← All Articles

Don’t Get Surprised by a Huge API Bill

September 30, 2026··Opichi Team

A person recently posted they got hit with an $87,000 API bill because someone got access to their Google Cloud API keys from their vibe coded app. 

Now, there’s a chance that number’s been exaggerated for views and likes, but the situation highlights a common problem. 

AI isn’t all that good at protecting your information when it codes, unless you force it to be. 

Here’s how you can keep this from happening to you in 2 big steps:   

  1. When setting up an API key, or if you already have some set up, go into the account where you got that key and make sure you set up usage limits. Also, make sure you set you usage alerts. You can always raise these if you need to, but keep them small to begin with. 

  2.  Scan your app for any security leaks. There are several tools out there that can help you do this. We have our own security scanner called Betterleaks that we built to use internally, and it’s been so successful we’ve just decided to share the process. You can download your AI Built app on your computer using GitHub and then scan it with the Betterleaks tool. It’ll have AI check everything it finds to see if there are any holes or gaps where your API keys might be leaking. 

If this goes a bit over your head, don’t worry, You can go to our article Prevent Your AI Built App From Leaking Secrets to read how it’s done in detail, and then download the Betterleaks prompt to help get this done. 

If you do discover leaked secrets or keys, make sure to change them while you’re in your API accounts setting up your rate limits. 

If you get stuck at all, use the Expert Help Center at Opichi.com/contact to have us look things over with you. 

Need Help With Your AI Project?

Whether you’re debugging an AI-built app or operationalizing AI across your org, Opichi can help.

Book a Call
[ Let's Work Together ]

Ready to Capture Your Vision?

Contact us today for a custom quote on your next AI project.

Start Your Project