#API KEY LEAKED

1 messages · Page 1 of 1 (latest)

tired pivot
#

Hey all

Just looking for some help. My open ai key for my Emergent Project was leaked. My project is private on Github so I know it can’t be that.

Does anyone know how this may have happened and how I can prevent it from happening?

spring radish
#

@tired pivot Will DM you so that you can share some details with us.
Just to note — all code and runtimes on our side are fully isolated, so it’s very unlikely the leak came from here.

tired pivot
#

No worries, I’m lost then. I genuinely have no idea. As I’m assuming it can only be one of the two places

smoky sundialBOT
#

Hi Beestonn
pls share the job id

spring radish
#

@novel pendant i have pinged it to you

smoky sundialBOT
#

Hi Beestonn

We have checked everything on our end and I can assure you that the API key is not leaked from Emergent’s end. All our systems have appropriate authentication and authorization mechanisms in place. If at all your key is leaked, it might have happened outside of Emergent system.

Regards

Kamran

tired pivot
#

Thanks for checking and clarifying. So, I’m even more confused as Github have assured me it’s not there side either.

Is there anyway to tell if the api key has been used anywhere else?

potent tiger
#

Why bother? Just replace (rotate) the API key. Write yourself a procedure for doing this, stick it in a calendar entry every 6mths, and move on with life?