AI · Secret guide

Leaked Anthropic (Claude) API Key: what to do in the first hour

High severityChecked liveLast verified · 5 min read

An Anthropic API key lets whoever holds it call the Claude models as your organization. Every request is billed to your account, counts against your rate limits and runs under whatever workspace the key belongs to. There is no per-user sign-in behind it and no second factor, so the key alone is the whole credential. Replace it, then look at what it was used for.

Check your GitHub account for leaked secrets — free

Provider
Anthropic
Severity
High
Impact
SaaS account access and billing
Checked live by LeakWatch
Yes
Revoke at
Anthropic

What an Anthropic API key looks like

Anthropic API keys start with a fixed prefix, a version segment, and a long random body:

sk-ant-api…XXXX   Anthropic API key (masked)

The sk-ant- prefix is specific to Anthropic, so a hit is rarely a false alarm. Other Anthropic-issued values look similar but are not the same thing:

  • Admin keys (sk-ant-admin…) are used for organization management through the Admin API, not for sending prompts. They are a different credential with their own rotation steps.
  • OAuth tokens (sk-ant-oat… access tokens and sk-ant-ort… refresh tokens) are issued to signed-in tools such as coding assistants. They are tied to a person’s login, not to an API workspace, and you end them by signing out or revoking the app’s access.

If your leaked key starts with sk-or- or a plain sk-, it belongs to another provider. See the OpenRouter API key or OpenAI API key pages.

How Anthropic API keys get leaked

  • .env files committed by accident. ANTHROPIC_API_KEY= is the variable name every SDK and tutorial uses, so it sits in a lot of .env files that were never added to .gitignore.
  • Notebooks and demos. A key pasted into a Jupyter or Colab cell to try a prompt, then published with its output.
  • Front-end code. A chat widget that calls the API straight from the browser ships the key to every visitor. Calls must go through your own backend.
  • Agent and tool configuration. MCP server configs, IDE settings and agent frameworks store keys in JSON or YAML files that end up in shared dotfiles repositories.
  • CI logs and screenshots. Verbose logging of request headers (x-api-key), or a terminal screenshot in an issue or a chat thread.

What to do in the first hour

  1. Create a replacement key first. In the Anthropic Console, open Settings and go to the API keys page. Create a new key, give it a name that says where it is used, and attach it to the right workspace.
  2. Deploy the new key to your secret manager or environment variables, then confirm production still works. Keep each key limited to one application so that the next revocation hurts less.
  3. Delete the exposed key from the same API keys page. Deleting is what ends the exposure; calls with the old value fail from then on. Do not leave it around “just in case”.
  4. Audit usage. Open the Console’s usage and cost views and look at the period since the exposure, by workspace and by key if the view allows it. Look for spikes, models you never call, and traffic at odd hours. Figures can lag, so check again a few hours later.
  5. Review the workspace and its limits. Check which workspace the key belonged to, set a spend limit that fits your real usage, and make sure billing alerts reach a mailbox someone reads.
  6. Check people and other keys. Review organization members and the list of remaining keys. Delete any key nobody can name an owner for.
  7. Then clean the repository: remove the value and rewrite history if you want to. See I accidentally pushed an API key to GitHub.

Not sure what else leaked? Run a free scan.

Not sure what else leaked? Run a free scan.

Revoke it at Anthropic

Open platform.claude.com/settings/keys, find the key (the list shows its name and the first and last characters, which is enough to match it), and delete it. Make sure you are in the right organization first: keys belong to one organization, and a key you cannot find is probably in another. The older console.anthropic.com address redirects to the same place. If the leaked value was an OAuth token rather than an API key, it will not appear here; revoke it from the account or the app that issued it.

How LeakWatch detects it

The rule is called “Anthropic / Claude API Key”. It looks for the literal sk-ant- prefix, an optional version segment such as api03-, then a long body of letters, digits, hyphens and underscores. Because the version segment is optional, the same pattern also catches the OAuth token variants, and when both rules match, the more serious OAuth finding is the one reported. This type is checked live: LeakWatch can check whether a detected key is still active with a read-only request that lists the models available to the key. It never sends a prompt, never reads your data and never spends credits.

LeakWatch can check whether a detected key is still active with a read-only request to Anthropic. It never reads your data or spends your credits.

FAQ

Can someone read my past conversations with the API key?

The Messages API does not offer a history of past requests, so a key by itself cannot replay your earlier calls. What an attacker can do is send new requests at your expense and, if you use features that store files or batches in your workspace, reach those through the same key. Check what your application stores.

The key was only exposed for a few minutes. Do I still need to revoke it?

Yes. Automated scrapers watch public commits continuously, and a revoked key costs you five minutes of work while an abused one costs you a bill. Revoke first, then look at usage to see whether it mattered.

Is a spend limit enough to protect me?

It caps the damage but does not stop it, and a stolen key can still burn through your rate limits and break your own application. Treat limits as a second line of defense and the key rotation as the fix.

Get alerted next time a secret leaks — create a free account

LeakWatch is not affiliated with Anthropic.