Action Required: Restrict Gemini API Keys by June 19 to Avoid Service Disruption
Google is taking significant steps to bolster the security of its Gemini API, urging all developers to take immediate action regarding their API keys. Effective June 19, 2026, the Gemini API will no longer process requests originating from unrestricted standard API keys. This change is a direct response to concerns over unauthorized usage and the potential for substantial, unexpected billing charges that have impacted some developers.
Developers with Google Cloud projects that have the Gemini API enabled and contain unrestricted keys are now required to take corrective measures. There are two primary options available: developers can navigate to their Google Cloud Credentials, select the relevant API key, and apply explicit restrictions to it, specifically limiting its use to the `generativelanguage.googleapis.com` service. Alternatively, developers can opt to generate entirely new API keys directly within Google AI Studio, as keys created through this platform are automatically restricted to the Gemini API by default.
This proactive security enhancement aims to safeguard developers from malicious actors who might exploit publicly exposed or otherwise compromised unrestricted keys to incur massive cloud bills. The move underscores Google's commitment to providing a more secure development environment for its AI services. Developers are strongly encouraged to implement these changes promptly to ensure uninterrupted service and protect their projects from potential security vulnerabilities and financial liabilities.
Read original source