AI · Secret guide

Leaked Hugging Face Access Token: what to do in the first hour

High severityChecked liveLast verified · 4 min read

A Hugging Face access token authenticates you to the Hub from scripts, notebooks and CI jobs. What it can do depends on its type: a read token can download your private models and datasets, while a write token can also push to your repositories and Spaces. A leaked write token is a supply-chain risk, because people who download your model or run your Space may receive whatever an attacker pushes.

Check your GitHub account for leaked secrets — free

Provider
HuggingFace
Severity
High
Impact
SaaS account access and billing
Checked live by LeakWatch
Yes
Revoke at
Hugging Face

What a Hugging Face access token looks like

Tokens start with hf_ followed by a string of letters:

hf_…XXXX   Hugging Face access token (masked)

The same prefix is used for every token type, so the value does not tell you its permissions. Open the token list in your settings to see its name, when it was last used, and whether it is a read token, a write token or a fine-grained token limited to certain repositories or actions. Fine-grained tokens usually cause the smallest incident, as they are meant to be scoped to what a job needs.

Two lookalikes are not this secret: an Inference Endpoint URL is an address, not a credential, and an OpenAI-style sk- key belongs to another provider.

How Hugging Face tokens get leaked

  • Notebook cells. login(token="...") or HF_TOKEN set in a Colab or Jupyter notebook that was shared or committed with its history.
  • Training scripts and CI. A script or workflow that pushes models to the Hub with the token hardcoded instead of read from a secret.
  • Committed .env files. Projects using the transformers or datasets libraries, where HF_TOKEN lands in the repository.
  • Spaces and Docker. A Dockerfile, app.py or a Space’s files containing the token, so anyone who can see the Space repository can read it. Public Spaces make this especially easy to miss.
  • Cached credentials. A copy of the Hub’s local token file in a shared home directory, a container image or a backup.

What to do in the first hour

  1. Invalidate the exposed token. In your Hugging Face account, open Settings and the Access Tokens page, and delete the token (or use the option to invalidate and refresh it, if you want to keep the same token name).
  2. Create a replacement with the least access you need. Prefer a fine-grained token limited to specific repositories, and read-only unless the job really pushes. Use separate tokens for separate jobs.
  3. Deploy the new token as a secret in your CI, your Space settings or your secret manager, never in the code.
  4. Audit your repositories. For each model, dataset and Space the token could write to, open the Commits history and check for commits you did not make, changed files (especially model weights, loading scripts and app.py) and new branches or pull requests.
  5. Look for changed visibility and settings. Check whether a private repository was made public, whether collaborators or webhooks were added, and whether Space secrets were altered.
  6. Check organizations and private data. If the token’s account belongs to organizations, review those repositories and members too, since a write token reaches whatever its owner can write to. If it could read private datasets, think about whether personal or licensed data was in them, and who needs to be told.

Not sure what else leaked? Run a free scan.

  1. Then clean the repository: remove the value and rewrite history if you want to. See I accidentally pushed an API key to GitHub.

Not sure what else leaked? Run a free scan.

Revoke it at Hugging Face

Sign in and open huggingface.co/settings/tokens. Find the token by name, and delete it or invalidate and refresh it. The old value stops working immediately. If you cannot tell which token leaked, delete the ones you do not recognize, then replace the rest.

How LeakWatch detects it

The rule is called HuggingFace Access Token. It matches hf_ followed by exactly 34 letters, and expects the token to end at a quote, whitespace, a semicolon or the end of the line, so hf_ strings that are part of a longer word are not reported. This type is checked live: LeakWatch can check whether a detected token is still active with a read-only request that asks the Hub who the token belongs to. It never reads your repositories or data and never spends credits.

LeakWatch can check whether a detected key is still active with a read-only request to HuggingFace. It never reads your data or spends your credits.

FAQ

Is a read-only token safe to leave exposed?

No. It still downloads private models and datasets, and your code may reveal what is in them. Rotate it. The damage is smaller than with a write token, but the exposure is real.

Could someone have changed my model after I rotated the token?

Only if they pushed before it was invalidated. Check commit history for the period since the exposure, and treat any suspicious change as a reason to roll back and to notify people who downloaded it.

Can I stop this happening to my Space?

Keep the token in the Space’s secrets settings and read it from the environment. Files in the Space repository are visible to anyone who can view the Space.

Get alerted next time a secret leaks — create a free account

LeakWatch is not affiliated with HuggingFace.