PonoLens guide

What to do after pasting an API key into an AI chat

Treat an exposed API key like a copied house key. Replacing it matters more than deleting the message.

1. Stop using the exposed key

Open the service that issued the key and revoke or disable it. Do this quickly. Do not wait to learn whether someone used it.

2. Create a replacement

Make a new key with only the permissions the application needs. Update the application through its secret manager or approved configuration process. Do not paste the replacement into another chat.

3. Check what happened

Review the PonoLens activity card and the AI provider’s account history. Look for the destination, time, prompt, and any other private information that may have been included. Check the key provider’s logs for unusual use.

4. Tell the right person

If the key belongs to your employer, client, or shared project, contact the person responsible for security or the account. Follow the organization’s incident steps.

Deleting the chat is not enough. Deletion may limit later access, but it does not make the old key safe again. Revoke and replace the key.

Prevent the next mistake

Keep secrets in an approved secret manager, use keys with narrow permissions, and review prompts before sending. PonoLens can warn about supported activity, but it cannot stop every prompt in every AI tool.

Read next

Codex vs. Claude CLI activity: what can local tools actually observe? →