Leaked secret · Payments
Your iyzico key
is exposed in .env?
Don't panic — but move fast. A committed or client-side IYZICO_SECRET_KEY gives anyone your iyzico API — payments and transaction data. Rotate it now, then make sure nothing else leaked.
Looks like
IYZICO_SECRET_KEY=sandbox-… / live secret key
What an attacker can do with a leaked iyzico key
⚠
Initiate and refund payments via the iyzico API
⚠
Read transaction and customer payment records
⚠
Abuse subscription and payment endpoints on your account
Fix it right now — rotate your iyzico key
- 1iyzico Merchant Panel → Settings → API Keys → regenerate your API and secret keys.
- 2Update IYZICO_API_KEY and IYZICO_SECRET_KEY in your server env and redeploy.
- 3Review your transactions for unfamiliar activity.
- 4Scrub the secret from git history and client bundles.
Removing the key from your latest commit isn't enough — it stays recoverable in git history until you scrub it. We do that (and find anything else you missed) in the free audit.
While you're at it
Other keys people leak
Not sure what else leaked? We'll scan your whole repo — free, in 48 hours.