Respond to a suspected compromised account

Rotate what can be rotated, re-establish your identity, and escalate if needed.

Updated September 14, 2026 · 1 min read

  1. Rotate or revoke API credentials immediately if any may have been exposed — see rotating and revoking API credentials.
  2. Re-register your device identity if you believe your device itself (not just an API key) may be compromised — see changing an authentication factor. Since PTERI's model requires a fresh signature for every sensitive action, an attacker without your physical device and biometrics cannot act as you going forward, even if something else was exposed.
  3. Review recent activity in your Developer Dashboard for anything you don't recognize.
  4. Escalate to us — open a ticket under Account & Access with severity SEV-2 or higher if you believe an action was taken without your authorization. If the root cause looks like a platform vulnerability rather than a lost device or exposed key, use Report a Security Vulnerability instead.

Still stuck?

Ask Kai about this article, or open a ticket with our team.

Submit a ticket