What to do if a key leaks

Rotate immediately — then know the blast radius: a leaked key can only pollute your visit log, nothing more.

First: rotate

Go to Console → Settings → Stores & API keys → “New API key” for the affected store. The leaked key is revoked the moment the replacement is issued. Then update your deployment with the new key.

What a leaked key could have done

The scope of a store key is writing visit events, nothing else. Someone holding it could submit fake events — inflating or muddying the numbers in your Overview and visit log — but could not read your data, access your Console account, change any setting, or affect your storefront.

Then: check and tidy up

  1. Skim Console → Agent visits around the time of the leak for rows that look wrong (URLs not on your store’s paths, implausible bursts).
  2. Remove the old key from wherever it leaked (repository history, shared docs, chat logs).
  3. If you see suspicious activity or want the polluted rows cleaned up, contact support with the store domain and the time window.