Hardcoded API keys and cryptographic secrets¶
An API key, signing secret or private encryption key embedded in source can spread through repositories, build logs, packages and backups. The impact depends on the permissions and purpose of the secret. Public verification keys and intentionally publishable identifiers are not equivalent to private credentials.
Load a provisioned secret¶
This Node.js example concerns a server-side API credential. The string in the unsafe example is an intentionally nonfunctional placeholder, not a real key.
Unsafe pattern: ship the credential with the code.
const apiKey = 'DEMO_NOT_A_REAL_SECRET';
Safer configuration pattern: require deployment-provided material.
const apiKey = process.env.SERVICE_API_KEY;
if (typeof apiKey !== 'string' || apiKey.trim().length === 0) {
throw new Error('SERVICE_API_KEY must be provisioned');
}
The application fails instead of silently using a shared fallback key. Provision the value through an access-controlled secret-management mechanism. An environment variable is an injection interface, not an encrypted vault: restrict process access, diagnostics and deployment permissions, and never copy the value to a browser bundle or logs. OWASP's secrets-management guidance covers lifecycle and access controls.
For signing and encryption, changing a key may invalidate tokens or make existing data unreadable. Plan versioning, key identification and a controlled migration before rotation. API credentials need permissions limited to the application's actual operations.
Respond to exposure¶
If a real secret entered a repository or public artifact, treat removal from the latest file as only one step. Revoke or rotate it through its provider, inspect relevant access records, update dependent applications and verify the old value no longer grants access. Coordinate any history cleanup without assuming it erases every copy.
Check the fix¶
In a test process containing only fictional values, verify startup succeeds when the required value is provisioned and fails when it is absent or empty. Assert that error output contains the variable name but never its value. No provider login or real credential is required.
Continue with hardcoded passwords, sensitive logging and dependency supply-chain security. Confirm a suspected secret's role before classifying a public identifier as a vulnerability.