Guide · 2026-08-26 · 3 min · by The SubScope team

How much are your API keys costing you?

API credential spend usually skips the AP process entirely — no PO, no contract review, no line item until the invoice posts.

The line item that doesn’t show up in the AP process

Most vendor spend runs through procurement: a PO, a contract, a renewal date finance can see coming a quarter out. API credential spend usually doesn’t. An engineer creates a key to test something, it ends up in production, and the charge posts straight to a corporate card or rides along inside a larger cloud invoice with no PO trail behind it. Finance finds out when the number is already large enough to ask about.

That’s not a process failure so much as a process that was never built for this. Nobody designed a review step for “an engineer pasted an API key into a Lambda on a Thursday,” because it doesn’t look like a purchase decision when it happens.

Why “check the vendor dashboard” doesn’t scale

Every vendor has its own console with its own spend view — that’s a real answer, right up until you need it to work across a dozen vendors nobody’s tracking a list of. It assumes someone knows which dashboards exist, which credential is driving which number, and remembers to look before the invoice rather than after. One team, one vendor, that holds up. Across a growing register of credentials, “just check the dashboard” stops being a control and starts being a hope.

The team behind one $4,210 weekend found out the same way most teams do: from the invoice, three weeks later. Not because anyone was careless — because nobody had a reason to look sooner.

What actual visibility changes

Worth being precise about what this is and isn’t. SubScope doesn’t consolidate billing or replace an AP process. What it does: catalogs every credential with an owner, so a spend anomaly has a name attached to it instead of just a dollar amount, and for the vendors that expose spend data — OpenAI, Anthropic, AWS, GCP, Azure, and several of the security-intel APIs — it shows real cost history and surfaces anomalies as they happen instead of at invoice time. It’s a detection layer, not a controls layer. The fix still happens at the vendor, by whoever owns the credential.

Accuracy matters more here than almost anywhere else on this site — a spend-tracking tool that gets the numbers wrong is worse than none at all. We found and fixed a double-counting bug in spend attribution in early August; it’s the kind of bug that makes a “cost spiked 400%” alert worthless if it’s silently doubling the real number.

The actual ask

Not “give finance a seat in every engineering credential decision.” It’s smaller than that: know how many vendor credentials exist, who owns each one, and see the spend trend before quarter-end turns it into a surprise. That’s a lower bar than most cost-governance conversations start at — and it’s the one that actually prevents the call finance dreads.

Governed

Filed under guide. Back to blog

Recommendation

Shrink your blast radius this week.

Connect one vendor. SubScope will show you what you have been trusting. Free during public beta.

Sign in Talk to us