# Leaked Razorpay Key? Regenerate It and Review Payments

> Razorpay API key (rzp_live_) exposed on GitHub? Regenerate keys in the dashboard, review payments and refunds. Step-by-step guide.

Source: https://leakwatch.net/secrets/razorpay-key

---

[LeakWatch](/)

[Product](/product)[Live feed](/leaks)[Guides](/secrets)[Blog](/blog)[Free scan](/)

1.  [Home](/)
2.  [Secrets](/secrets)
3.  Razorpay API Key

Payments · Secret guide

# Leaked Razorpay API Key: what to do in the first hour

Critical severityChecked liveLast verified October 2, 2026 · 4 min read

A Razorpay API key is a pair: a Key ID and a Key Secret. Together they authenticate server-side calls to the Razorpay API, which can create orders, read payments, and depending on your account, issue refunds. The Key ID alone is close to public, since it also goes into your checkout page. The Key Secret is the part that must stay private, and the part to rotate if it has been exposed.

[Check your GitHub account for leaked secrets — free](/)

Provider

Razorpay

Severity

Critical

Impact

Payments and customer data

Checked live by LeakWatch

Yes

Revoke at

[Razorpay](https://dashboard.razorpay.com/#/app/keys)

## What a Razorpay API key looks like

The Key ID starts with `rzp_`, then a mode (`live` or `test`), then a short identifier:

```text
rzp_live_…XXXX   Key ID (masked)
rzp_test_…XXXX   Key ID, test mode (masked)
```

The Key Secret has no fixed prefix; it is a separate random string shown once when the key pair is generated. That is why the two halves are often leaked together in a config file, as `RAZORPAY_KEY_ID` and `RAZORPAY_KEY_SECRET`.

A `rzp_test_` key only touches test mode, where no real money moves, but it still belongs in a secret store and is worth rotating. A `rzp_live_` key pair is the serious case. Do not confuse these with the **webhook secret** you set in the dashboard to verify event signatures, which is a different value with its own settings. If you also take cards through another provider, see the [Stripe secret key](/secrets/stripe-secret-key) guide.

## How Razorpay keys get leaked

-   **Config committed with the app.** A `.env`, `settings.py` or `config.js` holding `RAZORPAY_KEY_SECRET` pushed with the rest of a checkout integration.
-   **Tutorial code.** Sample projects that hardcode both halves so the example runs, then get reused in production.
-   **Mobile and front-end bundles.** Putting the secret into a React, Flutter or Android app because the Key ID is needed there; only the Key ID belongs on the client.
-   **Server logs and error reports.** A failed API call logged with its Basic auth header or the full client configuration.
-   **Shared accounts.** The key pair pasted into a chat or ticket to help a freelancer or agency debug a payment problem.

## What to do in the first hour

1.  **Regenerate the key pair in the dashboard.** In the Razorpay Dashboard go to *Account & Settings* and open the *API Keys* page, for the right mode (live or test), then regenerate the key. The new Key Secret is shown only once, so save it straight into your secret manager.
2.  **Check whether the old secret keeps working for a while.** Some dashboard flows keep the previous key valid for a transition period. Do not rely on that: deploy the new pair immediately and confirm the old one is rejected.
3.  **Deploy the new pair** to every service that creates orders or verifies payments, including any background workers.
4.  **Review payments and refunds.** In the dashboard, look at *Transactions* and *Refunds* for the period since the exposure. Look for refunds you did not issue, orders you did not create and unusual amounts or patterns.
5.  **Check settlements and payouts.** Confirm that your bank account details and settlement settings are unchanged, and review any payout or fund-account features you have enabled.
6.  **Review team access and webhooks.** Check that your team members and the webhook URLs configured in the dashboard are all ones you recognize.

Not sure what else leaked? [Run a free scan](/).

7.  **Then clean the repository**: remove the values and rewrite history if you want to. See [I accidentally pushed an API key to GitHub](/blog/i-accidentally-pushed-an-api-key-to-github).

[Not sure what else leaked? Run a free scan.](/)

## Revoke it at Razorpay

Sign in to the [Razorpay Dashboard keys page](https://dashboard.razorpay.com/#/app/keys), choose the mode that matches the leaked key (live or test), and regenerate the key. A regenerated pair replaces the old one, so update your servers at the same moment. If the account has several users, only those with the right role can see this page.

## How LeakWatch detects it

The rule is called Razorpay Key. It matches the `rzp_` prefix, a short mode segment such as `live` or `test`, and an underscore followed by the identifier. That is the Key ID, the public half, so a match alone is not a leaked secret. **This type is checked live** when the Key Secret is found near the Key ID: LeakWatch can then check whether the pair is still active with a read-only request. It does not create orders, change anything or move money. If only the Key ID is in the file, the check cannot run.

LeakWatch can check whether a detected key is still active with a read-only request to Razorpay. It never reads your data or spends your credits.

## FAQ

The Key ID is in my checkout page. Is that already a leak?

No. The Key ID is meant to be sent to the browser so Razorpay Checkout can open. The leak is the Key Secret, or both together in a place anyone can read.

Can someone take money from my account with the Key Secret?

They cannot withdraw to their own bank account through the key alone. What they can do depends on the key’s permissions: read your payment data, create orders, and potentially trigger refunds. That is why the review of refunds and settlements matters.

Do I need to rotate a test-mode key?

It holds no real funds, but if the same file also had a live key, rotate both. Treat the whole file as exposed.

## Related

-   [Stripe secret key](/secrets/stripe-secret-key)
-   [Shopify Access Token](/secrets/shopify-access-token)
-   [AWS access key](/secrets/aws-access-key)
-   [I accidentally pushed an API key to GitHub](/blog/i-accidentally-pushed-an-api-key-to-github)
-   [Which vendors leak most this week](/leaks/trends)
-   [All secret guides](/secrets)

[Get alerted next time a secret leaks — create a free account](/)

LeakWatch is not affiliated with Razorpay.

![Gabriel Diyan, founder of LeakWatch](/brand/Photo-Gabriel-Diyan.webp)

Gabriel Diyan (0xCr0c0)

Cybersecurity student, founder of LeakWatch. I built and run the scanner described here — the detection patterns, the false-positive classifier and the provider validators are mine. [More about who I am](/about).

[GitHub](https://github.com/Leakwatch-Scan) · [X](https://x.com/LeakwatchScan) · [LinkedIn](https://www.linkedin.com/in/gabriel-diyan-80a378375) · [GitHub (personal)](https://github.com/crocogab)

LeakWatch

Secrets leak into public commits every minute. This watches the forges for yours. Built and run by [Gabriel Diyan](/about), a cybersecurity student — [why LeakWatch exists](/about).

Scan

-   [Product](/product)
-   [Live feed](/leaks)
-   [Trends](/leaks/trends)
-   [API docs](/docs)
-   [CI/CD](/docs?tab=ci)

Read

-   [Blog](/blog)
-   [Secret guides](/secrets)
-   [Changelog](/changelog)
-   [About](/about)

Verify

-   [Security](/security)
-   [Privacy](/privacy)
-   [Terms](/terms)
-   [Legal](/legal)
-   [Contact](/contact)
-   [Status](https://status.leakwatch.net)

© 2026 LeakWatch

[GitHub](https://github.com/Leakwatch-Scan)[X](https://x.com/LeakwatchScan)
