Leaked secret · Messaging
Your Twilio key
is exposed in .env?
Don't panic — but move fast. A committed or client-side TWILIO_AUTH_TOKEN gives anyone your Twilio account — SMS, voice and number management. Rotate it now, then make sure nothing else leaked.
Looks like
TWILIO_AUTH_TOKEN=AC… (SID) + auth token
What an attacker can do with a leaked Twilio key
⚠
Send SMS and place calls on your account (toll-fraud bills add up fast)
⚠
Read your message and call logs, including customer numbers
⚠
Buy or release phone numbers tied to your account
Fix it right now — rotate your Twilio key
- 1Twilio Console → Account → API keys & tokens → rotate the Auth Token (promote the secondary, then regenerate).
- 2Update TWILIO_AUTH_TOKEN in your env and redeploy.
- 3Review Monitor → Logs and your usage for unfamiliar messages or calls.
- 4Scrub the token from git history.
Removing the key from your latest commit isn't enough — it stays recoverable in git history until you scrub it. We do that (and find anything else you missed) in the free audit.
While you're at it
Other keys people leak
Not sure what else leaked? We'll scan your whole repo — free, in 48 hours.