OpenRouter Security Center key sprawl: a Sume key checklist
OpenRouter's Security Center flags idle keys and missing limits. For Sume, rotate by replace, verify, revoke, and use per-call max_spend_usd and key budgets.

For Sume keys, the hygiene pattern is: one key per integration, rotate by creating a replacement, verifying it with GET /v1/me, then revoking the old one, and cap paid MCP calls with max_spend_usd. Sume documents per-key request budgets by plan; this post does not claim other per-key controls.
OpenRouter's announcement (2026-09-28) describes a Security Center that lists every key and flags risk. Its reasoning is stated plainly: the fewer old keys you have, the fewer can leak. Sume facts are from Authentication and MCP tools and gates, read 2026-10-01.
What does OpenRouter's Security Center check?
From the announcement: the Overview counts keys with no spend limit, keys that never expire, and keys unused or idle for 90+ days, and lists recommendations such as removing unused keys and setting a spend limit, because a limit caps what a leaked key can spend. OpenRouter says it audited its own org and found over 1,000 active keys for 85 employees. Those are OpenRouter features and numbers; none of it describes Sume.
What does Sume document for key hygiene?
| Practice | What the docs say |
|---|---|
| Rotation | Create a replacement key, deploy it, verify GET /v1/me, then revoke the old key from the dashboard |
| Exposure | Rotate keys from the dashboard if a key is exposed or appears in logs or chat history |
| Placement | Keep keys on trusted servers or CI secret stores, never in frontend JavaScript, mobile apps, support tickets or screenshots |
| Request budget | Per key, per minute, across all of /v1, set by the workspace plan; reads and writes have separate budgets |
| Per-call spend cap | Optional max_spend_usd on MCP paid calls, enforced only when provided |
What are the per-minute budgets?
Writes and reads are counted separately. The plan number is the write budget, and reads get forty times that.
| Plan | Writes per minute | Reads per minute |
|---|---|---|
| Free | 120 | 4800 |
| Pro | 300 | 12000 |
| Startup | 600 | 24000 |
| Scale | 1200 | 48000 |
| Enterprise | Contact sales | Contact sales |
How do I run this as a checklist?
Give each integration its own key so you can revoke one without breaking the others. Name where each key lives. Rotate by replace, verify, revoke. Send exactly one credential per request, since Sume rejects both Authorization: Bearer and x-api-key together. For agents, set max_spend_usd on paid calls. If a key leaks, follow what to do with an exposed API key.
Sources
Related posts
More in Developers
- OpenRouter eu. and us. base URLs vs Sume's single API host
OpenRouter added us. and eu. in-region base URLs on 2026-09-09. Sume documents one host, api.sume.com, and no region-pinned base URL or ZDR toggle.
- OpenRouter video webhooks vs Sume callback_url, signing, retries
OpenRouter's video guide points to a webhooks cookbook. On Sume, pass an HTTPS callback_url, verify x-sume-webhook-signature, retry with Idempotency-Key.
- OpenRouter weight_exceeds_budget: never retry; Sume queue_full
OpenRouter's weight_exceeds_budget 402 will not clear on retry; in_flight_budget_exhausted will. Sume splits the same way: queue_full retries, 402 does not.
- Pika API 'agent-native' setup vs Sume's OpenRouter-style wire
Pika hands agents copy-paste setup text. Sume documents /v1/videos field-for-field with OpenRouter, bare model ids and a models endpoint to read first.
Written by Sume