Supported providers

Capabilities are read from each vendor’s official documentation and cited with the date they were read. Where a provider does not expose an API for something, that is stated rather than worked around.

Verified — 11

Anthropic

aiGuided rotation

Claude models via the Messages API.

  • The Admin API can deactivate a key but documents no create endpoint, so a replacement must be created in the Console.

Cloudflare

infrastructureAutomated rotation

DNS, Workers, R2, and the edge network.

  • Creating or deleting a token requires a token with API Tokens write permission.

Deepgram

voiceAutomated rotation

Speech-to-text and audio intelligence.

  • Key operations are scoped to a project id.

ElevenLabs

voiceGuided rotation

Text-to-speech and voice cloning.

  • Programmatic create and delete cover service-account keys only, which require a multi-seat workspace. Personal keys are dashboard-only.
  • MyAPIKeys has not implemented the service-account flow, so rotation here is guided rather than automated.

GitHub

developer-toolsGuided rotation

Repositories, Actions secrets, and packages.

  • Personal access tokens can only be created in the web UI.
  • Revocation over REST covers org-approved fine-grained tokens only, and is performed by an organization owner — not by the token holder.

OpenAI

aiGuided rotation

GPT models, embeddings, and the Assistants API.

  • Create and revoke apply to organization admin keys and require an admin key to call.
  • Ordinary project keys document delete but not create, so a project key can be revoked automatically but its replacement must be minted in the dashboard.
  • MyAPIKeys has not implemented the admin-key flow, so rotation here is guided rather than automated.

Retell AI

voiceGuided rotation

Voice agents and call orchestration.

  • Key creation and deletion are documented as dashboard actions only.
  • The cheapest read endpoint is a POST, not a GET.

Stripe

paymentsGuided rotation

Payments, Connect, and billing.

  • Stripe documents key creation, expiry and rotation as Dashboard-only operations.

Supabase

databasesGuided rotation

Postgres, Auth, Storage, and Edge Functions.

  • Create and delete operate on a project’s publishable and secret keys. The personal access token used to call the Management API is itself created by hand in the dashboard.

Twilio

communicationsAutomated rotation

SMS, voice, and telephony.

  • Creating a key accepts Account SID + Auth Token, a Main key, or a restricted key with api-keys/create. Deleting accepts only Account SID + Auth Token or a Main key, so a restricted key can create but not revoke.
  • The 2010-04-01 Keys resource covers Standard and Main keys. Main keys cannot be created over REST at all.

Vercel

infrastructureAutomated rotation

Hosting, edge functions, and environment variables.

  • Minting a new token requires a full-account token; a project-scoped token cannot.

Stored but not health-checked — 11

These can be stored, organised, mapped into projects and deployed. They are not validated, because no validation endpoint has been verified for them. That is a statement about this product, not about the vendor.

Google Cloud

cloud

Compute, storage, and the Google APIs surface.

Google Maps Platform

cloud

Geocoding, routes, and places.

Hostinger

infrastructure

Hosting, VPS, and domains.

HubSpot

marketing

CRM, marketing, and sales automation.

n8n

developer-tools

Workflow automation.

Netlify

infrastructure

Static hosting and edge functions.

PostHog

analytics

Product analytics and feature flags.

Replit

developer-tools

Cloud development environments.

Resend

communications

Transactional email.

Synthflow

voice

No-code voice assistants.

Vapi

voice

Voice agent infrastructure.