Leaked secret · Cloud

Your Google Maps key
is exposed in .env?

Don't panic — but move fast. A committed or client-side GOOGLE_MAPS_API_KEY gives anyone your Google Maps Platform billing — every call is charged to you. Rotate it now, then make sure nothing else leaked.

Looks like
GOOGLE_MAPS_API_KEY=AIza…

What an attacker can do with a leaked Google Maps key

Run up your Maps Platform bill with quota theft

Exhaust your daily quota and break maps across your app

Use your key on other sites if it isn't restricted

Fix it right now — rotate your Google Maps key

  1. 1Google Cloud Console → APIs & Services → Credentials → regenerate or delete the leaked key.
  2. 2Add HTTP referrer / IP and API restrictions to the new key, then update GOOGLE_MAPS_API_KEY and redeploy.
  3. 3Check billing and API usage for spikes; set a budget alert.
  4. 4Remove the key from git history (note: Maps keys are often client-side — restrict, don't just hide).

Removing the key from your latest commit isn't enough — it stays recoverable in git history until you scrub it. We do that (and find anything else you missed) in the free audit.

Not sure what else leaked? We'll scan your whole repo — free, in 48 hours.