Secrets

Rotate a leaked secret, then clean up

A key in your bundle or your git history is live until you rotate it. The order that closes the hole first and tidies up second.

7 min readChecks: SE-1, SE-2, SE-3, SE-4

Deleting a secret from your code does not un-leak it. It is still in your git history, in any copy of the bundle someone saved, and in the logs of whoever found it. The only fix that closes the hole is to make the old secret stop working.

Rotate first, clean history second. Cleaning history while the secret still works fixes nothing.

The order

  1. Rotate: create a new key in the provider’s dashboard and revoke the old one.
  2. Update the new key in your hosting environment variables, never in code.
  3. Redeploy and confirm the app works with the new key.
  4. Check the provider’s usage or billing page for anything you did not do while the key was exposed.
  5. Only then remove the secret from the code and, if the repository is public or shared, from the history.

Stop it happening again

Paste into your AI coding tool
Search the whole repository for API keys, tokens, passwords and connection strings written as literals. Move each one to an environment variable, read it on the server only, and make sure no server-only secret is imported into code that runs in the browser. Make sure .gitignore covers every .env file and that no env file is tracked. List what you moved.

Turn on secret scanning and push protection in your repository host so the next one is caught before it lands.

All 77 checks, ranked by severity

The free checklist has every check in this guide and the rest, each with a fix prompt and a deadline.

Get the free checklist