Skip to main content
The Security settings page shows which API keys lack a spend limit or an expiration, and which haven’t been used recently. To run the same checks on a schedule, or to feed them into your own tooling, call the List API keys endpoint with a Management API key.

Prerequisites

  • A Management API key. For organizations, only organization admins can create one.
  • Python 3 with the requests package, or any HTTP client.

Fields to check

Each key returned by GET /api/v1/keys includes these fields:
  • limit: the spend limit in USD, or null if the key has no limit.
  • expires_at: the ISO 8601 UTC expiration, or null if the key never expires.
  • last_used_at: the ISO 8601 UTC timestamp of the most recent usage recorded for the key, or null if no usage has been recorded since the end of 2025.
  • usage and byok_usage: lifetime spend in USD, on OpenRouter credits and on your own provider keys (BYOK).
  • created_at, creator_user_id, workspace_id, name, and hash: to identify the key and its owner.
OpenRouter has recorded last-use times since the end of 2025. A key whose last_used_at is null but whose usage or byok_usage is greater than 0 was last used before then. Treat it as idle, not as never used. The endpoint lists the keys in one workspace: the workspace_id you pass, or your default workspace if you omit it. To audit every workspace, list them with List workspaces and call the endpoint once per workspace_id. It returns up to 100 keys per page. Pass offset to read the next page, and stop when a page has fewer than 100 keys. Disabled keys are excluded unless you pass include_disabled=true. The endpoint returns standard API keys only. Management API keys and keys created through OAuth aren’t included, so review those on the Security settings page.

Example

The following script reads your Management API key from the OPENROUTER_MANAGEMENT_KEY environment variable, lists the keys in every workspace, and prints the ones that have no spend limit, never expire, or have been idle for 90 days or more:
To audit one workspace, list keys for that workspace_id only. To build a list for owners to review, group the output by creator_user_id.

Act on the results

The API returns raw key data, not the risk or Safe to remove labels shown in the dashboard. Decide what counts as safe to remove for your organization. For example, keys that were never used, or that have been idle for 90 days with little lifetime usage. Confirm with each key’s owner before you change it. Then use Update an API key to set a limit or set disabled to true, or Delete an API key to remove it. Disabling is reversible; deleting is not. An expiration can’t be added to an existing key, so replace keys that never expire with new expiring keys, following the API key rotation guide.

Check your work

  • A key you just used shows a recent last_used_at, and a key you just created shows null with usage and byok_usage of 0.
  • Standard API keys flagged No limit or No expiry in the dashboard also appear in the script’s output.