# Leaked DigitalOcean API Token? Revoke It, Check Droplets

> DigitalOcean API token exposed on GitHub? Delete it, audit Droplets, Spaces and billing, and lock down your team. Step-by-step guide.

Source: https://leakwatch.net/secrets/digitalocean-token

---

[LeakWatch](/)

[Product](/product)[Live feed](/leaks)[Guides](/secrets)[Blog](/blog)[Free scan](/)

1.  [Home](/)
2.  [Secrets](/secrets)
3.  DigitalOcean API Token

Cloud · Secret guide

# Leaked DigitalOcean API Token: what to do in the first hour

Critical severityDetected onlyLast verified October 2, 2026 · 5 min read

A DigitalOcean API token acts as you on the DigitalOcean API. Depending on its scope, it can create and destroy Droplets, read and write Spaces, change firewalls and DNS, and run up a bill in your name. The classic abuse is quick and boring: a handful of large Droplets spun up to mine cryptocurrency or send spam, found only when the invoice arrives. Delete the token first, then look at what was created.

[Check your GitHub account for leaked secrets — free](/)

Provider

DigitalOcean

Severity

Critical

Impact

Cloud infrastructure access

Checked live by LeakWatch

No

## What a DigitalOcean API token looks like

Tokens start with `do`, a letter for the token type, and a version marker, followed by a long hexadecimal body. LeakWatch recognizes three types:

```text
dop_v1_…XXXX   personal access token (masked)
doo_v1_…XXXX   OAuth access token (masked)
dor_v1_…XXXX   OAuth refresh token (masked)
```

The `dop` token is the one you create yourself in the control panel. The `doo` and `dor` tokens are issued to an application you authorized: the refresh token is the more durable of the two, because it can mint new access tokens until you revoke the app.

Two things are not this secret. Spaces access keys, used for the S3-compatible object storage API, are a separate key pair with their own page in the control panel. An SSH private key for your Droplets is a different credential too: see the SSH private key guide for that.

## How DigitalOcean API tokens get leaked

-   **Terraform and infrastructure code.** A token written into a provider block or a `terraform.tfvars` file, then committed with the rest of the infrastructure repository.
-   **`doctl` configuration.** The CLI stores its token in a local config file, which gets copied into dotfile repositories or baked into container images.
-   **CI/CD variables.** Pipelines that deploy to Droplets or the App Platform often receive the token as an environment variable, and it appears in build logs or a committed workflow file.
-   **Droplet user-data and provisioning scripts.** Cloud-init snippets and shell scripts that call the API from inside a server, pasted into a public gist or tutorial.
-   **Third-party integrations.** Monitoring, backup and autoscaling tools that ask you to paste a token into their settings, and later export or log it.

## What to do in the first hour

1.  **Delete the token.** In the DigitalOcean control panel open *API* → *Tokens*, find the leaked token by its name, and delete it. If you cannot tell which one leaked, delete the likely candidates and create replacements; a few minutes of broken automation is cheaper than a stolen token.
2.  **Create a replacement with the least scope.** Generate a new token with an expiry date, and prefer read-only access if the tool only needs to read. Store it in a secret manager or CI secret, not in the repository.
3.  **Look for resources you did not create.** Check *Droplets*, *Kubernetes*, *Databases*, *Volumes*, *Snapshots* and *Spaces* in every project and region. Unfamiliar large Droplets, new SSH keys on the account, extra firewalls or DNS records under your domains are the signs to look for. Destroy what is not yours.
4.  **Check the account’s security and activity history.** Review the account’s security history in the control panel for new tokens, new SSH keys, new team members and logins you do not recognize. Revoke any application you do not remember authorizing.
5.  **Check billing.** Open the billing section and compare the current usage with your normal level. If you find abuse charges, contact DigitalOcean support early and explain what happened.

Not sure what else leaked? [Run a free scan](/).

6.  **Rotate what the token could reach.** If it could read Droplet metadata, databases or Spaces, assume those credentials may be exposed and rotate them too. Database passwords and Spaces keys are the usual ones.
7.  **Then clean the repository**: remove the value and rewrite history if you want to. See [I accidentally pushed an API key to GitHub](/blog/i-accidentally-pushed-an-api-key-to-github).

[Not sure what else leaked? Run a free scan.](/)

## Revoke it at DigitalOcean

Sign in to the control panel and open *API* in the left-hand menu, then the *Tokens* tab. Personal access tokens are listed by name with their scope and last-used date; delete the exposed one from its row. A token generated by a team member lives in that member’s own account, not the team’s, so ask them to delete it themselves. OAuth tokens (`doo` and `dor`) are not in that list: they come from an application you authorized, so remove the application from your account’s authorized applications. Once deleted, the old value is refused by the API.

## How LeakWatch detects it

The rule is called DigitalOcean Token. It matches the three prefixes above followed by an exact-length hexadecimal body, so truncated or oversized strings are ignored and no surrounding keyword is needed. LeakWatch detects this format but does not check it live: it can tell you the token is exposed, not whether it still works. Assume it does until you have revoked it.

LeakWatch detects this format but does **not** check it live: it can tell you the key is exposed, not whether it still works. Assume it does until you have revoked it.

## FAQ

Does a read-only token matter?

Yes, less than a write token, but it still exposes your whole infrastructure map: server names, IP addresses, firewall rules and project layout. That is useful to an attacker choosing a target, so revoke it all the same.

Will deleting the token delete my Droplets?

No. Deleting a token only removes that credential. Your Droplets, volumes and Spaces are untouched. Only the automation using the token stops until you give it a new one.

My bill jumped but I see no new Droplets. What now?

Look at bandwidth, snapshots, load balancers, managed databases and Spaces storage in every region and project, since cost can come from resources that are easy to overlook. If you still cannot explain it, open a ticket with DigitalOcean support.

## Related

-   [AWS access key](/secrets/aws-access-key)
-   [Azure Client Secret](/secrets/azure-client-secret)
-   [Terraform Cloud API Token](/secrets/terraform-cloud-api-token)
-   [I accidentally pushed an API key to GitHub](/blog/i-accidentally-pushed-an-api-key-to-github)
-   [Which vendors leak most this week](/leaks/trends)
-   [All secret guides](/secrets)

[Get alerted next time a secret leaks — create a free account](/)

LeakWatch is not affiliated with DigitalOcean.

![Gabriel Diyan, founder of LeakWatch](/brand/Photo-Gabriel-Diyan.webp)

Gabriel Diyan (0xCr0c0)

Cybersecurity student, founder of LeakWatch. I built and run the scanner described here — the detection patterns, the false-positive classifier and the provider validators are mine. [More about who I am](/about).

[GitHub](https://github.com/Leakwatch-Scan) · [X](https://x.com/LeakwatchScan) · [LinkedIn](https://www.linkedin.com/in/gabriel-diyan-80a378375) · [GitHub (personal)](https://github.com/crocogab)

LeakWatch

Secrets leak into public commits every minute. This watches the forges for yours. Built and run by [Gabriel Diyan](/about), a cybersecurity student — [why LeakWatch exists](/about).

Scan

-   [Product](/product)
-   [Live feed](/leaks)
-   [Trends](/leaks/trends)
-   [API docs](/docs)
-   [CI/CD](/docs?tab=ci)

Read

-   [Blog](/blog)
-   [Secret guides](/secrets)
-   [Changelog](/changelog)
-   [About](/about)

Verify

-   [Security](/security)
-   [Privacy](/privacy)
-   [Terms](/terms)
-   [Legal](/legal)
-   [Contact](/contact)
-   [Status](https://status.leakwatch.net)

© 2026 LeakWatch

[GitHub](https://github.com/Leakwatch-Scan)[X](https://x.com/LeakwatchScan)
