When to use it
- Catching a leaked or compromised key that’s being abused after sitting idle.
- Spotting old integrations that have come back online unexpectedly.
- General key hygiene — knowing when “dormant” keys aren’t actually dormant anymore.
What you configure
| Setting | What it does |
|---|---|
| Dormant Days | How long a key has to be unused before its return triggers an alert (default 30 days). |
| Scope | What to watch — your User keys, individual keys (Per API Key), or for organizations, Organization / Team / Per API Key. |
| Schedule | How often to evaluate — daily, weekly, or monthly. |