SubsiMail
Why self-host Pricing Docs Support FAQ Log in Get a license
Log in Get a license

← Back to Support

How do I rotate my API key if I think it leaked?

#93 Resolved
Deborah M. 24 days ago

Might have accidentally committed my API key to a public repo. How do I revoke it and generate a new one immediately?

Margaret Turner Staff 24 days ago

Go to Settings > API & Webhooks and click “Revoke” next to the key — this takes effect immediately and any requests using the old key will start failing right away. Then generate a new key and update it in whatever integration was using the old one. If you have a moment, also worth double checking your repo's commit history — removing the key from the latest commit doesn't remove it from git history, so if the repo is public, consider it compromised regardless and treat the rotation as the actual fix, not just cleaning the file.

This ticket has been resolved. Its author or SubsiMail staff can reopen it to reply further.

Other tickets

Resolved Should I use a subdomain for cold email instead of my root domain?
Jason J. 1 reply
Open Webhook payload for 'email opened' events — what fields are included?
Elizabeth H. 1 reply
Resolved API returns 401 even though my key looks correct
Christopher C. 2 replies
Resolved Can I get an invoice with my company's VAT number on it?
Elizabeth H. 1 reply
Resolved Password reset email never arrives
Elizabeth H. 1 reply

SubsiMail

The self-hosted alternative to Mailshake.

Documentation Setup guides Support Pricing Terms of Service Privacy Policy Sitemap

© 2026 SubsiMail.

We use Google Analytics to understand traffic to this site. It only runs if you accept -- see our Privacy Policy.