Home/ Articles/ [ whoever-holds-the-api-keys-after-launch-controls-the-system ]

The Person Holding Your API Keys Controls Your Business

A fixed price launch should end with a handover, not a hostage situation. This post argues that you must own every account, domain and key, not only the finished site.

A single brass key resting on a pale stone surface, lit from one side.

Every software project ends with a moment nobody plans for. The site goes live, the invoice is paid and everyone moves on to the next thing. But somewhere in that handover sits a small, unglamorous file: the collection of API keys, passwords and access tokens that make the system actually work.

Whoever controls that file controls the system. Not the person who built it. Not the person who paid for it. Whoever holds the keys.

This matters more than most business owners realise until the day it goes wrong. Say your payment provider needs a new key rotated. Say you want to move your email service to a different plan. Say the developer who set everything up is no longer answering messages. If the keys live only in someone else's account, none of that is your decision to make. It is theirs.

Why studios hold on to keys

Some studios keep keys under their own accounts because it is simpler for them. One dashboard, one login, one place to debug when something breaks. There is a reason for this, and it is rarely malicious. But convenience for the studio should not become dependence for you.

A fixed price project should end with a handover, not a hostage situation. When we finish a build at Yunaris, ownership of every account, domain, API key and service subscription transfers to you as a matter of course. You should never need our permission to change a payment provider, add a staff member to an admin panel or move hosting elsewhere.

The test of a good handover is simple: can you fire us and keep running.

If a studio cannot answer that question clearly before you sign anything, ask again before you pay anything. Find out who owns the domain registration. Find out whose email address is attached to the payment gateway account. Find out whether the analytics account was created under your business or under theirs.

None of this is about distrust. Most studios, including us, are not trying to trap anyone. But systems tend to drift towards whatever is easiest to set up, and the easiest setup is usually the one where the studio keeps the keys because nobody asked otherwise. You have to ask.

What to check before launch

Before your project goes live, request a simple list: every third party service the system depends on, who owns each account and where the credentials are stored. If that list does not exist yet, ask for it to be built as part of the handover, not after.

A launch is not finished when the site works. It is finished when you can run the business without calling anyone for permission.