Protect the OpenAI API key
Apply least privilege and secret-handling controls to the stored credential.
Exact navigationAdmin Area → Setup → Settings → AI → OpenAI
Before you begin
- Use an account with Settings: Edit and confirm the intended record or setting before making a change.
- Follow the exact route above. If the screen or action is absent, check module activation, ownership and permissions rather than using another person’s account.
- Use controlled test data for configuration, integration, email, AI, payment, portal or automation changes before production-wide use.
What this guide covers
Apply least privilege and secret-handling controls to the stored credential. The instructions reflect the supplied module’s registered menus, controller actions, views, settings and code-backed validation flow.
Exact step-by-step process
- Open Admin Area → Setup → Settings → AI → OpenAI.
- Select the exact record or option described in this guide.
- Complete the displayed fields or action using the rules below.
- Save or submit once and resolve any validation response.
- Verify the resulting record, status, file, notification or integration effect.
Fields, choices and supported possibilities
ActionProtect the OpenAI API key
Exact navigationAdmin Area → Setup → Settings → AI → OpenAI
Module version1.0.0
VerificationConfirm the saved record, status, output or setting in the same workspace and review any linked activity, file or notification.
Code-backed validations and workflow rules
- The settings view renders the key as a password input.
- The module has no built-in rotation, expiry or usage-metadata workflow.
- Rotate through the provider account and replace the stored value when required.
Expected result and verification
- The supported protect the openai api key flow completes without bypassing permission or validation checks.
- The resulting record, setting, status, file, delivery event or external response is visible from the relevant workspace.
- Unexpected validation, provider or linked-record errors are investigated before retrying.
Security, privacy and operational checks
- Restrict the API key and AI settings to authorised administrators.
- Do not submit confidential, special-category or unnecessary personal data to the external AI provider.
- Review generated text before using it in customer, staff, legal, financial or compliance communication.
- Monitor provider billing and retention independently because this module has no built-in cost dashboard.
