sk-ant-api03-…

Exposed Anthropic API Key? Here's how to detect and rotate it

A leaked Claude key (sk-ant-api03-…) bills Claude API usage to you. Scan free with Trust, then delete it in the Claude Console settings in seconds.

An Anthropic API key (starting with sk-ant-api03-) authenticates calls to the Claude API and bills them to your account. Whoever holds it can run Claude on your dime until you delete it. Keys are shown only at creation, so a leak means you replace, not recover.

What an attacker can do with a leaked Anthropic API Key

How Anthropic API Keys get exposed

Scan your repo and live site for exposed Anthropic API Keys — free

Trust checks your code, git history, and shipped JavaScript. No signup, results in about a minute.

Run a free scan →

How to rotate a leaked Anthropic API Key

  1. Sign in to the Claude Console and open Settings → API keys.
  2. Find the leaked key, click the ‘…’ menu next to it, and choose Delete API Key (revocation is instant).
  3. Click Create Key, name it, optionally set an expiration, and copy it once.
  4. Update your server environment/secrets manager with the new key and redeploy.
  5. Verify your app works on the new key.
  6. Review Usage/billing for anomalies; if it was in a public repo, confirm Anthropic's auto-disable email and still delete it manually.

Open the Anthropic API Key dashboard →