Leaked secret · Email

Your SendGrid key
is exposed in .env?

Don't panic — but move fast. A committed or client-side SENDGRID_API_KEY gives anyone your SendGrid account — sending email as your domain. Rotate it now, then make sure nothing else leaked.

Looks like
SENDGRID_API_KEY=SG.…

What an attacker can do with a leaked SendGrid key

Send phishing and spam from your verified domain

Destroy your sender reputation and deliverability

Read contacts, templates and email activity

Fix it right now — rotate your SendGrid key

  1. 1SendGrid → Settings → API Keys → delete the leaked key and create a new one.
  2. 2Update SENDGRID_API_KEY in your env and redeploy.
  3. 3Check Activity Feed for emails you didn't send and review domain auth.
  4. 4Remove the key from git history.

Removing the key from your latest commit isn't enough — it stays recoverable in git history until you scrub it. We do that (and find anything else you missed) in the free audit.

Not sure what else leaked? We'll scan your whole repo — free, in 48 hours.