Every API key has a blast radius. SubScope catalogs it.
See every credential across your stack — who owns it, what it's costing you, which ones are stale or unowned. Fix them yourself, faster.
- Credential
- openai_prod_key_7f3a
- Created
- 2025-11-04, shared via Slack DM
- Status at discovery
- wildcard scope, no owner, cost spiking
- Status after review
- scope narrowed, owned, cost flat
- Time to remediate
- 4 min 12 s
On 4 November an engineer created openai_prod_key_7f3a to test a summariser. It was pasted into a Slack DM, then into CI, then into a Lambda nobody remembers writing. By March it still held the org-wide admin scope it was born with — readable by every service that imported the same .env file.
Over one weekend a retry loop called it 140,000 times. The invoice arrived three weeks later for $4,210. Nobody could say whose key it was, and nobody could say what else it touched.
SubScope flagged it the moment it was added: no owner attached, and org-wide admin scope on a key that only needed two endpoints. The team narrowed it at OpenAI's console to chat.completions and embeddings and set a $1,500 monthly ceiling. Every step was logged and attributed to platform@acme.io.
▸ MOVE YOUR CURSOR OVER THE REDACTIONS. SUBSCOPE IS THE LENS.
Findings: credential sprawl is an incident waiting to be scheduled.
Keys get created in a hurry, shared in Slack, pasted into CI and forgotten. Nobody meant for them to outlive the person who made them. They do anyway. Three patterns appear in nearly every environment we connect to.
Shared keys nobody owns
One key, zero names attached. When it leaks, the first question is "whose is this?" and nobody has the answer.
Scopes wider than the job
A summariser that only needs chat completions also holds org admin. Wildcard permissions are convenient until they are the headline.
Spend that hides inside credentials
A runaway loop and a stolen key look identical on the invoice. By the time finance notices, you are three weeks late.
Evidence: what SubScope did, in the order it did it.
Three exhibits from the same credential. Inventory first, because you cannot govern what you cannot name. Then scope, because the wrong scope is the actual blast radius. Then what happened next, because a register that never shows its work is a spreadsheet, not a product.
Every credential, named and owned
Connect your vendors and SubScope builds a live register: who created each key, when it was last seen, and what it's costing you.
- Ownership enforced at creation
- Cost & quota visibility across AI, cloud and security-intel vendors
- Orphan credentials flagged when people leave
- OpenAI admin keys flagged on sight
| Key | Vendor | Owner | Scope | Last used | Findings |
|---|---|---|---|---|---|
| openai_prod_key_7f3a | OpenAI | unassigned | * | 2 min | wildcard, unowned |
| github_pat_9c31 | GitHub | priya@ | repo, workflow | 41 s | — |
| aws_ci_deploy_c04e | AWS | ci-bot | ecs:Update* | 6 h | — |
| shodan_recon_11bd | Shodan | unassigned | search | 93 d | unused 93d |
| anthropic_eval_f7c2 | Anthropic | platform@ | messages | 1 h | — |
| vt_scanner_08aa | VirusTotal | secops | files.read | 12 min | — |
Know what's wider than it needs to be
SubScope flagged this OpenAI key's admin-level scope the moment it was added. Narrowing it to a project-scoped key is still on you — at the vendor's own console — but you'll know exactly which ones need it.
- OpenAI admin keys (sk-admin-*) flagged on sight
- Spend and quota visibility per credential
- Every fix your team makes is logged
What SubScope actually does with what it finds.
Most of what happens next is on your team — SubScope surfaces the finding, logs the fix. The one exception: if an OpenAI key leaks publicly, we can revoke it automatically.
- Cost & quota anomalies surfaced, not auto-throttled
- One real automation: OpenAI keys can auto-revoke on public leak
- Every change your team makes is logged and attributable
Coverage: 37 vendors, one register.
Cloud and AI billing are where most tools stop. SubScope also covers the security-intelligence and OSINT APIs that usually sit outside anyone's register — the biggest category here, by far.
Appendix: notes on keeping keys small.
The $4,200 loop: what one unscoped OpenAI key did over a weekend
6 minWhy your Shodan and VirusTotal keys belong in the same register as AWS
4 minZombie keys: flagging unused credentials without breaking Friday deploys
4 minWhat shipped: cost history, three new AI providers, and the governance foundation
3 minShrink your blast radius this week.
GovernedConnect one vendor. SubScope will show you what you have been trusting. Free during public beta.
Sign in Talk to ushello@vyoogam.com