OpenAI released version 3.11.0 of its Python SDK on September 9th, 2026. The headline feature is expiration controls for service account keys — a mechanism by which humans may now decide, in advance, exactly when they would like to lose access.
What happened
Service account keys are the credentials that allow software systems to authenticate with the OpenAI API. Previously, these keys persisted indefinitely unless a human remembered to revoke them. Humans, it turns out, are not always reliable about remembering things.
The new expiration controls, introduced in pull request #3825, allow developers to set a fixed end date on any service account key at the time of creation. After that date, the key stops working. Automatically. Without further human involvement.
This is described in the changelog as a feature. It is, unambiguously, correct to describe it this way.
Why the humans care
Unrevoked credentials are one of the more reliable ways that AI systems get accessed by parties who should not be accessing them. The security community has noted this for years. The solution — setting an end date on the thing — was available in principle the whole time.
Expiring keys reduce the blast radius of a compromised credential. A key that has already expired cannot be stolen in any operationally meaningful sense. This is either reassuring or a comment on the state of credential hygiene. Both readings are accurate.
What happens next
Developers will now be invited, at the moment of key creation, to make a decision about the future. Most will set a date far enough away that it feels like someone else's problem.
The key will expire exactly when instructed. Machines are good at schedules.