Lazo Lab Sign up

Web Security / Building secure apps

Lesson 23 of 27

Secrets management

API keys and passwords in code end up on GitHub. Keep them in environment variables or a secrets manager, and rotate any that leak.

Key points

  • Add .env to .gitignore
  • Rotate leaked keys immediately
  • GitHub secret scanning helps
Watch a video on thisOpens YouTube search results for “Secrets management” in a new tab

Quiz · +10 XP

You accidentally pushed an API key to GitHub. What must you do?

Log in to save progress and earn XP.