Supported providers
Capabilities are read from each vendor’s official documentation and cited with the date they were read. Where a provider does not expose an API for something, that is stated rather than worked around.
Verified — 11
Anthropic
aiGuided rotationClaude models via the Messages API.
- The Admin API can deactivate a key but documents no create endpoint, so a replacement must be created in the Console.
Cloudflare
infrastructureAutomated rotationDNS, Workers, R2, and the edge network.
- Creating or deleting a token requires a token with API Tokens write permission.
Deepgram
voiceAutomated rotationSpeech-to-text and audio intelligence.
- Key operations are scoped to a project id.
ElevenLabs
voiceGuided rotationText-to-speech and voice cloning.
- Programmatic create and delete cover service-account keys only, which require a multi-seat workspace. Personal keys are dashboard-only.
- MyAPIKeys has not implemented the service-account flow, so rotation here is guided rather than automated.
GitHub
developer-toolsGuided rotationRepositories, Actions secrets, and packages.
- Personal access tokens can only be created in the web UI.
- Revocation over REST covers org-approved fine-grained tokens only, and is performed by an organization owner — not by the token holder.
OpenAI
aiGuided rotationGPT models, embeddings, and the Assistants API.
- Create and revoke apply to organization admin keys and require an admin key to call.
- Ordinary project keys document delete but not create, so a project key can be revoked automatically but its replacement must be minted in the dashboard.
- MyAPIKeys has not implemented the admin-key flow, so rotation here is guided rather than automated.
Retell AI
voiceGuided rotationVoice agents and call orchestration.
- Key creation and deletion are documented as dashboard actions only.
- The cheapest read endpoint is a POST, not a GET.
Stripe
paymentsGuided rotationPayments, Connect, and billing.
- Stripe documents key creation, expiry and rotation as Dashboard-only operations.
Supabase
databasesGuided rotationPostgres, Auth, Storage, and Edge Functions.
- Create and delete operate on a project’s publishable and secret keys. The personal access token used to call the Management API is itself created by hand in the dashboard.
Twilio
communicationsAutomated rotationSMS, voice, and telephony.
- Creating a key accepts Account SID + Auth Token, a Main key, or a restricted key with api-keys/create. Deleting accepts only Account SID + Auth Token or a Main key, so a restricted key can create but not revoke.
- The 2010-04-01 Keys resource covers Standard and Main keys. Main keys cannot be created over REST at all.
Vercel
infrastructureAutomated rotationHosting, edge functions, and environment variables.
- Minting a new token requires a full-account token; a project-scoped token cannot.
Stored but not health-checked — 11
These can be stored, organised, mapped into projects and deployed. They are not validated, because no validation endpoint has been verified for them. That is a statement about this product, not about the vendor.
Google Cloud
cloudCompute, storage, and the Google APIs surface.
Google Maps Platform
cloudGeocoding, routes, and places.
Hostinger
infrastructureHosting, VPS, and domains.
HubSpot
marketingCRM, marketing, and sales automation.
n8n
developer-toolsWorkflow automation.
Netlify
infrastructureStatic hosting and edge functions.
PostHog
analyticsProduct analytics and feature flags.
Replit
developer-toolsCloud development environments.
Resend
communicationsTransactional email.
Synthflow
voiceNo-code voice assistants.
Vapi
voiceVoice agent infrastructure.