logo

Deleted Google API keys keep working for up to 23 minutes, researchers warn

ID: f6274638-2b1c-5235-8eba-c242654514d8

STIX ID: report--f6274638-2b1c-5235-8eba-c242654514d8

Feed Name: Help Net Security

Threat Score
50/100

Date Published: 2026-05-22

Date Updated: 2026-05-22

Author: Zeljka Zorz

...
...

Aikido Security found that deleted Google API keys can still authenticate for a median of ~16 minutes (up to 23 minutes) due to eventual consistency in Google Cloud, meaning key deletion is not immediately effective; this affects keys for Gemini and other GCP APIs. Researchers note misleading UI messaging and lack of a way to confirm revocation; faster revocation is possible for other key types, but Google currently treats the delay as expected, so users should monitor API usage and assume a ~30-minute window before deletion is fully effective.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.