OpenAI Project API Key Expiration and Org/Project Max Lifetime

Coffee Summary

  • FACT (changelog Sep 10, 2026): You can set expiration dates when creating project API keys.
  • FACT: Admins can enforce a maximum key lifetime at organization or project level in Platform settings; new keys must expire within that limit.
  • FACT (production best practices): OpenAI strongly recommends setting expiration on create and running a regular rotation process.
  • Project max lifetime cannot exceed the organization max lifetime.
  • This is hygiene, not a new auth protocol — still store secrets outside source control.

What happened

On September 10, 2026, OpenAI’s API changelog shipped project API key expiration: creators can attach an expiry at key creation time, and administrators can require a maximum lifetime for newly created keys at the organization and/or project level in Platform settings.