Notes on keeping keys small.
Incidents we have seen, guides we wish existed, and what shipped. No growth hacks, no listicles.
How much are your API keys costing you?
API credential spend usually skips the AP process entirely — no PO, no contract review, no line item until the invoice posts.
How do you manage your API keys?
SOC 2 prep, a customer's security questionnaire, a due-diligence data room — the question always arrives eventually.
What's actually running your product?
Cost, vendor sprawl, and ownership gaps live one layer below the roadmap — invisible until a bill, an audit, or a renewal forces the question.
sk-admin- vs sk-proj-: one string, one blast radius
SubScope's one real scope-detection rule is a single prefix check on OpenAI keys. Here's exactly what it does, and why it's narrower than it sounds.
What shipped: cost history and three new AI providers
A real changelog — multi-tenant governance foundation at launch, then a July-August push on cost visibility: daily cost history, Claude usage, spend-guardrail visibility, and three new AI providers.
Zombie keys: flagging unused credentials safely
How SubScope's 30/90/180-day rules actually work — and why 'unused' and 'stale' are different risks with different fixes.
Shodan and VirusTotal keys belong beside AWS
Security-intelligence APIs are high-privilege and usually invisible to credential governance. That's backwards.
The $4,200 loop: one unscoped OpenAI key, one weekend
A retry loop, a wildcard scope and a Slack DM. How a test key became a four-figure invoice, and how faster visibility would have changed the outcome.
Shrink your blast radius this week.
Connect one vendor. SubScope will show you what you have been trusting. Free during public beta.
Sign in Talk to us