Leaked secret · Payments

Your Stripe key
is exposed in .env?

Don't panic — but move fast. A committed or client-side STRIPE_SECRET_KEY gives anyone full access to your Stripe account — charges, refunds, customers and payouts. Rotate it now, then make sure nothing else leaked.

Looks like
STRIPE_SECRET_KEY=sk_live_…

What an attacker can do with a leaked Stripe key

Create charges and issue refunds to attacker-controlled accounts

Read every customer, card token, invoice and payout record

Change payout bank details and drain settled funds

Fix it right now — rotate your Stripe key

  1. 1Stripe Dashboard → Developers → API keys → Roll the live secret key (this instantly revokes the old one).
  2. 2Update STRIPE_SECRET_KEY in your host's env vars and redeploy.
  3. 3Check Developers → Logs and your Payments for any unfamiliar charges or refunds.
  4. 4Remove the key from git history (it stays recoverable in old commits).

Removing the key from your latest commit isn't enough — it stays recoverable in git history until you scrub it. We do that (and find anything else you missed) in the free audit.

Not sure what else leaked? We'll scan your whole repo — free, in 48 hours.