OpenAI
LiveDeveloperOpenAI connector — read-only, agentless
Scans your OpenAI organization: admin + project API keys (with OpenAI’s native last-used signal), member roles, projects, and audit events — flags stale, org-wide, and orphaned keys, owner sprawl, and audit logging left disabled.
What we scan
- API-key inventories (admin + per-project): names, scope, created / last-used — never credentials (values are redacted by OpenAI)
- Organization members, roles, and projects
- Audit-log events (optional — opt-in on OpenAI’s side; a finding tells you if it is off)
Read-only monitoring — nothing in your OpenAI data changes unless you turn on auto-remediation and grant write access separately.
Security findings
6 detection rules run on every OpenAI scan. Each finding ships with a plain-language explanation, the evidence behind it and remediation steps.
- HIGHOver permission
OpenAI API key is org-wide (not workspace-scoped)
- HIGHStale access
OpenAI API key outlives its departed creator
- HIGHOver permission
OpenAI org-wide API key held by a non-admin member
- MEDIUMStale access
OpenAI API key unused for 90+ days
- MEDIUMMisconfig
OpenAI organization has too many admins
- MEDIUMMisconfig
OpenAI audit logging is not enabled
How to connect OpenAI
Step 1
Sign up or log in to 8200.dev
Step 2
Go to Connectors → OpenAI
Step 3
Click Connect and authorize via OpenAI's consent screen
Step 4
8200.dev scans automatically — results appear within minutes
Connect your first source in minutes — free, read-only, no sales call.