Secrets & Token Exposure

    Keys Leak Faster Than You Think

    Protect .env files, API keys, GitHub tokens, SSH keys, cloud credentials and debug logs.

    Developer & Technical SecurityDevelopersIT & help desk

    Illustrative scenario

    How It Looks in Real Life

    A developer commits a .env file to a public repo, notices, and deletes it in the next commit. The cloud key remains in history and is used within hours.

    Understand it

    How the Attack Works

    Automated scanners search public code, logs and paste sites for credentials. Deleting a file does not remove it from history or from copies already taken.

    Red flags

    Warning Signs

    • .env files or credential files not covered by .gitignore.
    • Tokens printed in debug logs, screenshots or support tickets.
    • Long-lived tokens with broad permissions.

    Safer habits

    What to Do Instead

    • 1Keep secrets in a secret manager or CI secret store, never in code.
    • 2Enable secret scanning and push protection on repositories.
    • 3Use short-lived, least-privilege tokens and rotate them regularly.

    Response playbook

    Already Interacted?

    For work accounts and devices, report promptly through your organisation’s IT or security process first. Never share passwords, codes or tokens in a report.

    If you: exposed a token, key or secret
    1. 1Revoke or rotate the exposed secret at the provider first; deleting the commit or message is not enough.
    2. 2Report it to the security team with where and when it was exposed. Never paste the secret itself into the report.
    3. 3Review provider logs for use of the key after the exposure time.

    Knowledge Check

    What Would You Do?

    You pushed an API key to a public repo ten minutes ago. What comes first?

    Fictional example for learning. Not a test score or certification.

    Sources

    Content reviewed by WazuGuardix on 5 October 2026. Summaries are in our own words.

    All Awareness Guides

    Make Safe Habits Part of Your Culture

    Plain-language awareness sessions for everyday staff, developers and business teams.

    Email Us