Revocation triggers
What causes an API key or hostname authorization to be revoked, and how fast. For the narrative version, see API keys and Cybersecurity verification.
| Trigger | Detection source | Signal | Action | Typical latency |
|---|---|---|---|---|
| Key committed to git (harness, IDE, tooling) | Merki API observes the commit; private repos without a Merki integration are not visible | Key pattern present in a repository commit | Key revoked automatically | Immediate after detection |
| Key found on the public internet | Merki monitoring and reports | Key visible on a public code host or site | Key revoked automatically | Within 24 hours of detection |
| Challenge removed | API re-check | DNS TXT record missing or .merki file stops resolving | Hostname access suspended, key revoked | 30 to 60 seconds |
| Challenge expired | API re-check | Challenge older than the 7 day maximum | Hostname access suspended, key revoked | 30 to 60 seconds |
Notes
- Revocation applies to Merki-issued keys and to BYOK routes registered with Merki.
- A revoked key stays revoked. Appeals: contact billing@merki.dev with the key prefix and the triggering commit or URL; reviewed within 2 business days.
- Repeated exposure can affect the account itself. See the Acceptable use policy.