Leaked secret · Payments
Your Razorpay key
is exposed in .env?
Don't panic — but move fast. A committed or client-side RAZORPAY_KEY_SECRET gives anyone your Razorpay API — payments, refunds and transaction data. Rotate it now, then make sure nothing else leaked.
Looks like
RAZORPAY_KEY_SECRET=rzp_live_… + key secret
What an attacker can do with a leaked Razorpay key
⚠
Create orders and trigger refunds via the API
⚠
Read transactions, settlements and customer details
⚠
Abuse payment links and subscriptions tied to your account
Fix it right now — rotate your Razorpay key
- 1Razorpay Dashboard → Settings → API Keys → Regenerate Live Keys (revokes the old pair).
- 2Update RAZORPAY_KEY_ID and RAZORPAY_KEY_SECRET in your env and redeploy.
- 3Review Transactions and Settlements for anything you don't recognise.
- 4Scrub the secret from git history and any client-side bundle.
Removing the key from your latest commit isn't enough — it stays recoverable in git history until you scrub it. We do that (and find anything else you missed) in the free audit.
While you're at it
Other keys people leak
Not sure what else leaked? We'll scan your whole repo — free, in 48 hours.