One key per system, scoped, with a spend cap
Open each provider's key list. Any key used from two places is a shared key. Any key with no "restricted" or "project" scope is a master key.
Get every Fix AI Slop Code episode
The code it wrote, the code it should have written and a check, for every episode
What is going on
A shared key turns one leak into several rotations and one outage into several. A master key turns a leaked key into a full account. A key with no spend cap turns a leaked key into a bill. Stripe's own guidance: use restricted keys "especially when giving a key to an AI agent."
Where it bit
The Gemini key in 01 was reused by a second internal tool. One leak, two systems to rotate, and the scrub in one system did nothing for the other. In the research: LLMjacking worst cases run over $100,000 a day; OpenAI removed hard spend caps in October 2025 and only restored them in July 2026.
The practice
Stripe restricted keys with an IP policy. One OpenAI project per app with a hard limit. GitHub fine-grained tokens with an expiry. Anthropic spend limits under Billing. Vercel Spend Management set to pause, and set below your real maximum because it checks every few minutes, not continuously.
Get this check as a script you can run tonight

The coding agent never holds production credentials
An agent with a production database URL will sooner or later run a migration or a cleanup against it, so production secrets never enter its env
Keys go in headers, never in URLs
A URL is written to server logs, CDN logs, browser history and error trackers, so an API key in a query string is a key in five places
Backups the app cannot reach, and one restore you have actually done
A backup on the same account the app or an agent can delete from is not a backup, and a restore you have never run is a number you do not have
If this check came back with more than you expected, that is worth a conversation