“You have no way to revoke it faster or confirm when it stops working”: Experts find that Google API keys are still usable, even after deleting them


  • Aikido Researchers Find Google API Keys Remain Usable Up to 23 Minutes After Deletion
  • Success rates varied across trials, with Gemini-enabled projects particularly vulnerable to stolen files and cached conversations.
  • Google dismisses the issue as a delay in propagation, but Aikido advises treating the deletion as a 30-minute window and monitoring for unexpected usage.

If, when you delete a Google API key, you expect it to no longer work – effective immediately – we have a surprise for you.

Researchers at Aikido found that users can successfully authenticate up to 23 minutes after deletion, creating a gigantic security risk and a major opportunity for bad actors.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top