So, even if you added a new commit to remove it from master, the commit remains in master's history.
Note that cbe85dc is not a branch, but a commit. It is part of master's history, and if you have a public GitHub repository, then anyone can see it even if you remove the API key in a later commit.
I would proceed by using interactive-rebase to edit this commit to remove the api key.
At the same time you can drop the commit where you remove the api key (is it won't make sense anymore to remove the API key when it's already removed).
Warning: This involves rewriting history, and requires a force-push to correct on GitHub. This is discouraged if there are several contributers on the repository, or you have it cloned to multiple computers, as everyone would need to "hard-reset" or delete and re-clone their local repository after you force-push to master.
If you determine that is OK, here is how I would proceed:
git rebase -i cbe85dc~1
This will open up interactive-rebase in your editor, which looks something like this
pick cbe85dc Some message
pick abcdef Another message
pick defabc Yet another message
# Commands:
# p, pick <commit> = use commit
# r, reword <commit> = use commit, but edit the commit message
# e, edit <commit> = use commit, but stop for amending
# d, drop <commit> = remove commit
...
Now, change pick to edit for cbe85dc.
You should also see the commit where you later removed the API key, for this commit you can change pick to drop to remove the commit.
Save and exit your editor, and you should be in a "rebase" state for editing cbe85dc.
Now remove the API key, and amend the commit (update the file, git add the file, then git commit --amend).
Then git rebase --continue to replay every later commit on top of your change.
Now, if everything has worked out, you can force-push your changes to github with git push origin master -f
At this point commit cbe85dc is no longer a part of master's history, and will be removed by garbage collection after some time. The edited commit gets a new hash. You should still consider the API key compromised and get a new one.
Alternatively you could use the filter-branch command, but this also rewrites the history, and requires force-push etc. Personally, I would use interactive-rebase, since that is what I'm used to.
For more information, see here from the Git book