# Leaked Stripe Secret Key? Roll It and Check Logs

> Stripe secret key exposed? Roll it from the Dashboard, review API logs, webhooks and payouts, and move to restricted keys. Step-by-step.

Source: https://leakwatch.net/secrets/stripe-secret-key

---

[LeakWatch](/)

[Product](/product)[Live feed](/leaks)[Guides](/secrets)[Blog](/blog)[Free scan](/)

1.  [Home](/)
2.  [Secrets](/secrets)
3.  Stripe secret key

Payments · Secret guide

# Leaked Stripe secret key: what to do in the first hour

Critical severityChecked liveLast verified October 2, 2026 · 3 min read

A live Stripe secret key gives whoever holds it control over your payment account through the API: creating and refunding charges, reading customer data and changing account objects such as webhook endpoints. It is one of the most damaging keys to leak, and one of the quickest to fix. Roll the key first, then read the logs.

[Check your GitHub account for leaked secrets — free](/)

Provider

Stripe

Severity

Critical

Impact

Payments and customer data

Checked live by LeakWatch

Yes

Revoke at

[Stripe](https://dashboard.stripe.com/apikeys)

## What a Stripe key looks like

The prefix tells you which key it is and how much it matters:

```text
sk_live_…XXXX   secret key, live mode      → real money. Treat a leak as an incident.
rk_live_…XXXX   restricted key, live mode  → limited by the permissions you gave it.
sk_test_…XXXX   secret key, test mode      → no real money, but still rotate it.
pk_live_…XXXX   publishable key            → designed to be public. Not a leak by itself.
```

LeakWatch has a separate rule for each of these, so a publishable key is not flagged as a secret one. Detection of live secret keys requires the `sk_live_` prefix followed by a long alphanumeric body.

## How Stripe keys get leaked

-   **Hardcoded in server code** during integration and never moved to an environment variable.
-   **The wrong key in the front end.** The secret key was used where the publishable one belongs, so it shipped inside the JavaScript bundle or the mobile app.
-   **Documentation and snippets**: a `curl -u sk_live_…:` example in a README, a Postman collection, a support ticket or a screenshot.
-   **Webhook and cron scripts** that run on a server and get committed with their config.
-   **Shared `.env` files** passed around in chat, then committed.

## What to do in the first hour

1.  **Roll the key.** In the Stripe Dashboard go to Developers → API keys, find the exposed key and choose *Roll key*. Because the key is compromised, set the old one to expire **immediately** rather than after the grace period.
2.  **Deploy the new key** to your servers and check that payments still go through. Store it in an environment variable or secret manager.
3.  **Read the API request logs.** Developers → Logs shows requests made with each key. Look at the window since the exposure for calls from IP addresses or endpoints you do not recognize, and for anything that creates or changes things rather than reads.
4.  **Check what an attacker could have changed.** Review webhook endpoints (a new endpoint is a way to intercept your events), recent refunds and payouts, new restricted keys, connected accounts, and the list of team members.
5.  **Switch to restricted keys.** For each service, create a restricted key (`rk_live_…`) with only the permissions it needs, so a future leak has a small blast radius.
6.  **Assess customer-data exposure.** If the logs suggest customer data was read, you may have notification duties (for example under GDPR). Talk to Stripe support and a qualified adviser; this is not something to decide alone.
7.  **Then clean the repository** and the history. Our guide [I accidentally pushed an API key to GitHub](/blog/i-accidentally-pushed-an-api-key-to-github) covers the order.

[Not sure what else leaked? Run a free scan.](/)

## Revoke it at Stripe

Open the [Stripe API keys page](https://dashboard.stripe.com/apikeys) and roll the key. Rolling creates a replacement and retires the old value, which is what you want when a key leaks. Stripe’s reference for key types and best practices is at [docs.stripe.com/keys](https://docs.stripe.com/keys).

## How LeakWatch detects it

LeakWatch recognizes live secret keys by their `sk_live_` prefix. Test, restricted and publishable keys have their own rules. See which vendors leak most this week on the [leak trends](/leaks/trends) page.

LeakWatch can check whether a detected key is still active with a read-only request to Stripe. It never reads your data or spends your credits.

The check is a read-only request to the Stripe balance endpoint. A restricted key without balance permission is still recognized as a working credential. The check does not move money and does not read customer data.

## FAQ

Is a leaked pk\_live\_ publishable key dangerous?

No, not on its own. Publishable keys are meant to be embedded in your web and mobile apps. What matters is that the *secret* key (`sk_live_`) has not leaked next to it.

My leaked key was sk\_test\_. Do I still need to act?

Test-mode keys cannot touch real money, so the urgency is lower. Rotate it anyway: it can expose your test data and integration setup, and it is a sign that the same habit may have leaked a live key.

How can I tell whether the key was used by someone else?

Check Developers → Logs for requests you did not make, then review webhook endpoints, refunds and payouts. If you find activity you did not cause, contact Stripe support right away.

## Related

-   [Razorpay API Key](/secrets/razorpay-key)
-   [Shopify Access Token](/secrets/shopify-access-token)
-   [Database Connection String](/secrets/database-connection-string)
-   [I accidentally pushed an API key to GitHub](/blog/i-accidentally-pushed-an-api-key-to-github)
-   [Which vendors leak most this week](/leaks/trends)
-   [All secret guides](/secrets)

[Get alerted next time a secret leaks — create a free account](/)

LeakWatch is not affiliated with Stripe.

![Gabriel Diyan, founder of LeakWatch](/brand/Photo-Gabriel-Diyan.webp)

Gabriel Diyan (0xCr0c0)

Cybersecurity student, founder of LeakWatch. I built and run the scanner described here — the detection patterns, the false-positive classifier and the provider validators are mine. [More about who I am](/about).

[GitHub](https://github.com/Leakwatch-Scan) · [X](https://x.com/LeakwatchScan) · [LinkedIn](https://www.linkedin.com/in/gabriel-diyan-80a378375) · [GitHub (personal)](https://github.com/crocogab)

LeakWatch

Secrets leak into public commits every minute. This watches the forges for yours. Built and run by [Gabriel Diyan](/about), a cybersecurity student — [why LeakWatch exists](/about).

Scan

-   [Product](/product)
-   [Live feed](/leaks)
-   [Trends](/leaks/trends)
-   [API docs](/docs)
-   [CI/CD](/docs?tab=ci)

Read

-   [Blog](/blog)
-   [Secret guides](/secrets)
-   [Changelog](/changelog)
-   [About](/about)

Verify

-   [Security](/security)
-   [Privacy](/privacy)
-   [Terms](/terms)
-   [Legal](/legal)
-   [Contact](/contact)
-   [Status](https://status.leakwatch.net)

© 2026 LeakWatch

[GitHub](https://github.com/Leakwatch-Scan)[X](https://x.com/LeakwatchScan)
