Does an OpenAI API key expire? Expiry dates and key rotation

OpenAI project keys can now carry an expiration date and orgs can cap lifetime. Sume documents no expiry field: rotate by minting a replacement key.

4 min readSume
All posts

An OpenAI project API key can now expire: you can set an expiration date when you create it, and administrators can enforce a maximum key lifetime at the organization or project level. A key created without a date is not described as expiring in the changelog, so check your org settings. Sume's authentication docs describe no expiry field, so plan rotation yourself.

OpenAI's statement is from its changelog (Sep 10 entry); Sume's is from Authentication, read 2026-10-01.

What exactly changed at OpenAI?

The entry says you can set expiration dates when creating project API keys, and administrators can require newly created keys to expire within a configured limit in Platform settings, at organization or project level. It points to the production best-practices guide for expiration and rotation.

What does Sume document about key lifetime?

The docs describe keys by metadata: id, name, prefix, scopes and last-used time, and never the full secret. They do not describe an expiration date. What they do state is that scopes are fixed when a key is created and cannot be added later, and that there is no API to patch scopes onto an existing key.

Key lifecycle facts, OpenAI changelog and Sume authentication docs, read 2026-10-01.
TopicOpenAISume
Expiration dateSettable at key creationNot documented
Org-wide lifetime capAdministrators can enforceNot documented
Change a key's permissionsNot covered in the entryNot possible: scopes fixed at creation
Last-used signalNot covered in the entryLast-used time in key metadata

How do I rotate a Sume key?

Create a new key with the scopes you need, deploy it, confirm the old key's last-used time stops moving, then remove the old one. The docs use exactly this advice for older keys missing a newer scope: create a new key and rotate to it.

During the overlap, send exactly one credential per request. A request carrying both Authorization: Bearer and x-api-key is rejected with 401 unauthorized, so a gateway that adds its own header on top of your client's can break a rotation.

What should a rotation checklist include?

Calendar the date for each vendor that enforces expiry, since Sume will not do it for you. Re-list scopes before minting, because a missing scope surfaces as 403 insufficient_scope; see Format run 403. Keep job ids rather than keys in your logs, and do not paste keys into chat or tickets.

Sources

Related posts

More in Developers

All Developers posts

Written by Sume