// the verdict, and the quote that decides it
No, as of 2026-10-02. Google's Gemini API key page, last updated 2026-09-25, lists exactly one rejection rule for standard keys:
No date for restricted keys appears anywhere on the page. It does still say that "Gemini API will move from standard keys to auth keys". That plan is real, but it has no deadline attached. The only other dated items are that new AI Studio keys are auth keys from May 28, 2026, and that dormant unrestricted keys have been blocked since May 7, 2026.
Fair to the headline: the date was Google's
This wasn't invented. In June, DoiT's blog (2026-06-17) laid out the plan as it stood: "September 2026: The Gemini API will reject requests from all standard keys. You'll need to be on auth keys by then." Google's own key page carried a September 2026 standard-key cutoff through mid-September too. A third-party docs-change tracker (techdevnotes) logged on 2026-09-26 at 00:02 UTC: "Removed the September 2026 notice that the Gemini API would reject standard keys (and that you must migrate to auth keys by then)". That matches the page's "Last updated 2026-09-25".
So the headline reported a real plan that Google dropped a few days before the date. The verdict is about the claim as people still share it, that every key dies in September. That didn't happen, and today's first-party page gives it no date.
We could not load an archived copy of Google's earlier page from our build machine. The removal rests on the tracker's log and on search-engine snippets of the old wording, not on a first-party archive.
If you just use the app: nothing to do
The Gemini app, and Gemini inside Google's own products, don't use API keys you manage. Nothing in this story touches them.
The one case that matters is a Google API key you pasted into some third-party tool, such as a writing app, a browser extension or a self-hosted chat UI. If that key still works today, it's either restricted or a newer auth key. Either way, Google's page sets no date to stop it. If it stopped working back in June, it was probably unrestricted, and the fix is a new key from AI Studio, which is restricted to the Gemini API by default.
If you write code: restrict every key
Google's own fix, from the June announcement on its developer forum:
generativelanguage.googleapis.com).One trap: if the key also serves Maps, Firebase or another Google API, don't just tick Gemini on it. Google's page says to restrict it to the other APIs, leave the Generative Language API off, and "Create a separate, restricted key in AI Studio to continue using the Gemini API." One key per job also means a leaked Maps key can't run up a Gemini bill.
Then plan, without panic, for auth keys. Google says it "will move from standard keys to auth keys", and auth keys are "restricted to the Generative Language API (Gemini API) by default" with faster leaked-key enforcement. Migrating means creating a new key in AI Studio, swapping it in, testing, then revoking the old one. There is no published deadline today.
Related: keeping keys out of your agent's reach, and a vendor deadline that was real.
What would change this verdict
One thing: Google publishing a date for standard keys again. The move to auth keys is still on the page, so a new cutoff could come back with little notice. If one does, this verdict flips to real for that date, and the coder advice becomes "migrate to auth keys" rather than "restrict".
To check it yourself, open ai.google.dev/gemini-api/docs/api-key, read the "Unrestricted keys rejected" bullet and the "Last updated" line at the bottom, and search the page for a month name.
Sources: Google AI for Developers, "Using Gemini API keys" (ai.google.dev/gemini-api/docs/api-key, last updated 2026-09-25); Google Developer forum, "Gemini API Update" (discuss.google.dev/t/gemini-api-update/375447, 2026-06-24). Coverage: DoiT blog, 2026-06-17. Docs-change log: techdevnotes.com, 2026-09-16 and 2026-09-26 entries. All checked 2026-10-02.
One concept a week. Free.
The deeper, copy-paste version of each ToolCall short — in your inbox.
// total: 0.00 · spam: void · unsubscribe: one click
