📋 Overview
If your Search Atlas API key has been exposed—for example, committed to a public code repository, shared in a message, or pasted into an unsecured location—you should treat it as compromised. Anyone with your key can make requests on your behalf and consume your account resources. This article explains how to delete the exposed key, generate a new one, and update your integrations safely.
⚠️ When You Should Reset Your API Key
Reset your key right away if any of the following apply:
- The key was accidentally published in a public GitHub or GitLab repository.
- The key was shared in an email, chat, screenshot, or support ticket.
- The key appears in client-side code, logs, or a browser network tab.
- You notice unexpected API activity or usage you cannot explain.
- A team member with access has left your organization.
🤔 Why Resetting Matters
An exposed key cannot be "un-shared." Even if you delete the post or file that contained it, automated bots routinely scan public sources for credentials. Deleting the old key is the only reliable way to stop unauthorized use.
🚫 Step 1: Revoke (Delete) the Exposed Key
Deleting the key immediately blocks any further requests made with it.
- Log in to your Search Atlas account.
- Open Settings and select the API or API Keys section.
- Locate the key that was exposed. If you have several keys, match it by name, creation date, or the last few visible characters.
- Click the Delete (or Revoke) option next to that key.
- Confirm the deletion when prompted.
Once deleted, the key is permanently disabled and can no longer be used to authenticate.
🆕 Step 2: Generate a New API Key
- In the same API Keys section, click Generate New Key (or Create API Key).
- Give the key a clear, descriptive name so you can identify where it is used—for example, "Production Server" or "Reporting Script."
- Copy the new key and store it immediately in a secure location, such as a password manager or your application's secrets store.
❗ Important
For security, the full key is usually shown only once at creation. If you lose it, you will need to delete it and generate another. Never store API keys in plain text files, shared documents, or source code.
🔄 Step 3: Update Your Integrations
After deleting the old key, any application or workflow that relied on it will stop working until you add the new key. There is no grace period—the old key is invalidated immediately. To restore service:
- Replace the old key wherever it was stored—environment variables, configuration files, automation tools, or third-party connections.
- Restart any services or scripts that load the key at startup.
- Run a quick test request to confirm the new key authenticates successfully.
🔒 How to Keep Your API Key Secure
Follow these best practices to prevent future exposures:
- Use environment variables or a secrets manager. Never hard-code keys directly into your application.
- Keep keys out of version control. Add configuration and secrets files to your
.gitignore. - Avoid sharing keys. Do not send keys over email or chat. If a teammate needs access, have them generate their own key where possible.
- Rotate keys periodically. Regularly replacing keys limits the impact of an exposure you may not be aware of.
- Use separate keys per integration. This makes it easy to revoke one key without disrupting everything else.
- Remove keys you no longer use. Fewer active keys means a smaller risk surface.
❓ Frequently Asked Questions
Will deleting my key affect my data or account?
No. Deleting an API key only disables that credential. Your account, settings, and data remain intact.
Can I recover a deleted key?
No. Deleted keys cannot be restored. You will need to generate a new key and update your integrations.
How do I know if my key was misused?
Review your API usage and activity within your account. If you see requests you did not make or unexpected spikes in usage, delete the key right away and generate a new one.
How can I tell which type of API key I have?
Search Atlas is migrating to API Key V2. Legacy (V1) keys are a 32-character hexadecimal string, while V2 keys begin with the sa_ prefix and are noticeably longer (around 100 characters). Use the prefix or the last few visible characters to tell your keys apart when you have more than one.
What happens to my old key when I create a new one?
With API Key V2 you can hold multiple named keys at once and revoke them individually. However, generating your first V2 key automatically revokes your existing legacy V1 key, so any integration still using the V1 key will stop working until you update it. V1 keys are being deprecated and will be phased out after a migration window.
What if I don't see a Delete, Revoke, or Generate option in my account?
Self-service key management and rotation are part of the API Key V2 rollout and may not yet be enabled on every account. If you cannot find the controls to revoke or regenerate your key, contact support and ask us to reset it for you. Please do not include the exposed key in your message—just let us know a reset is needed.
💬 Still Need Help?
If you cannot locate the API Keys section, suspect ongoing unauthorized activity, or need help confirming that a key has been fully revoked, contact our support team. Please do not include the exposed key in your message—just let us know that a reset is needed.