OpenRouter Security Center key sprawl: a Sume key checklist

OpenRouter's Security Center flags idle keys and missing limits. For Sume, rotate by replace, verify, revoke, and use per-call max_spend_usd and key budgets.

4 min readSume
All posts

For Sume keys, the hygiene pattern is: one key per integration, rotate by creating a replacement, verifying it with GET /v1/me, then revoking the old one, and cap paid MCP calls with max_spend_usd. Sume documents per-key request budgets by plan; this post does not claim other per-key controls.

OpenRouter's announcement (2026-09-28) describes a Security Center that lists every key and flags risk. Its reasoning is stated plainly: the fewer old keys you have, the fewer can leak. Sume facts are from Authentication and MCP tools and gates, read 2026-10-01.

What does OpenRouter's Security Center check?

From the announcement: the Overview counts keys with no spend limit, keys that never expire, and keys unused or idle for 90+ days, and lists recommendations such as removing unused keys and setting a spend limit, because a limit caps what a leaked key can spend. OpenRouter says it audited its own org and found over 1,000 active keys for 85 employees. Those are OpenRouter features and numbers; none of it describes Sume.

What does Sume document for key hygiene?

Key controls from the Sume docs, read 2026-10-01: https://docs.sume.com/authentication
PracticeWhat the docs say
RotationCreate a replacement key, deploy it, verify GET /v1/me, then revoke the old key from the dashboard
ExposureRotate keys from the dashboard if a key is exposed or appears in logs or chat history
PlacementKeep keys on trusted servers or CI secret stores, never in frontend JavaScript, mobile apps, support tickets or screenshots
Request budgetPer key, per minute, across all of /v1, set by the workspace plan; reads and writes have separate budgets
Per-call spend capOptional max_spend_usd on MCP paid calls, enforced only when provided

What are the per-minute budgets?

Writes and reads are counted separately. The plan number is the write budget, and reads get forty times that.

Per-key request budgets from the Sume authentication page, read 2026-10-01
PlanWrites per minuteReads per minute
Free1204800
Pro30012000
Startup60024000
Scale120048000
EnterpriseContact salesContact sales

How do I run this as a checklist?

Give each integration its own key so you can revoke one without breaking the others. Name where each key lives. Rotate by replace, verify, revoke. Send exactly one credential per request, since Sume rejects both Authorization: Bearer and x-api-key together. For agents, set max_spend_usd on paid calls. If a key leaks, follow what to do with an exposed API key.

Sources

Related posts

More in Developers

All Developers posts

Written by Sume