# Leaked Hugging Face Token? Invalidate It and Audit Repos

> Hugging Face access token (hf_…) exposed on GitHub? Invalidate it, create a scoped token and audit repos. Step-by-step guide.

Source: https://leakwatch.net/secrets/huggingface-access-token

---

[LeakWatch](/)

[Product](/product)[Live feed](/leaks)[Guides](/secrets)[Blog](/blog)[Free scan](/)

1.  [Home](/)
2.  [Secrets](/secrets)
3.  Hugging Face Access Token

AI · Secret guide

# Leaked Hugging Face Access Token: what to do in the first hour

High severityChecked liveLast verified October 2, 2026 · 4 min read

A Hugging Face access token authenticates you to the Hub from scripts, notebooks and CI jobs. What it can do depends on its type: a read token can download your private models and datasets, while a write token can also push to your repositories and Spaces. A leaked write token is a supply-chain risk, because people who download your model or run your Space may receive whatever an attacker pushes.

[Check your GitHub account for leaked secrets — free](/)

Provider

HuggingFace

Severity

High

Impact

SaaS account access and billing

Checked live by LeakWatch

Yes

Revoke at

[Hugging Face](https://huggingface.co/settings/tokens)

## What a Hugging Face access token looks like

Tokens start with `hf_` followed by a string of letters:

```text
hf_…XXXX   Hugging Face access token (masked)
```

The same prefix is used for every token type, so the value does not tell you its permissions. Open the token list in your settings to see its name, when it was last used, and whether it is a **read** token, a **write** token or a **fine-grained** token limited to certain repositories or actions. Fine-grained tokens usually cause the smallest incident, as they are meant to be scoped to what a job needs.

Two lookalikes are not this secret: an **Inference Endpoint URL** is an address, not a credential, and an OpenAI-style `sk-` key belongs to another provider.

## How Hugging Face tokens get leaked

-   **Notebook cells.** `login(token="...")` or `HF_TOKEN` set in a Colab or Jupyter notebook that was shared or committed with its history.
-   **Training scripts and CI.** A script or workflow that pushes models to the Hub with the token hardcoded instead of read from a secret.
-   **Committed `.env` files.** Projects using the transformers or datasets libraries, where `HF_TOKEN` lands in the repository.
-   **Spaces and Docker.** A Dockerfile, `app.py` or a Space’s files containing the token, so anyone who can see the Space repository can read it. Public Spaces make this especially easy to miss.
-   **Cached credentials.** A copy of the Hub’s local token file in a shared home directory, a container image or a backup.

## What to do in the first hour

1.  **Invalidate the exposed token.** In your Hugging Face account, open *Settings* and the *Access Tokens* page, and delete the token (or use the option to invalidate and refresh it, if you want to keep the same token name).
2.  **Create a replacement with the least access you need.** Prefer a fine-grained token limited to specific repositories, and read-only unless the job really pushes. Use separate tokens for separate jobs.
3.  **Deploy the new token** as a secret in your CI, your Space settings or your secret manager, never in the code.
4.  **Audit your repositories.** For each model, dataset and Space the token could write to, open the *Commits* history and check for commits you did not make, changed files (especially model weights, loading scripts and `app.py`) and new branches or pull requests.
5.  **Look for changed visibility and settings.** Check whether a private repository was made public, whether collaborators or webhooks were added, and whether Space secrets were altered.
6.  **Check organizations and private data.** If the token’s account belongs to organizations, review those repositories and members too, since a write token reaches whatever its owner can write to. If it could read private datasets, think about whether personal or licensed data was in them, and who needs to be told.

Not sure what else leaked? [Run a free scan](/).

7.  **Then clean the repository**: remove the value and rewrite history if you want to. See [I accidentally pushed an API key to GitHub](/blog/i-accidentally-pushed-an-api-key-to-github).

[Not sure what else leaked? Run a free scan.](/)

## Revoke it at Hugging Face

Sign in and open [huggingface.co/settings/tokens](https://huggingface.co/settings/tokens). Find the token by name, and delete it or invalidate and refresh it. The old value stops working immediately. If you cannot tell which token leaked, delete the ones you do not recognize, then replace the rest.

## How LeakWatch detects it

The rule is called HuggingFace Access Token. It matches `hf_` followed by exactly 34 letters, and expects the token to end at a quote, whitespace, a semicolon or the end of the line, so `hf_` strings that are part of a longer word are not reported. **This type is checked live**: LeakWatch can check whether a detected token is still active with a read-only request that asks the Hub who the token belongs to. It never reads your repositories or data and never spends credits.

LeakWatch can check whether a detected key is still active with a read-only request to HuggingFace. It never reads your data or spends your credits.

## FAQ

Is a read-only token safe to leave exposed?

No. It still downloads private models and datasets, and your code may reveal what is in them. Rotate it. The damage is smaller than with a write token, but the exposure is real.

Could someone have changed my model after I rotated the token?

Only if they pushed before it was invalidated. Check commit history for the period since the exposure, and treat any suspicious change as a reason to roll back and to notify people who downloaded it.

Can I stop this happening to my Space?

Keep the token in the Space’s secrets settings and read it from the environment. Files in the Space repository are visible to anyone who can view the Space.

## Related

-   [OpenAI API key](/secrets/openai-api-key)
-   [Anthropic (Claude) API Key](/secrets/anthropic-api-key)
-   [DeepSeek API Key](/secrets/deepseek-api-key)
-   [I accidentally pushed an API key to GitHub](/blog/i-accidentally-pushed-an-api-key-to-github)
-   [Which vendors leak most this week](/leaks/trends)
-   [All secret guides](/secrets)

[Get alerted next time a secret leaks — create a free account](/)

LeakWatch is not affiliated with HuggingFace.

![Gabriel Diyan, founder of LeakWatch](/brand/Photo-Gabriel-Diyan.webp)

Gabriel Diyan (0xCr0c0)

Cybersecurity student, founder of LeakWatch. I built and run the scanner described here — the detection patterns, the false-positive classifier and the provider validators are mine. [More about who I am](/about).

[GitHub](https://github.com/Leakwatch-Scan) · [X](https://x.com/LeakwatchScan) · [LinkedIn](https://www.linkedin.com/in/gabriel-diyan-80a378375) · [GitHub (personal)](https://github.com/crocogab)

LeakWatch

Secrets leak into public commits every minute. This watches the forges for yours. Built and run by [Gabriel Diyan](/about), a cybersecurity student — [why LeakWatch exists](/about).

Scan

-   [Product](/product)
-   [Live feed](/leaks)
-   [Trends](/leaks/trends)
-   [API docs](/docs)
-   [CI/CD](/docs?tab=ci)

Read

-   [Blog](/blog)
-   [Secret guides](/secrets)
-   [Changelog](/changelog)
-   [About](/about)

Verify

-   [Security](/security)
-   [Privacy](/privacy)
-   [Terms](/terms)
-   [Legal](/legal)
-   [Contact](/contact)
-   [Status](https://status.leakwatch.net)

© 2026 LeakWatch

[GitHub](https://github.com/Leakwatch-Scan)[X](https://x.com/LeakwatchScan)
