Payments · Secret guide

Leaked Stripe secret key: what to do in the first hour

Critical severityChecked liveLast verified · 3 min read

A live Stripe secret key gives whoever holds it control over your payment account through the API: creating and refunding charges, reading customer data and changing account objects such as webhook endpoints. It is one of the most damaging keys to leak, and one of the quickest to fix. Roll the key first, then read the logs.

Check your GitHub account for leaked secrets — free

Provider
Stripe
Severity
Critical
Impact
Payments and customer data
Checked live by LeakWatch
Yes
Revoke at
Stripe

What a Stripe key looks like

The prefix tells you which key it is and how much it matters:

sk_live_…XXXX   secret key, live mode      → real money. Treat a leak as an incident.
rk_live_…XXXX   restricted key, live mode  → limited by the permissions you gave it.
sk_test_…XXXX   secret key, test mode      → no real money, but still rotate it.
pk_live_…XXXX   publishable key            → designed to be public. Not a leak by itself.

LeakWatch has a separate rule for each of these, so a publishable key is not flagged as a secret one. Detection of live secret keys requires the sk_live_ prefix followed by a long alphanumeric body.

How Stripe keys get leaked

  • Hardcoded in server code during integration and never moved to an environment variable.
  • The wrong key in the front end. The secret key was used where the publishable one belongs, so it shipped inside the JavaScript bundle or the mobile app.
  • Documentation and snippets: a curl -u sk_live_…: example in a README, a Postman collection, a support ticket or a screenshot.
  • Webhook and cron scripts that run on a server and get committed with their config.
  • Shared .env files passed around in chat, then committed.

What to do in the first hour

  1. Roll the key. In the Stripe Dashboard go to Developers → API keys, find the exposed key and choose Roll key. Because the key is compromised, set the old one to expire immediately rather than after the grace period.
  2. Deploy the new key to your servers and check that payments still go through. Store it in an environment variable or secret manager.
  3. Read the API request logs. Developers → Logs shows requests made with each key. Look at the window since the exposure for calls from IP addresses or endpoints you do not recognize, and for anything that creates or changes things rather than reads.
  4. Check what an attacker could have changed. Review webhook endpoints (a new endpoint is a way to intercept your events), recent refunds and payouts, new restricted keys, connected accounts, and the list of team members.
  5. Switch to restricted keys. For each service, create a restricted key (rk_live_…) with only the permissions it needs, so a future leak has a small blast radius.
  6. Assess customer-data exposure. If the logs suggest customer data was read, you may have notification duties (for example under GDPR). Talk to Stripe support and a qualified adviser; this is not something to decide alone.
  7. Then clean the repository and the history. Our guide I accidentally pushed an API key to GitHub covers the order.

Not sure what else leaked? Run a free scan.

Revoke it at Stripe

Open the Stripe API keys page and roll the key. Rolling creates a replacement and retires the old value, which is what you want when a key leaks. Stripe’s reference for key types and best practices is at docs.stripe.com/keys.

How LeakWatch detects it

LeakWatch recognizes live secret keys by their sk_live_ prefix. Test, restricted and publishable keys have their own rules. See which vendors leak most this week on the leak trends page.

LeakWatch can check whether a detected key is still active with a read-only request to Stripe. It never reads your data or spends your credits.

The check is a read-only request to the Stripe balance endpoint. A restricted key without balance permission is still recognized as a working credential. The check does not move money and does not read customer data.

FAQ

Is a leaked pk_live_ publishable key dangerous?

No, not on its own. Publishable keys are meant to be embedded in your web and mobile apps. What matters is that the secret key (sk_live_) has not leaked next to it.

My leaked key was sk_test_. Do I still need to act?

Test-mode keys cannot touch real money, so the urgency is lower. Rotate it anyway: it can expose your test data and integration setup, and it is a sign that the same habit may have leaked a live key.

How can I tell whether the key was used by someone else?

Check Developers → Logs for requests you did not make, then review webhook endpoints, refunds and payouts. If you find activity you did not cause, contact Stripe support right away.

Get alerted next time a secret leaks — create a free account

LeakWatch is not affiliated with Stripe.