Revocation triggers

What causes an API key or hostname authorization to be revoked, and how fast. For the narrative version, see API keys and Cybersecurity verification.

TriggerDetection sourceSignalActionTypical latency
Key committed to git (harness, IDE, tooling)Merki API observes the commit; private repos without a Merki integration are not visibleKey pattern present in a repository commitKey revoked automaticallyImmediate after detection
Key found on the public internetMerki monitoring and reportsKey visible on a public code host or siteKey revoked automaticallyWithin 24 hours of detection
Challenge removedAPI re-checkDNS TXT record missing or .merki file stops resolvingHostname access suspended, key revoked30 to 60 seconds
Challenge expiredAPI re-checkChallenge older than the 7 day maximumHostname access suspended, key revoked30 to 60 seconds

Notes

  • Revocation applies to Merki-issued keys and to BYOK routes registered with Merki.
  • A revoked key stays revoked. Appeals: contact billing@merki.dev with the key prefix and the triggering commit or URL; reviewed within 2 business days.
  • Repeated exposure can affect the account itself. See the Acceptable use policy.