Prerequisites
- A Management API key. For organizations, only organization admins can create one.
- Python 3 with the
requestspackage, or any HTTP client.
Fields to check
Each key returned byGET /api/v1/keys includes these fields:
limit: the spend limit in USD, ornullif the key has no limit.expires_at: the ISO 8601 UTC expiration, ornullif the key never expires.last_used_at: the ISO 8601 UTC timestamp of the most recent usage recorded for the key, ornullif no usage has been recorded since the end of 2025.usageandbyok_usage: lifetime spend in USD, on OpenRouter credits and on your own provider keys (BYOK).created_at,creator_user_id,workspace_id,name, andhash: to identify the key and its owner.
last_used_at is null but whose usage or byok_usage is greater than 0 was last used before then. Treat it as idle, not as never used.
The endpoint lists the keys in one workspace: the workspace_id you pass, or your default workspace if you omit it. To audit every workspace, list them with List workspaces and call the endpoint once per workspace_id. It returns up to 100 keys per page. Pass offset to read the next page, and stop when a page has fewer than 100 keys. Disabled keys are excluded unless you pass include_disabled=true.
The endpoint returns standard API keys only. Management API keys and keys created through OAuth aren’t included, so review those on the Security settings page.
Example
The following script reads your Management API key from theOPENROUTER_MANAGEMENT_KEY environment variable, lists the keys in every workspace, and prints the ones that have no spend limit, never expire, or have been idle for 90 days or more:
workspace_id only. To build a list for owners to review, group the output by creator_user_id.
Act on the results
The API returns raw key data, not the risk or Safe to remove labels shown in the dashboard. Decide what counts as safe to remove for your organization. For example, keys that were never used, or that have been idle for 90 days with little lifetimeusage.
Confirm with each key’s owner before you change it. Then use Update an API key to set a limit or set disabled to true, or Delete an API key to remove it. Disabling is reversible; deleting is not. An expiration can’t be added to an existing key, so replace keys that never expire with new expiring keys, following the API key rotation guide.
Check your work
- A key you just used shows a recent
last_used_at, and a key you just created showsnullwithusageandbyok_usageof 0. - Standard API keys flagged No limit or No expiry in the dashboard also appear in the script’s output.