Product

One register. Real signals. You decide what to fix.

SubScope sits between your teams and every vendor API they touch. It catalogs what it finds, tells you what's risky, and gets out of the way — you act at the vendor, we track that it happened. This page walks the same credential through all four exhibits.

Reading time · 6 min
Exhibits · 4
Exhibit A

Findings: a key is only as safe as what you know about it.

SubScope flags unowned keys, staleness and cost spikes on every credential you connect — plus OpenAI admin-key scope on the ones that need it — then tracks the fix as your team works through them. Drag the slider to see one credential's findings resolve.

credential
openai_prod_key_7f3a
created
2025-11-04 · via Slack DM
owner
unassigned
scope
* (wildcard)
at discoveryopen 11 / 11
risk
HIGH
open findings
wildcard scope, no owner, cost spike…
last synced
2 min ago · hourly poll
rules triggered
wildcard-scope, unowned, zombie-key
Exhibit B

Inventory: every credential, named and owned.

Connect your vendors and SubScope builds a live register: who created each key, when it was last seen, and what it's costing you. Ownership is enforced at creation; unowned or stale keys are flagged for review.

Discovery

Catalogs what you paste in

Recognizes credentials you add manually or bulk-import, and matches duplicates across sources.

Ownership

A name on every key

New personal credentials cannot be issued without an owner. Missing owners on existing keys are flagged for review.

Hygiene

Unused means flagged

Policy: anything unused 30+ days is flagged as a zombie key; 90+ and 180+ day rules flag increasingly stale ones. You decide what to do with them.

Exhibit C

Guardrails: know what's wider than it needs to be.

SubScope flags what's risky the moment it sees it — an OpenAI admin key, a cost spike, a finding worth a Slack ping. Fixing it at the vendor is still on you, but you'll know exactly what needs it.

Scope risk

OpenAI admin-key detection

An OpenAI key that starts with sk-admin- gets flagged, with a recommendation to switch to a project-scoped sk-proj- key.

Cost & quota

Spend and usage visibility

Real spend and quota data for AI, cloud and security-intel vendors, so a spike has a name attached to it.

Alerts

Slack notifications

Cost anomalies and new findings post to Slack, with more channels on paid plans.

Exhibit D

What SubScope actually does with what it finds.

Most of what happens next is on your team — SubScope surfaces the finding, logs the fix. The one exception: if an OpenAI key leaks publicly, we can revoke it automatically.

Action log · sampleGoverned
14:31:07 anomaly openai_prod_key_7f3a · cost +412% vs 7d avg (visibility only)
14:31:09 flagged openai_prod_key_7f3a · wildcard scope · master-key rule
16:02:11 disabled shodan_recon_11bd · polling disabled · owner left
16:02:40 assigned openai_prod_key_7f3a · owner set to platform@acme.io
16:03:05 auto-revoke openai_leaked_key_9d10 · revoked automatically · public leak detected
16:03:06 logged 6 changes logged · attributable to platform@acme.io
Procedure

How it connects.

  1. 01

    Connect a vendor

    OAuth or a read-only admin key. SubScope never needs write access to discover.

  2. 02

    Review the register

    Within minutes you see every credential, ranked by staleness and cost.

  3. 03

    Check what's flagged

    Owners assigned, stale keys called out, cost anomalies surfaced.

  4. 04

    Fix it at the vendor

    Narrow, rotate or revoke there — SubScope logs it. The one exception is OpenAI leak auto-revoke.

Recommendation

Shrink your blast radius this week.

Connect one vendor. SubScope will show you what you have been trusting. Free during public beta.

Sign in Talk to us