Operator guide

LiteLLM credential exposure response

A gateway credential exposure is not resolved by rotation alone. This guide explains how to contain the exposure, confirm revocation, preserve request evidence, and determine whether the exposed credential was used before the response began.

InferTrail · September 2026

Does rotation tell me whether a key was used?

No. Rotation is prospective. It stops future use only if revocation completes. Review historical gateway and provider events before retention windows expire.

What should an operator do next?

Preserve the relevant time window, attach customer and deployment context, and make the smallest reversible response that contains credible risk. Record why a case opened so another investigator can reproduce the decision.

Where does this approach fail?

Behavioral metadata cannot identify intent or permission by itself. Legitimate launches, failover, automation, and registered relays can resemble misuse. Treat the output as a ranked investigation queue, then resolve authorization with stronger identity and reconciliation evidence.

Frequently asked questions

What is the highest-confidence post-rotation signal?

Requests authenticated with a hard-revoked credential after a defined grace period. Verify revocation and clocks first.

Does InferTrail read prompts or responses?

No. The investigation design uses provider-visible metadata and customer context, with content collection governed separately if a customer requires it.

What is the right first action?

Open a verification case, preserve evidence, and check credential state before making a destructive enforcement decision.

Related guides