Leaked secret · AI

Your Anthropic (Claude) key
is exposed in .env?

Don't panic — but move fast. A committed or client-side ANTHROPIC_API_KEY gives anyone your Anthropic account's API — Claude usage billed to you. Rotate it now, then make sure nothing else leaked.

Looks like
ANTHROPIC_API_KEY=sk-ant-…

What an attacker can do with a leaked Anthropic (Claude) key

Burn through your Claude credits and run up the bill

Hit your rate limits and take your AI features offline

Access workspace usage tied to the key

Fix it right now — rotate your Anthropic (Claude) key

  1. 1Anthropic Console → Settings → API keys → revoke the leaked key and generate a new one.
  2. 2Update ANTHROPIC_API_KEY in your server env and redeploy.
  3. 3Set a monthly spend limit in the Console as a guardrail.
  4. 4Strip the key from git history and client code.

Removing the key from your latest commit isn't enough — it stays recoverable in git history until you scrub it. We do that (and find anything else you missed) in the free audit.

Not sure what else leaked? We'll scan your whole repo — free, in 48 hours.