If someone is broadcasting on your YouTube channel without permission, first stop the transmission if you can, then reset the stream key and replace it in the encoder you recognise. A new key addresses the encoder credential; it does not secure a compromised Google Account, remove unauthorised channel access or guarantee that every broadcast will end immediately.
Treat this as an incident with two possible causes: a key may have been exposed while your account remains under your control, or someone may also have gained access to the Google Account or channel. Follow the urgent steps in order, and do the account-recovery work as well if you see changes you did not make.
Treat the stream key as a credential
A stream key lets an encoder send a video or audio feed to a particular YouTube stream. YouTube Help describes stream keys as a stream’s “password and address”. If another person obtains a usable key, they may be able to send a feed without signing in to your Google Account. That makes the key sensitive even if you never share your Google password.
The distinction matters when you decide what to do next. If a key was pasted into a public screenshot, sent to the wrong person or left in a shared encoder profile, rotate it and check where it was exposed. If you find unfamiliar account activity, new channel managers, changed channel details or altered recovery information, treat the incident as possible account or channel compromise too. Resetting the key alone cannot address those signs.
Do not post the old or replacement key in a support forum, chat or screenshot. Avoid copying it into a note that is shared with people who do not operate the channel. If someone helps with the recovery, share only the access they need through YouTube’s permissions rather than giving them a Google password.
For a channel that normally runs a continuous programme, such as a devotional loop or a local news slate, take care to distinguish the authorised encoder from the unknown feed. The guide to keeping a YouTube playlist livestream running when your computer is off explains the normal always-on arrangement; during an incident, use the same knowledge to identify which account or device is meant to be sending your programme.
Stop the unauthorized feed
If you can reach the active stream in YouTube Studio’s Live Control Room, use the available control to end it. For a scheduled stream, YouTube documents an End Stream action in Live Control Room. If you can identify and control the encoder that is sending the unauthorised content, stop its transmission as well. YouTube’s encoder instructions say to stop sending content from the encoder to end an encoder-originated stream.
After taking the action, check the public watch page and Live Control Room rather than assuming that a button press has settled everything. Confirm that the stream is no longer marked live. If the unknown encoder is not yours, you may not be able to stop it directly. End the stream using the controls available to you, continue with key rotation and account security, and check again for the result.
Do not rely on a key reset as a guaranteed immediate cutoff for an already-running feed. YouTube’s instructions explain how to reset a key and how to end a stream, but they do not promise a particular revocation time for a connection already sending content. The practical response is to use the end-stream control where available, stop any sending encoder you control, rotate the credential, then verify what viewers can see.
If the stream is causing immediate harm, preserve basic evidence before making changes where doing so does not delay stopping it: note the public watch-page URL, the time you noticed it and any unfamiliar stream title or account activity. Do not delay ending the feed to collect a complete record. This information can help you describe the event to YouTube or to the people who administer the channel.
Reset the key in YouTube Studio
Once you have addressed the visible feed, reset the key in YouTube Studio. Open Live Control Room, select Stream from the left menu, find the Stream key section and choose Reset beside the hidden key. Copy the new key using a method that does not expose it to other people.
YouTube says a channel owner or manager can reset a stream key; editors and viewers do not have that permission. If you cannot see the control, do not hand your password to someone else to get the task done. Ask an authorised owner or manager to reset it, and review whether the people with those roles are still meant to have access.
A reset replaces the credential you should use going forward. It is not a substitute for ending a live transmission, and it does not change who can sign in to the Google Account or who has channel permissions. The official YouTube Live setup and stream-key guidance covers the stream setup workflow. Follow the current instructions shown for your channel, since Studio controls can change.
Keep the replacement key private as you move to the next step. If you operate more than one channel or stream, check that you reset the key for the affected channel and intended stream rather than a different setup. Do not assume that changing a saved label or stream title changes the key itself.
Update the authorized encoder
A reset key will not make your legitimate broadcast work until the authorised encoder has the replacement. Open the encoder or service that you operate, find the YouTube stream settings and replace the old key. Check that its destination is the intended YouTube channel and stream before starting it again. YouTube’s setup guidance describes entering the stream key in the encoder alongside the server URL.
If your usual encoder is OBS, FFmpeg or a radio encoder, the replacement belongs in that application’s YouTube output settings. The BUTT encoder routing guide is relevant if your channel uses a radio workflow; the OBS and FFmpeg comparison for a YouTube loop can help you identify which of those applications is normally responsible for sending the feed. Do not change software in the middle of the incident unless you need to; first re-establish the known-good path with the new credential.
Pay particular attention to saved or reused stream configurations. YouTube notes that Reuse settings can carry over the previous stream’s metadata, settings and stream key. After rotation, inspect the configuration you will actually run and confirm it contains the new key. An old saved profile can otherwise make a correctly reset channel appear broken, or lead you to copy the exposed credential back into use.
If the encoder connects by direct YouTube sign-in rather than using a stream key, this reset process may not apply. YouTube’s troubleshooting guidance says to contact the software provider for direct-sign-in cases. Do not paste the new key into an application that does not use one; first establish which authentication method your encoder uses.
For a channel whose normal output is a long-running recorded programme, the 24/7 worship loop guide offers a useful reference for the authorised playback setup. The incident goal is not to redesign that setup. It is to ensure that the encoder you intended to use, and only that encoder, has the replacement credential.
StreamNeo can remove the particular burden of keeping your own computer on as the authorised encoder: you upload a video, provide the YouTube stream key and the broadcast can continue from the cloud with your computer switched off. It is YouTube-only, so it is relevant only if a file-based YouTube loop fits your channel; regardless of the arrangement, keep the key private and update the authorised encoder after rotation.
Secure the Google Account
If you suspect someone signed in to the associated Google Account, secure that account as a separate response. Use Google’s account recovery guidance if you cannot sign in. If you can, review account security, change the password to a new one that is not reused elsewhere, and verify the recovery methods and devices shown are yours. Follow Google’s current prompts for suspicious activity and any additional security checks.
YouTube describes channel hacking as involving compromise of at least one associated Google Account. In that situation, work through account recovery and security first, then undo unwanted channel changes where you can. Secure the Google Accounts of other channel owners and managers as well if they may have been affected. A stream-key reset does not secure any of these accounts.
Look for signs beyond the live feed: unfamiliar sign-ins or devices, changed recovery details, altered channel name or description, unknown uploads, modified permissions or changes to monetisation and other channel settings. The YouTube channel recovery and security guidance sets out official steps for a hacked channel. Check it directly for the current process rather than relying on an old checklist or a third-party message asking for credentials.
If you still control the account, be wary of messages that claim to be support and request your password, one-time code or stream key. Use the official account and YouTube pages yourself. A genuine recovery process should not require you to disclose a sign-in code to someone in a chat.
Review channel access
A person can have channel access without using your personal Google password. Once the account is secure, review the channel’s permissions and any Brand Account access that applies. Remove accounts that are no longer authorised, and investigate unfamiliar roles before restoring normal operations. YouTube recommends limiting access to authorised accounts and advises against sharing sign-in details.
Consider what each person needs to do. Someone who schedules or manages broadcasts may need a channel role, while a viewer does not. Owners and managers can reset keys, so those roles deserve particular attention during an incident. If you do not recognise an account, first make sure it is not a legitimate colleague using a different address; then remove it through the current YouTube or Google access controls.
Review access for channel owners and managers individually, not just the person who first noticed the broadcast. If one manager’s Google Account was compromised, the channel can remain exposed even after you secure your own account and change the stream key. Ask other authorised people to secure their accounts and confirm their recovery details as part of the same incident response.
Record the outcome: which account was removed or retained, who authorised the decision and when the review happened. This is especially useful for a small business or community channel where several people share responsibility. Keep that record free of passwords and stream keys.
Confirm the new feed is working
After the authorised encoder has the replacement key, start the intended stream and check its status in Live Control Room. Confirm that the stream title and channel are correct, the expected programme is visible, and the public watch page is live. For an audio-led channel, listen for sound as well as checking the image; a successful connection alone does not prove the right material is reaching viewers.
If the encoder fails to connect, check the basics in order: correct channel and stream selected, new key pasted without extra spaces, encoder using the expected YouTube destination, and saved profile not restoring the old key. Check whether you are using a stream-key workflow or direct sign-in. Avoid repeatedly changing unrelated settings while you are still unsure which encoder is authorised.
Keep monitoring after the first successful restart. Confirm that no unfamiliar broadcast reappears and that your own stream remains the one viewers can reach. There is no universal time after which you can assume an incident is over; continue checking account activity and channel permissions if the original event suggested wider access.
If the new feed is stable, update any private operating notes that contain the old key, and remove obsolete copies where you control them. Do not put the replacement key into public documentation or a shared troubleshooting post. If you use Reuse settings later, inspect the copied key before going live so an old credential is not inadvertently put back into service.
Before committing, compare the operating options on the pricing page. When the file and channel are ready, start free — 24-hour trial, no card.
FAQ
How do I change my YouTube stream key?
In YouTube Studio, open Live Control Room, choose Stream, and use Reset in the Stream key section. Then replace the key in the encoder you have authorised to broadcast. Only a channel owner or manager can reset it.
Someone is streaming on my YouTube channel. What should I do first?
Use the available Live Control Room control to end the stream, and stop the sending encoder if you control it. Then rotate the key, update your legitimate encoder and check whether the Google Account or channel access has also changed. Confirm that the public watch page is no longer showing the unwanted feed.
Will resetting the key stop an unauthorized broadcast immediately?
Do not assume that it will. YouTube explains how to reset a key and how to end a stream, but does not promise that resetting alone immediately stops a connection already sending content. Use the end-stream control where available, stop the encoder you control and verify the result.
What if my streaming software signs in directly to YouTube?
A stream-key reset may not apply to software that uses direct YouTube sign-in. YouTube’s troubleshooting guidance directs users to contact the software provider for that case. Secure the associated Google Account as well if you see signs of unauthorised sign-in or channel changes.