One register. Real signals. You decide what to fix.
SubScope sits between your teams and every vendor API they touch. It catalogs what it finds, tells you what's risky, and gets out of the way — you act at the vendor, we track that it happened. This page walks the same credential through all four exhibits.
Findings: a key is only as safe as what you know about it.
SubScope flags unowned keys, staleness and cost spikes on every credential you connect — plus OpenAI admin-key scope on the ones that need it — then tracks the fix as your team works through them. Drag the slider to see one credential's findings resolve.
- credential
- openai_prod_key_7f3a
- created
- 2025-11-04 · via Slack DM
- owner
- unassigned
- scope
- * (wildcard)
- risk
- HIGH
- open findings
- wildcard scope, no owner, cost spike…
- last synced
- 2 min ago · hourly poll
- rules triggered
- wildcard-scope, unowned, zombie-key
Inventory: every credential, named and owned.
Connect your vendors and SubScope builds a live register: who created each key, when it was last seen, and what it's costing you. Ownership is enforced at creation; unowned or stale keys are flagged for review.
Catalogs what you paste in
Recognizes credentials you add manually or bulk-import, and matches duplicates across sources.
A name on every key
New personal credentials cannot be issued without an owner. Missing owners on existing keys are flagged for review.
Unused means flagged
Policy: anything unused 30+ days is flagged as a zombie key; 90+ and 180+ day rules flag increasingly stale ones. You decide what to do with them.
Guardrails: know what's wider than it needs to be.
SubScope flags what's risky the moment it sees it — an OpenAI admin key, a cost spike, a finding worth a Slack ping. Fixing it at the vendor is still on you, but you'll know exactly what needs it.
OpenAI admin-key detection
An OpenAI key that starts with sk-admin- gets flagged, with a recommendation to switch to a project-scoped sk-proj- key.
Spend and usage visibility
Real spend and quota data for AI, cloud and security-intel vendors, so a spike has a name attached to it.
Slack notifications
Cost anomalies and new findings post to Slack, with more channels on paid plans.
What SubScope actually does with what it finds.
Most of what happens next is on your team — SubScope surfaces the finding, logs the fix. The one exception: if an OpenAI key leaks publicly, we can revoke it automatically.
How it connects.
- 01
Connect a vendor
OAuth or a read-only admin key. SubScope never needs write access to discover.
- 02
Review the register
Within minutes you see every credential, ranked by staleness and cost.
- 03
Check what's flagged
Owners assigned, stale keys called out, cost anomalies surfaced.
- 04
Fix it at the vendor
Narrow, rotate or revoke there — SubScope logs it. The one exception is OpenAI leak auto-revoke.
Shrink your blast radius this week.
Connect one vendor. SubScope will show you what you have been trusting. Free during public beta.
Sign in Talk to us