Answer
How do I check if an API key or AWS key is still live without sending it to a third party?
You don't need a third-party checker to find out if a key still works. For AWS, run aws sts get-caller-identity --profile <name> locally — it calls AWS directly and returns an error if the credentials are dead. For OpenAI or Anthropic keys, call the provider's own list-models endpoint with the key; a 200 response means it's live, a 401 means it isn't. Neither leaves your machine toward anyone but the provider.
Updated · Kloudle
How do you check an AWS key is live, without sending it anywhere?
Run aws sts get-caller-identity --profile <name>. AWS's own CLI documentation describes it as returning "details about the IAM user or role whose credentials are used to call the operation" — your UserId, Account, and Arn if the credentials work, or an authentication error if they don't. The AWS CLI signs the request with your local credentials and sends it to AWS's own STS endpoint; nothing about the call involves a third party, and the response tells you definitively whether that profile is currently valid.
This is also a narrow check: it confirms the credentials authenticate, not what they're authorized to do. A dead key and a live-but-locked-down key both need separate handling, but get-caller-identity is the fastest way to rule out "this key simply doesn't work anymore."
How do you check an OpenAI or Anthropic key is live?
The same pattern applies to model API keys: call the provider's own list-models endpoint with the key, from your own machine, and read the HTTP status. Anthropic's API reference documents GET /v1/models as the call that "list[s] available models," authenticated with the X-Api-Key header — a request that succeeds only if the key is valid, costs nothing beyond that request, and never requires handing the key to anyone but Anthropic's own API. OpenAI's API works the same way: list-models calls on your own provider's domain, authenticated with your own key, answered by that provider alone.
A failed call (401/403) means the key is dead or revoked; a successful one confirms it's live, without ever sending a test prompt or spending more than the cost of a metadata call.
Why is pasting a key into an online "key checker" risky?
Every method above works precisely because the only party that ever sees your key is the provider that issued it. A third-party "paste your key here to check if it's valid" site breaks that: the key has to leave your machine and pass through that site's servers to reach the provider on your behalf, which means the operator of that site — or anyone who compromises it — now has a copy of a working credential. Even a well-intentioned checker is, functionally, a credential collection point you don't control and can't audit.
There's no technical reason to accept that risk: the provider's own CLI or API already answers the question directly, for free, without a middleman.
How does blast verify check keys locally?
Agent Blast Radius's free scan finds and fingerprints credentials on your machine without ever checking whether they still work. blast verify is a separate, paid step for the narrow question "is this one still live," and it does exactly what's described above, on your own machine: for AWS profiles it runs aws sts get-caller-identity locally, and for OpenAI or Anthropic keys present in your environment it makes a local model-list API call to that provider. No other credential classes are supported — not GitHub, npm, GCP, or Azure.
It costs $0.10 USDC per check, paid on Algorand through the x402 protocol using your own wallet — see agent payments and wallet setup. The server at abr.kloudle.dev never receives the key, a profile name, an environment variable name, or a file path; it sees only a class count, like aws-sts-identity:2, and returns an Ed25519-signed manifest. The check itself — the actual AWS or provider call — runs on your machine, the same way the CLI commands above do. Payments are final, and this still only tells you whether a credential authenticates, not whether it was compromised.
Check your own machine
See what an agent running as you can reach. Offline, read-only, never prints values:
npx -y @kloudle/agent-blast-radius@0.3.0Inside your agent: install guides for Claude Code, Codex, Cursor, Claude Desktop and more. Which keys are live? npx -y @kloudle/agent-blast-radius@0.3.0 verify (paid per check).
Frequently asked
Does checking if an AWS key works require sending it to a third party?
No. aws sts get-caller-identity runs locally and talks only to AWS's own STS endpoint, authenticated by the credentials already on your machine. It returns your UserId, Account, and Arn if the key is valid, or an error if it isn't.
How do I check if an OpenAI or Anthropic key still works without spending much?
Call the provider's own list-models endpoint with the key. Anthropic documents GET /v1/models for exactly this; a 200 response means the key is live, a 401 means it's dead or revoked, and the only party that sees the key is the provider itself.
Why not just use an online API key checker tool?
Because your key has to pass through that site's servers to reach the provider, giving the site's operator a working copy of your credential. The provider's own CLI or API already answers the same question directly, with no middleman involved.
How is blast verify different from the free blast scan?
The free scan only locates and fingerprints credentials; it never tests whether they work. blast verify is a separate paid check, limited to AWS profiles and OpenAI/Anthropic keys, that runs the same local calls described above and reports only class counts to the server, never values.
Sources
- get-caller-identity — AWS CLI Command Reference — AWS
- List Models — Anthropic