Stream keys, rotation and account security
Your channel ingest key is a credential. Anyone who has it may be able to publish to the channel, so keep it out of screenshots, repositories, chat and overlay URLs.
If a key is exposed
- Open the channel settings and choose Rotate key.
- Update the encoder and any approved backup source.
- Check the ingest log for unexpected publishers.
- Revoke devices or integrations you do not recognise.
Use a separate channel for testing and avoid sharing one key across a team or production systems. Enable two-factor authentication or passkeys on your account, use a unique password, and review workspace members regularly. Support will not ask for a complete key, password or provider secret.