Podcast
Root Causes 639: Fighting Static API Key Spillage Is Like Fighting Gravity
Hosted by
Tim Callan
Chief Compliance Officer
Jason Soroko
Fellow
Original broadcast date
July 10, 2026
Static API keys are a common security practice. In this episode we discuss the risk of these keys being revealed, including directly by the AIs that use them.
Podcast Transcript
So right there, put on your pen tester hat. How many different places has this now been in the cloud? And so, even if you're really trusting of your environment file in Linux, that's great. But, Tim, we've seen so many of these static API keys end up being found in public GitHub repositories. And that's just one of many places. Furthermore, because it's a static API key, that means it doesn't expire. You can set, typically, an expiry date. Some services allow you to do that. But how many people are setting it to, like, daily? Nobody.