Leaked secret · Payments
Your Stripe key
is exposed in .env?
Don't panic — but move fast. A committed or client-side STRIPE_SECRET_KEY gives anyone full access to your Stripe account — charges, refunds, customers and payouts. Rotate it now, then make sure nothing else leaked.
Looks like
STRIPE_SECRET_KEY=sk_live_…
What an attacker can do with a leaked Stripe key
⚠
Create charges and issue refunds to attacker-controlled accounts
⚠
Read every customer, card token, invoice and payout record
⚠
Change payout bank details and drain settled funds
Fix it right now — rotate your Stripe key
- 1Stripe Dashboard → Developers → API keys → Roll the live secret key (this instantly revokes the old one).
- 2Update STRIPE_SECRET_KEY in your host's env vars and redeploy.
- 3Check Developers → Logs and your Payments for any unfamiliar charges or refunds.
- 4Remove the key from git history (it stays recoverable in old commits).
Removing the key from your latest commit isn't enough — it stays recoverable in git history until you scrub it. We do that (and find anything else you missed) in the free audit.
While you're at it
Other keys people leak
Not sure what else leaked? We'll scan your whole repo — free, in 48 hours.