# OpenAI API Key Stored in Plaintext (Security Risk)

**URL:** <https://forums.plex.tv/t/openai-api-key-stored-in-plaintext-security-risk/926247>\
**Category:** Plex Labs\
**Tags:** plexamp\
**Created:** [July 18, 2025, 4:28am UTC](https://forums.plex.tv/t/openai-api-key-stored-in-plaintext-security-risk/926247 "2025-07-18T04:28:56Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![billy\_nimbus](https://avatars.discourse-cdn.com/v4/letter/b/6de8d8/32.png) [@billy\_nimbus](https://forums.plex.tv/u/billy_nimbus)\
**Post date:** [July 18, 2025, 4:28am UTC](https://forums.plex.tv/t/openai-api-key-stored-in-plaintext-security-risk/926247/1 "2025-07-18T04:28:56Z")

</div>

**Title:** OpenAI API Key Stored in Plaintext (Security Risk)

**Description:**  
Long-time Plexamp fan here — nothing else like it. Loving the ChatGPT feature, but I spotted a potential security concern:

The OpenAI API key pasted into Plexamp’s **Settings → OpenAI** panel is saved in **plaintext** within LevelDB logs:

~/Library/Application Support/Plexamp/Local Storage/leveldb/

- The full key remains visible in the UI.
- It’s unmasked and unencrypted on disk.
- If your machine is shared, accessed remotely, or compromised, this exposes the key.

**Screenshots:**

1. OpenAI settings panel with API Key visible.
2. Two Plexamp app versions side-by-side (iOS-like vs native ARM).  
_(I can provide actual screenshots upon request.)_

 ![Screenshot 2025-07-18 at 12.24.49 AM](https://global.discourse-cdn.com/plex/original/4X/a/6/a/a6ae4c39cfd7ee26a9d82f6ce24a08f59b108b62.png)

**Steps to Reproduce:**

1. Open Plexamp on macOS.
2. Navigate to **Settings → OpenAI**.
3. Paste your API key.
4. Close Plexamp.
5. Inspect LevelDB files in the above path — the key appears in plaintext.

**Expected Behavior:**

- The key should be masked (e.g., `••••••••`) in UI.
- On disk, it should be encrypted or securely protected (macOS Keychain, etc.).

**Impact:**

- Exposes users to key leakage if macOS account is accessed by others or compromised.
- Could lead to leaked keys, unintended costs, or unauthorized access.

**Environment:**

- macOS Monterey / Ventura on Mac mini (Apple Silicon).
- Plexamp v4.12.3 (React Native v0.72.15).
- Both ARM-native and iOS-styled builds.

**Additional Info:**

- Happy to submit logs or screenshots privately.
- Let me know if there’s a preferred secure channel for these types of reports.

---

<div class="post-metadata">

**Author:** ![system](https://global.discourse-cdn.com/plex/original/3X/2/a/2acb9765406f63293d357b4ec509ec39aa28f2ad.png) [@system](https://forums.plex.tv/u/system)\
**Post date:** [October 16, 2025, 4:29am UTC](https://forums.plex.tv/t/openai-api-key-stored-in-plaintext-security-risk/926247/2 "2025-10-16T04:29:27Z")

</div>

This topic was automatically closed 90 days after the last reply. New replies are no longer allowed.
