Leaked secret · Payments

Your Midtrans key
is exposed in .env?

Don't panic — but move fast. A committed or client-side MIDTRANS_SERVER_KEY gives anyone your Midtrans API — transactions and refunds. Rotate it now, then make sure nothing else leaked.

Looks like
MIDTRANS_SERVER_KEY=Mid-server-…

What an attacker can do with a leaked Midtrans key

Create and refund transactions through the Midtrans API

Read transaction status and customer payment details

Abuse payment notifications tied to your merchant account

Fix it right now — rotate your Midtrans key

  1. 1Midtrans Dashboard → Settings → Access Keys → regenerate the Server Key.
  2. 2Update MIDTRANS_SERVER_KEY in your server env and redeploy.
  3. 3Review your transaction history for anything unfamiliar.
  4. 4Remove the key from git history and any client-side code.

Removing the key from your latest commit isn't enough — it stays recoverable in git history until you scrub it. We do that (and find anything else you missed) in the free audit.

Not sure what else leaked? We'll scan your whole repo — free, in 48 hours.