Can API request logs be retrieved by originating IP address for a specific API key?

Hey,

I’m looking to understand the API logging and usage visibility available for OpenAI API keys.

For a specific API key, is there a way to retrieve request-level information that includes the originating IP address?

Ideally, I’m looking to understand whether information such as the following is available:

  • Originating IP address
  • Request timestamp
  • Model used
  • Token usage
  • Request-level cost/spend
  • Request or prompt details

If this information isn’t available through the OpenAI dashboard, API, or usage endpoints, is there a recommended way to identify the source of requests made using a particular API key?

Thanks in advance for any guidance.

Hey, welcome to the forum!

There’s currently no documented way to retrieve request IP addresses for a specific API key. Going forward, using separate keys for each application and keeping your own request logs can help identify where requests are coming from.

OpenAI also recommends logging request IDs for troubleshooting: https://developers.openai.com/api/reference/overview#debugging-requests

Farah

Keeping our own request logs can help understand the OpenAI requests made by our application. But I want to check if my key was used else where apart from my application as I suspect that my API key could’ve been compromised. Though I’ve archived the key, I want to know from where it originated or what kind of prompts were used on it. Is there any other way to identify this?

In the absence of IP address reporting per API call, you can stop the problem before you ever see unknown IP addresses, by using IP allowlists that you set up in the platform site for your organization or projects:

https://platform.openai.com/settings/organization/security/ip-allowlist

Without remote access toolkit to your known edge IPs, that should stop even compromised key use cold.

“What kind of prompts” is not a question that can be answered, as call content logging (which is only present in the platform site for manual inspection) can be disabled by individual API call parameter.