Respond to a suspected compromised account
Rotate what can be rotated, re-establish your identity, and escalate if needed.
- Rotate or revoke API credentials immediately if any may have been exposed — see rotating and revoking API credentials.
- Re-register your device identity if you believe your device itself (not just an API key) may be compromised — see changing an authentication factor. Since PTERI's model requires a fresh signature for every sensitive action, an attacker without your physical device and biometrics cannot act as you going forward, even if something else was exposed.
- Review recent activity in your Developer Dashboard for anything you don't recognize.
- Escalate to us — open a ticket under Account & Access with severity SEV-2 or higher if you believe an action was taken without your authorization. If the root cause looks like a platform vulnerability rather than a lost device or exposed key, use Report a Security Vulnerability instead.