Account Security
Protect sign-in credentials
Use a unique password and never share passwords or verification codes. Enter credentials only on a page you have confirmed belongs to this site.
Restrict API keys
Limit allowed models, source IP addresses, RPM, TPM, and concurrency to what the workload requires. Use separate keys for development, test, and production.
Store secrets safely
Keep API keys and AppClient secrets in a Secret Manager or equivalent and inject them only into trusted server processes. Never place them in source code, sample configuration, logs, screenshots, or tickets.
Rotate and revoke
If exposure is suspected, create a replacement credential, update the service, and revoke the old credential promptly. For routine rotation, verify the new credential before disabling the old one.
If you cannot sign in, use the public support email shown below. Never send a password, verification code, or complete credential.