A Razorpay API key is a pair: a Key ID and a Key Secret. Together they authenticate server-side calls to the Razorpay API, which can create orders, read payments, and depending on your account, issue refunds. The Key ID alone is close to public, since it also goes into your checkout page. The Key Secret is the part that must stay private, and the part to rotate if it has been exposed.
Check your GitHub account for leaked secrets — free
- Provider
- Razorpay
- Severity
- Critical
- Impact
- Payments and customer data
- Checked live by LeakWatch
- Yes
- Revoke at
- Razorpay
What a Razorpay API key looks like
The Key ID starts with rzp_, then a mode (live or test), then a short identifier:
rzp_live_…XXXX Key ID (masked)
rzp_test_…XXXX Key ID, test mode (masked)
The Key Secret has no fixed prefix; it is a separate random string shown once when the key pair is generated. That is why the two halves are often leaked together in a config file, as RAZORPAY_KEY_ID and RAZORPAY_KEY_SECRET.
A rzp_test_ key only touches test mode, where no real money moves, but it still belongs in a secret store and is worth rotating. A rzp_live_ key pair is the serious case. Do not confuse these with the webhook secret you set in the dashboard to verify event signatures, which is a different value with its own settings. If you also take cards through another provider, see the Stripe secret key guide.
How Razorpay keys get leaked
- Config committed with the app. A
.env,settings.pyorconfig.jsholdingRAZORPAY_KEY_SECRETpushed with the rest of a checkout integration. - Tutorial code. Sample projects that hardcode both halves so the example runs, then get reused in production.
- Mobile and front-end bundles. Putting the secret into a React, Flutter or Android app because the Key ID is needed there; only the Key ID belongs on the client.
- Server logs and error reports. A failed API call logged with its Basic auth header or the full client configuration.
- Shared accounts. The key pair pasted into a chat or ticket to help a freelancer or agency debug a payment problem.
What to do in the first hour
- Regenerate the key pair in the dashboard. In the Razorpay Dashboard go to Account & Settings and open the API Keys page, for the right mode (live or test), then regenerate the key. The new Key Secret is shown only once, so save it straight into your secret manager.
- Check whether the old secret keeps working for a while. Some dashboard flows keep the previous key valid for a transition period. Do not rely on that: deploy the new pair immediately and confirm the old one is rejected.
- Deploy the new pair to every service that creates orders or verifies payments, including any background workers.
- Review payments and refunds. In the dashboard, look at Transactions and Refunds for the period since the exposure. Look for refunds you did not issue, orders you did not create and unusual amounts or patterns.
- Check settlements and payouts. Confirm that your bank account details and settlement settings are unchanged, and review any payout or fund-account features you have enabled.
- Review team access and webhooks. Check that your team members and the webhook URLs configured in the dashboard are all ones you recognize.
Not sure what else leaked? Run a free scan.
- Then clean the repository: remove the values and rewrite history if you want to. See I accidentally pushed an API key to GitHub.
Revoke it at Razorpay
Sign in to the Razorpay Dashboard keys page, choose the mode that matches the leaked key (live or test), and regenerate the key. A regenerated pair replaces the old one, so update your servers at the same moment. If the account has several users, only those with the right role can see this page.
How LeakWatch detects it
The rule is called Razorpay Key. It matches the rzp_ prefix, a short mode segment such as live or test, and an underscore followed by the identifier. That is the Key ID, the public half, so a match alone is not a leaked secret. This type is checked live when the Key Secret is found near the Key ID: LeakWatch can then check whether the pair is still active with a read-only request. It does not create orders, change anything or move money. If only the Key ID is in the file, the check cannot run.
LeakWatch can check whether a detected key is still active with a read-only request to Razorpay. It never reads your data or spends your credits.
FAQ
The Key ID is in my checkout page. Is that already a leak?
No. The Key ID is meant to be sent to the browser so Razorpay Checkout can open. The leak is the Key Secret, or both together in a place anyone can read.
Can someone take money from my account with the Key Secret?
They cannot withdraw to their own bank account through the key alone. What they can do depends on the key’s permissions: read your payment data, create orders, and potentially trigger refunds. That is why the review of refunds and settlements matters.
Do I need to rotate a test-mode key?
It holds no real funds, but if the same file also had a live key, rotate both. Treat the whole file as exposed.