cybee

Menu

Start freeDeutsch

Who still has your client’s API keys?

A practical handover for agencies using client API keys in scripts, automations and AI tools. Know what to keep, replace and remove.

Agency colleagues reviewing a project handover with a client at a shared table.
Illustrative scene.

How should an agency hand over client API keys securely?

List every client credential your team uses, the jobs that depend on it and the person who owns it. Agree which access continues after handover. Replace or revoke unnecessary credentials at the issuing service, update legitimate workflows and verify the result. Deleting a local file does not cancel a key.

Start with the automations that must keep working

The campaign is finished, but a lead-routing script still runs every morning. A client’s CRM key also lives in a freelancer’s automation account. An assistant has a connector to the same system. A good handover begins with these working relationships, because changing a key without understanding them can interrupt the client’s business.

Create a record for each service: client owner, purpose, account or key name, permissions, storage location and dependent workflow. Include hosted automation platforms as well as laptops. Do not put the secret value in the record, a ticket or a shared document. You need a map of access, not another place holding the keys.

Put the client in control of the lasting setup

A client should know who owns the account running an essential workflow. If it runs inside your agency’s personal account, decide whether to transfer it, rebuild it under the client’s account or continue managing it under an explicit agreement. Check the service’s transfer options before promising a move between organisations without interruption.

Separate production work from experiments. A test connector used during a pitch should not quietly become the permanent route into a client’s CRM. Where the provider allows it, use separate credentials for distinct jobs and grant only the access each job needs. That makes a later change easier to understand and less disruptive.

A handover that keeps work running

  1. Map

    Find every dependent workflow.

  2. Replace

    Test the client-owned access.

  3. Retire

    Revoke and verify old access.

Example workflow.

Replace access without breaking the workflow

For a planned handover, agree a change window and an owner on both sides. Follow the provider’s process to create replacement access, update the intended workflows and test a representative job. Then revoke the old credential and verify the old route no longer works. Some services use a different rotation sequence; follow their documentation.

If a key is exposed, treat that as an incident rather than waiting for the next scheduled handover. GitHub’s guidance puts revocation or rotation first when a committed secret is involved. Removing the visible text alone does not remove the access it grants. Preserve useful incident details without spreading the secret into more messages.

Check people, agents and unattended jobs

Ask each project contributor which tools they connected. Review editor integrations, AI assistants, deployment services and scheduled automations. Someone leaving a Slack channel does not establish that their other access has ended. The same applies to cancelling an agency seat while a shared credential remains in an external workflow.

Finish with a concise handover record: what remains active, who owns it, which credentials were replaced, when old access ended and what still needs a decision. Have the client confirm the ongoing workflows they rely on. Keep any exception visible, especially if support access continues beyond the project’s final invoice.

Use the device view as one part of the check

Cybee shows installed AI tools and mapped MCP connections on enrolled Macs. This gives the handover a useful starting point: which tools did this team member connect? Available activity records can support follow-up questions, but do not establish that every use or every secret has been found.

Cybee does not currently promise universal API-key discovery, bulk revocation or rotation across client services. The service that issued the access remains where you verify those changes. Bringing that boundary into the handover is practical: your client gets a clear owner and an honest record, instead of a vague assurance that everything was removed.

What to remember

  • Map the workflows before changing their credentials.
  • Keep secret values out of handover documents.
  • Verify revocation at the issuing service and record any continuing access.
Sources and further reading

Product scope and provider guidance can change. Check the linked source for your own setup.

Put it to work.

Continue with a practical guide or see how cybee helps with the work.