
Rotate or disable an xAI API key in the Console
Disable a compromised or unused xAI API key from the Console, then create a replacement so your apps keep calling Grok without sharing the old secret. Official Security walks through the API Keys table: open the vertical ellipsis on a row, choose Disable key to stop traffic temporarily or Delete key to remove it permanently, then Create API Key for the new secret. Keys belong to a specific team, so the team picker must show the team that owns the key before you act. Treat every key like a password: store it in environment variables or a secret manager, never commit it to a public repo, and avoid sharing one key across teammates. Start at console.x.ai.
What you need
A Console login that can see the team's API Keys sidebar entry, the correct team selected in the picker, and a plan to update every app, cron, and CI secret that still holds the old value. Prefer Disable first when you need a short investigation window; Delete when the secret must never work again. For programmatic create, list, update, and delete instead of the Console UI, use Manage API keys with the xAI Management API. Neighboring Console jobs include Enable Zero Data Retention on the xAI Console and View xAI Console audit logs. More API jobs live on the API hub.
Disable or delete, then create the replacement
- Sign in to console.x.ai and confirm the team picker shows the team that owns the key. Keys are tied to teams, so the wrong team hides the row you need.
- Open API Keys in the sidebar and find the key in the table by name or redacted prefix.
- Click the vertical ellipsis (three dots) on that row. Choose Disable key to deactivate it while you investigate, or Delete key to remove it permanently.
- Click Create API Key, copy the new secret once, and store it in your secret manager or environment before you leave the page.
- Update every application, script, and CI variable that still used the old key, then send a low-risk test request so you know the new secret works.
xAI partners with GitHub's Secret Scanning program. When a leak is detected, xAI disables the key and emails you — still rotate in the Console and replace the secret in your systems so the next deploy does not revive a dead value. Monitor the team for unusual traffic after a compromise.
After rotation
Confirm the old key fails with an auth error and the new key succeeds on the same endpoint you use in production. If you keep regional traffic on https://us.api.x.ai/v1, follow Use the US regional API endpoint when you re-point clients. Administrative events such as key creation and deletion still appear in the Console audit log even when Zero Data Retention is on for request content — open View xAI Console audit logs when you need that trail.
Pitfalls
Acting on the wrong team in the picker leaves the compromised key live on the team that actually owns it. Creating the new key without updating every runtime leaves production on the disabled or deleted secret. Choosing Delete when you only needed a temporary stop removes the row before you finish triage. Leaving the new secret in chat history or a public gist recreates the leak you just closed.