I leaked an API key. What do I do?

Also searched as: API key exposed GitHub · API key leaked · OpenAI API key leaked · Stripe API key leaked · Gemini API key leaked on GitHub · API key leak check

Updated 3 October 2026

Short answer

Revoke the key and create a new one, now, before you do anything else. Deleting it from your code doesn't help: it's still in the repository's history and in every copy anyone made. Once the old key is revoked, it's useless to whoever has it. Then check the provider's usage and billing for activity that wasn't yours, and find out how it leaked so it doesn't happen again.

What's the problem

A key for a paid service (an AI model, payments, email, maps, cloud storage) has ended up somewhere public: a public repository, your website's code, a screenshot, a log. Whoever finds it can use the service as you, on your bill, and sometimes read your data.

Why it happens

  • It was committed to the code. Put in a file "just for now", then pushed. Git keeps every version, so removing it later leaves it in the history.
  • It was put in the frontend. Anything in browser code is downloaded by every visitor. Build tools such as Vite bundle certain settings straight into that code.
  • It was shared to get help. Pasted into a forum post, a chat, or a screenshot of the code.
  • Nothing checked. Secret scanning tools catch keys in repositories, but only if they're switched on.

How to fix it

  1. Revoke or rotate the key at the provider. Create a new one. This is the step that actually stops the damage.
  2. Check usage and billing for the time it was exposed. Contact the provider about charges that weren't yours, and set spending limits if they offer them.
  3. Put the new key where it belongs. In your server's environment variables, never in frontend code. Redeploy.
  4. Find every place the old one leaked. The repository history, the built frontend, logs, other branches, other repositories.
  5. Move any secret out of the browser. If the frontend needs a paid service, route the request through your own server, which holds the key.
  6. Turn on secret scanning in your repository so the next one is caught.
  7. If the key gave access to customer data, you may have a data breach to assess. See do I have to report a data breach.

When to call Preventionlabs

Rotate the key now. Don't wait for anyone, including us. Call us when the leak was a symptom: secrets scattered through the frontend, no server-side layer to hold them, nobody sure what else is exposed. Data exposure is on the MVP-level protection checklist in every resurrection, alongside authentication, access control and the rest.

Submit your project for a free assessment

Free assessment. $10,000 AUD flat to get it live, only if we take it on and you go ahead.

Sources

  1. GitHub: Removing sensitive data from a repositoryofficial docsIt is important to note that if the sensitive data you need to remove is a secret (e.g. password/token/credential), as is often the case, then as a first step you need to revoke and/or rotate that secret.
  2. GitHub: Removing sensitive data from a repositoryofficial docsOnce the secret is revoked or rotated, it can no longer be used for access, and that may be sufficient to solve your problem.
  3. GitHub: Secret scanningofficial docsSecret scanning scans your entire Git history on all branches of your repository for hardcoded credentials, including API keys, passwords, tokens, and other known secret types.
  4. Vite: Env Variables and Modes: Protecting secretsbuild tool docsVITE_* variables should not contain sensitive information such as API keys.
← All of Is it safe?