API Key Management Best Practices | Vault, Rotation & Scoping | WebFootprint
Automation Integrations API Key Management

API Key Management Best Practices: Vault, Rotate, Scope

Your integrations depend on API keys scattered across scripts, Zapier, and developer laptops. Keys in git history, no rotation schedule, and over-scoped credentials that can wipe a database are one paste away from a breach or an overnight cloud bill.

We put vault-backed key management in place with rotation, scoped permissions, environment separation, and an audit of which system uses which key.

Glass APIs panel and cyan vault key badge linked by a ribbon of masked secret tokens, illustrating vault-backed API key management
39 million
secrets leaked across GitHub in 2024 alone
64%
of secrets leaked in 2022 still active and exploitable years later
39%
of breaches involve credential abuse somewhere in the attack chain
600+ days
average lifespan of unrotated secrets in the wild
The Problem

Sound Familiar?

These are the exact issues our clients faced before a proper key management practice:

  • Payment, CRM, and accounting API keys live in Slack threads, shared drives, and .env files on laptops
  • Nobody can say which Zapier, script, or webhook still uses a given key
  • Keys sit unrotated for years while AWS recommends a 90-day cycle
  • Over-scoped keys can wipe a database or launch cloud resources if they leak
  • Manual revocation causes silent outages because dependent systems were never inventoried

A single AWS access key committed to a public repo is typically exploited within minutes. Documented crypto-mining incidents have produced overnight bills around R1.5 million (about US$89,000). GitGuardian found 64% of secrets leaked in 2022 were still valid years later. Hoping nobody finds your keys is not a strategy.

How It Works

What Proper API Security Looks Like

Inventory → vault → scoped rotation → revoke without guessing. No keys left in Slack or git.

1

Map Every Key

Payment, CRM, accounting, cloud, and webhook credentials inventoried with owners and consumers

2

Move Into a Vault

Secrets leave .env files and chat threads; access is logged and least-privilege by default

3

Scope & Separate

Dev, staging, and production keys diverge; each integration only gets the permissions it needs

4

Rotate on Schedule

90-day (or tighter) key rotation with a revoke-and-replace playbook when something leaks

What We Build

Everything You Need for Reliable Key Rotation

Vault-Backed Storage

Keys leave Slack, git history, and laptop .env files. Production secrets live in a vault with access controls and an audit trail of who retrieved what.

Scheduled Key Rotation

Payment gateway, CRM, and accounting keys rotate on a defined cycle. Dependent systems pick up the new value without a Friday-night firefight.

Least-Privilege Scoping

Each integration gets a key limited to the actions it needs. A leaked webhook key cannot empty a ledger or spin up cloud instances.

Environment Separation

Dev, staging, and production keys never share the same secret. Test work cannot touch live payment or customer data.

Usage Inventory & Audit

A living register shows which system uses which key. When you revoke, you know what will break and what stays healthy.

Revoke-and-Replace Playbook

Documented cutover steps so a compromised key is rotated across Zapier, scripts, and webhooks in minutes, not days of guessing.

Platforms We've Brought Under Key Management

StripePayFastNetcashHubSpotSalesforceXeroAWSHashiCorp VaultDopplerGitHub Secrets
Client Story

From Keys in Slack to a Vault on a 90-Day Cycle

How a 35-person SaaS ops team stopped treating API security as tribal knowledge and cut leak blast radius before the next incident.

Before

The Scattered Process

  • Stripe, HubSpot, and Xero keys pasted into Slack when someone needed access
  • Production .env files on three developer laptops, never rotated
  • One over-scoped AWS key used by a Zapier workflow and a nightly script
  • Revoking a key meant hours of guessing which webhook would fail
  • No register of which system owned which secret
18 months+ since any payment or CRM key was rotated
After

The Managed Process

  • All production secrets in a vault with role-based retrieval
  • Scoped keys per integration; AWS key can no longer launch compute
  • Dev and production environments use separate credentials
  • 90-day rotation calendar with staged cutovers
  • Living inventory: revoke in minutes with a known consumer list
90 days maximum age of any live integration key
100% production keys out of Slack and git
12 keys scoped and inventoried in week one
R1.5M class of overnight cloud risk avoided
3 weeks to vault, scope, and first rotation
The Difference

Before vs After Key Management

Before
After
Where keys live
Slack, .env, git history
Vault with access logs
Rotation cadence
Never / ad hoc
90-day scheduled cycle
Key permissions
Admin / full access
Least privilege per system
Environments
Shared production keys
Dev / staging / prod split
Revoke response
Hours of hunting consumers
Minutes from the register
Blast radius of a leak
Full account / cloud bill
Single scoped integration
Getting Started

How It Works

From first conversation to live vault and rotation schedule in 2–4 weeks.

01

Tell Us Your Setup

Which gateways, CRMs, and accounting APIs hold keys, where they live today, and what nearly went wrong.

02

Free Scoping Call

30-minute call to map every machine credential, prioritise high-blast-radius keys, and design vault and rotation practice.

03

Build & Test

We move secrets into a vault, wire scoped keys per environment, and rehearse rotation against staging before production.

04

Go Live & Monitor

Old keys revoked on a schedule. Alerts and an ownership register keep every payment and CRM integration accountable.

Questions

Frequently Asked Questions

How long does an API key management programme take to put in place?

A focused vault and rotation rollout for your core payment, CRM, and accounting integrations usually takes 2–4 weeks from scoping to go-live. Inventorying a handful of keys and moving them into a vault can be live within a week. Broader estates with Zapier, custom scripts, and multi-cloud credentials take closer to 4–6 weeks.

Which systems and vaults can you cover?

We specialise in payment gateways (Stripe, PayFast, Netcash), CRM and accounting APIs (HubSpot, Salesforce, Xero), cloud credentials (AWS and similar), and secret stores such as HashiCorp Vault, Doppler, and GitHub Secrets. If a system issues an API key or token, we can bring it under the same rotation and audit practice.

Will rotating keys break our live integrations?

No. We stage rotation so the new key is loaded into every dependent system before the old one is revoked. Staging rehearsals catch missing consumers. Production cutovers happen in a short, monitored window with a rollback path.

How is this different from identity provider / SSO work?

SSO governs human logins. This programme governs machine credentials: the keys that let Zapier, webhooks, and scripts talk to payment gateways, CRMs, and accounting APIs. Both matter; they solve different risks.

What happens when a key leaks in git or Slack?

Treat exposure as compromise. We revoke the old key, issue a scoped replacement, update every registered consumer, and check provider logs for unauthorised use. The inventory we build is what makes that response minutes instead of days of hunting through chat history.

How much does API key management work cost?

A focused vault migration and rotation schedule for a small set of high-risk keys typically starts from around R25,000. Broader estates with environment separation, automated rotation, and revoke playbooks usually sit between R40,000 and R80,000. Against overnight cloud mining bills that can exceed R1.5 million from a single leaked key, most teams see payback on the first avoided incident.

Ready to lock this down?

Stop Leaving API Keys in Slack and Git

If payment, CRM, and accounting credentials still live in chat threads and laptop .env files, you are one accidental push away from a breach or a seven-figure cloud bill.

Tell us which gateways and APIs you connect, where keys live today, and what nearly went wrong. We'll show you a vault-backed rotation and scoping plan sized to your stack.

Chat with us