A Groq API key lets whoever holds it call Groq’s hosted inference API as your organization. Requests made with the key are attributed to your account and count against your rate limits and, on paid plans, your bill. The key carries no user identity and no second factor, so there is nothing to stop a stranger who finds it. Delete it, issue a new one, and then look at how much it was used.
Check your GitHub account for leaked secrets — free
- Provider
- Groq
- Severity
- High
- Impact
- SaaS account access and billing
- Checked live by LeakWatch
- Yes
- Revoke at
- Groq
What a Groq API key looks like
A Groq key starts with the lowercase prefix gsk_ followed by a long run of letters and digits:
gsk_…XXXX Groq API key (masked)
Groq’s API is OpenAI-compatible, so the key is often stored under names borrowed from other tools: GROQ_API_KEY, but also OPENAI_API_KEY when a project points an OpenAI client at Groq’s base URL. If you find a gsk_ value under an OpenAI-looking variable name, it is still a Groq key and this is the guide to use.
Two things are not this secret. A key starting with sk- belongs to another provider; see the OpenAI API key or DeepSeek API key guides. And a Groq key is separate from your Groq console login: leaking a key does not expose your password.
How Groq API keys get leaked
- Hardcoded in a demo. Groq is popular for fast chatbot and voice prototypes, and the quick-start snippet with the key pasted inline often becomes the first commit.
- Committed
.envfiles. A.envor.env.localthat was not in.gitignore, pushed along with the rest of the project. - Notebooks. A key set in a Colab or Jupyter cell, then shared or published with its saved output.
- Front-end code. A browser app calling Groq directly with the key in JavaScript, so every visitor can read it in developer tools.
- Logs and screenshots. A failing request dumped with its headers (
Authorization: Bearer gsk_…) into an issue, a chat thread or a CI log.
What to do in the first hour
- Create a replacement key first. In the Groq console open the API Keys page and create a new key with a name that says what it is for. Put it in your secret manager or environment, not in the code.
- Deploy the new key to every service that used the old one, so you can delete the old one without an outage. If you are not sure where the old key was used, delete it anyway and let the errors tell you.
- Delete the exposed key on the same API Keys page. Deleting is what ends the exposure; a key you keep “just in case” stays usable by anyone who copied it.
- Audit the usage. In the console, look at the usage and logs views for the period since the exposure. Requests you cannot explain, models you never call, or traffic at odd hours are the signs. Figures can lag, so look again later in the day.
- Check limits and billing. If you are on a paid plan, compare spend with your normal level and set a spending limit or alert if the console offers one. On a free plan, a stolen key mostly burns your rate limit, which can break your own app.
- Use one key per service. Separate keys for development, staging and production mean the next leak costs one deletion, not a re-deploy of everything.
Not sure what else leaked? Run a free scan.
- Then clean the repository: remove the value and rewrite history if you want to. See I accidentally pushed an API key to GitHub.
Revoke it at Groq
Open console.groq.com/keys, find the key by its name (the full value is not shown again after creation, so match on the name and creation date), and delete it. Requests using that value fail from then on. If you cannot tell which entry is the leaked one, delete the ones you do not recognize and re-issue the rest.
How LeakWatch detects it
The rule is called Groq API Key. It matches the literal lowercase gsk_ prefix followed by 50 to 70 letters and digits, with word boundaries on both sides, so GSK_ in capitals or a short gsk_ string does not match. This type is checked live: LeakWatch can check whether a detected key is still active with a read-only request that lists the models available to the key. It never reads your data and never spends credits.
LeakWatch can check whether a detected key is still active with a read-only request to Groq. It never reads your data or spends your credits.
FAQ
Can someone read my past prompts or conversations with a Groq key?
The inference API does not offer a history of past requests to read back, so the key mainly lets someone make new calls at your expense. What you should check is what your own app logs and stores, since those logs are a separate exposure.
My key was on GitHub for a few minutes. Do I really need to rotate it?
Yes. Automated scanners watch public pushes continuously, and a short exposure is enough. Rotation takes a couple of minutes and is the only way to know the value is dead.
Why does my app still work after I deleted the key?
It probably has another key, or a cached copy of the old one in a running process or a build. Search your deployments for the old value and restart them; a request that still succeeds after deletion is worth investigating.