A credential is revoked only after the code proves nothing reads it
Decided
three pieces of leftover state were removed — the read-write Better Stack tokens My Uptime token and My Telemetry token, the never-used Zammad token novelsystems-website, and the __probe_publishable_key__ row in public.quotes — and in each case the proof of safety was gathered *before* the deletion, from code or from the vendor's own telemetry, never from the absence of a reason to keep it.
Why this is a decision and not a chore. "Nothing uses it" is the most dangerous sentence in an operations log, because it is normally an inference from not having looked. The Better Stack case shows what looking costs and what it buys. UPTIME_MONITOR_API_KEY is marked Sensitive in Vercel and cannot be read back, so the token in use could not be identified by comparing values. The account held four tokens. Three live pages — /, /support and /security — render figures fetched with that credential through lib/uptime-monitor.ts, which is imported by lib/support-center.ts, lib/security-posture.ts, lib/helpdesk.ts and lib/constants.ts. Revoking the wrong one would have taken the uptime numbers off the marketing site, the support page and the security page simultaneously, and the only symptom would have been a figure quietly not rendering.
The identification came from this file's sibling. CHANGELOG's 2026-08-03 entry records the *shape check* performed at the moment the value was typed into Vercel — len: 24, startsWith: "GVr", hasSpace: false. Exactly one token in the dashboard matches: GVrNbyfKF7KNnc2aGEJxeE21, the read-only novelsystems-ca status board (read-only). The read-write token canRJs1f2x6eiR82FHftpqHH does not. That is a positive identification of the token to *keep*, which is a stronger claim than a guess about which to remove, and it is only available because the shape check was written down at the time. Recording a non-secret fingerprint of a secret you cannot read back is what made this reversible.
The telemetry token was removed on the same evidence rather than a separate judgement call: lib/uptime-monitor.ts calls exactly two URLs, both uptime.betterstack.com/api/v2/monitors, both GET, and a repository-wide search for telemetry.betterstack, logs.betterstack, LOGTAIL and TELEMETRY_TOKEN returns nothing. The site's entire relationship with Better Stack is two read-only GETs, so a read-write token of either kind was scope the code could not justify.
For Zammad the evidence was the vendor's, not ours. The token list carries a Last Used column; novelsystems-website was blank and ns-site-2 read "just now" from the live ?probe=deep call to users/me. That blank column is the same signal that originally diagnosed the 401 in D-031, so it was already known to be load-bearing here rather than decorative.
For the quotes row the question was not whether the row was ours but whether anything else was in the table. A column-name-agnostic census — to_jsonb(q)::text ilike '%probe%' — returned total 1, probe_rows 1, exact_marker 1. The diagnostic row was the table's only row, so there was no real intake data to put at risk, and the DELETE was still scoped to both the primary key and the marker string so that it could not have matched anything else even if the census had been wrong.
The alternative was to leave all four in place. Rejected for the Better Stack tokens specifically: Better Stack displays API tokens in cleartext on the settings page forever, and that account also owns the public status page, so a read-write token there is a credential that can rewrite the thing customers look at to decide whether we are up. Unused is not the same as harmless when the scope is write and the storage is plaintext.
This would be wrong if a future feature needed to *write* to Better Stack — creating monitors from code, pushing telemetry — in which case a new token should be minted with exactly that scope rather than a broad one kept around in anticipation. It would also be wrong to read this entry as licence to delete unrecognised credentials generally: the licence here is specifically to delete credentials whose non-use has been demonstrated, and the demonstration is the work.