Does an OpenAI API key expire? Expiry dates and key rotation
OpenAI project keys can now carry an expiration date and orgs can cap lifetime. Sume documents no expiry field: rotate by minting a replacement key.

An OpenAI project API key can now expire: you can set an expiration date when you create it, and administrators can enforce a maximum key lifetime at the organization or project level. A key created without a date is not described as expiring in the changelog, so check your org settings. Sume's authentication docs describe no expiry field, so plan rotation yourself.
OpenAI's statement is from its changelog (Sep 10 entry); Sume's is from Authentication, read 2026-10-01.
What exactly changed at OpenAI?
The entry says you can set expiration dates when creating project API keys, and administrators can require newly created keys to expire within a configured limit in Platform settings, at organization or project level. It points to the production best-practices guide for expiration and rotation.
What does Sume document about key lifetime?
The docs describe keys by metadata: id, name, prefix, scopes and last-used time, and never the full secret. They do not describe an expiration date. What they do state is that scopes are fixed when a key is created and cannot be added later, and that there is no API to patch scopes onto an existing key.
| Topic | OpenAI | Sume |
|---|---|---|
| Expiration date | Settable at key creation | Not documented |
| Org-wide lifetime cap | Administrators can enforce | Not documented |
| Change a key's permissions | Not covered in the entry | Not possible: scopes fixed at creation |
| Last-used signal | Not covered in the entry | Last-used time in key metadata |
How do I rotate a Sume key?
Create a new key with the scopes you need, deploy it, confirm the old key's last-used time stops moving, then remove the old one. The docs use exactly this advice for older keys missing a newer scope: create a new key and rotate to it.
During the overlap, send exactly one credential per request. A request carrying both Authorization: Bearer and x-api-key is rejected with 401 unauthorized, so a gateway that adds its own header on top of your client's can break a rotation.
What should a rotation checklist include?
Calendar the date for each vendor that enforces expiry, since Sume will not do it for you. Re-list scopes before minting, because a missing scope surfaces as 403 insufficient_scope; see Format run 403. Keep job ids rather than keys in your logs, and do not paste keys into chat or tickets.
Sources
Related posts
More in Developers
- OpenAI async tool calling for long-running render jobs
OpenAI's async tool calling lets the model keep working while your tool runs. For a slow Sume render, return the job id fast, then wait in slices.
- OpenAI image-encoding fix: rerun workflows with the right key
OpenAI fixed an image-encoding bug and advised retrying affected workflows. On Sume, a replayed idempotency key returns the original; use a new key to rerun.
- mTLS instead of an API key? How Sume authenticates calls
OpenAI's docs list mutual TLS and workload identity federation. Sume authenticates API calls with one API key header and signs webhooks with HMAC.
- Punch-in zoom on video by API: crop or zoompan, no keyframes
Sume has no auto zoom switch. Use a crop op for a fixed punch-in or the allowlisted zoompan filter in a video-filter graph; there are no keyframes.
Written by Sume