Revoke a leaked AI API key, issue a new one to every environment, scrub it from your repo, and check your usage for abuse.
I think I pushed my OpenAI key to GitHub. Kill it and fix everything
How it works
- Confirm what leaked: Vovy searches your GitHub repo and commit history for key patterns and checks GitHub's secret scanning alerts to see exactly what is exposed.
- Check for abuse: Vovy opens your provider's usage page and flags unusual spikes, models you never use, or calls at odd hours since the leak.
- Create a new key: Vovy creates a replacement key and updates every place it lives: your host's env vars, Supabase secrets and local .env.
- Revoke the leaked key: Once the new key works, Vovy deletes the old one. This is irreversible and anything still using it breaks, so it asks first.
- Stop it happening again: Vovy removes the key from code, adds .env to .gitignore, and shows a card of what changed and whether history needs cleaning.
What you provide
- Access to your GitHub repo
- Admin access to your AI provider
- Access to your host's settings
What you get
- The leaked key revoked
- A new key in every environment
- An abuse check of recent usage
- .gitignore protection
FAQ
Is deleting the commit enough?
No. The key stays in Git history and may already be copied. Revoking it is the only real fix.
Will OpenAI catch it for me?
OpenAI and GitHub scan public repos and may disable leaked keys automatically, but do not rely on it. Rotate it yourself.
Can I get a refund for abuse?
Contact the provider's support with details. Refunds are not guaranteed, which is why spend caps matter.
Related tasks
All tasks