI Platform and open the API keys page for each project
    • Record each key by its name, creation date and last used date
    • Never copy, display or store the secret value of any key
    • Work out each key's age in days and how long it has been since it was last used

    Done when Every key is listed by name with its age and last used date, and no secret value has been captured.

  3. 2
    Airtable - record the key inventory
    airtable.com
    WebRun in Airtable: record the key inventory
    WebRun opens Airtable to record the key inventory.
    • Open your engineering inventory base in Airtable
    • Add or update a row per key with the project, key name, created date, last used date and owner
    • Flag rows with no owner recorded so someone can claim or retire them
    • Mark a row Removed when the key no longer appears on the platform

    Done when The Airtable inventory matches the live key list, with owners flagged where missing.

  4. 3
    Twilio - text you about stale keys
    twilio.com
    WebRun in Twilio: text you about stale keys
    WebRun opens Twilio to text you about stale keys.
    • Open Twilio and send an SMS only when a key is past your rotation window or unused beyond your idle limit
    • Name the project, the key name and the reason it was flagged
    • Send only to your own saved engineering numbers. Never text anyone outside that list
    • Never revoke, rotate or create a key. WebRun lists candidates and a person acts in the platform

    Done when You have been texted about every flagged key, or nothing was sent because the inventory is clean.

Run settings

How is each run configured?

Starting pageWhere Chrome opens at the start of each run
platform.openai.com
ScheduleRuns automatically on this cadence
Every Monday at 9:00 AM
DeliveryHow each run's result reaches you
Stale key alert · Twilio SMS
OutputWhat each run produces - A weekly inventory of API keys by project with names, creation dates, last used dates and owners, plus a flag list of rotation candidates.
Text
Setup & safety

Secure by default

Connect once, stays signed in

WebRun signs in once and keeps each session in a persistent environment, so every run picks up right where it left off.

Your credentials stay in your own private environment - WebRun never stores your passwords.
Strict Lockdown

Every action is checked against this policy before it runs.

Domains ALLOWLIST
Typed input ALLOW
Shell command BLOCK
File uploads BLOCK
Runs in a contained environment More on policies
Good to know

Questions, answered

Does it store my secret keys anywhere?

No. WebRun records only key names, creation dates and last used dates. Secret values are never copied, never displayed and never written to Airtable or any message.

Will it revoke a key on its own?

No. Revoking a key can break production, so WebRun only lists rotation candidates and texts you. Deleting or rotating a key is always done by a person inside the platform.

How does it decide a key is stale?

By your own limits. You set a rotation window in days and an idle limit for unused keys, and only keys past one of those thresholds are flagged.

Put this on autopilot.

Turn it on in minutes - or have our team set it up for you.