Live workspace. Durable storage schema active — live connectors, billing, and AI automation are activation-gated.View Activation Status
Signed out
Sign in as the approved QA user before running RLS-bound QA.
Sign in
Back to Workflows

Restrict API key

Apply API and application restrictions to an over-permissive API key.

SLA

24h

Applicable severity

critical
high

Suggested owner

cloud api lead

Workflow steps
Steps run in order. Integration steps are preview-only in this pilot and perform no real action.
  1. 1
    Identify affected key & usage
    Manual task
    Required

    Confirm which key is flagged and where it is used.

  2. 2
    Apply API/referrer/IP restrictions
    Integration (sample)
    Required

    Simulated in this pilot — no real cloud call is made.

  3. 3
    Verify restriction & capture evidence
    Evidence request
    Required

    Attach a scan result showing the key is restricted.

Linked remediation scenarios
Findings that recommend this workflow.
  • critical
    Unrestricted API key detected (frontend-exposed)
    Open finding