My API key rotation went from quarterly to weekly after a breach scare
We got hit with a leaked key in a public GitHub repo back in March, someone scraped it within 4 hours and ran up a $2,300 bill on our cloud account. Now I rotate every Monday morning with a script that also revokes old keys, has anyone else automated their rotation or are you still doing it manually?