Cloud · Secret guide

Leaked Terraform Cloud API Token: what to do in the first hour

Critical severityDetected onlyLast verified · 5 min read

A Terraform Cloud API token, now branded HCP Terraform, is the credential behind terraform login and behind the API: it lets its holder do what its owner can do in your organization. With enough rights that includes queueing runs, changing workspace variables and downloading state files. That is more serious than it sounds, because a run executes code in an environment that holds your cloud credentials. Revoke the token first, then check what ran.

Check your GitHub account for leaked secrets — free

Provider
HashiCorp Terraform
Severity
Critical
Impact
Cloud infrastructure access
Checked live by LeakWatch
No

What a Terraform Cloud token looks like

Every token from HCP Terraform and Terraform Enterprise has the same three-part shape, with a literal atlasv1 in the middle:

…XXXX.atlasv1.…XXXX   (masked)

There are four kinds, and the format does not tell them apart:

  • User tokens: belong to a person and carry everything that person can do.
  • Team tokens: belong to a team and carry that team’s permissions.
  • Organization tokens: manage teams and workspaces for one organization.
  • Audit trail tokens: read-only access to audit events.

LeakWatch also catches this format under two rule names, “HashiCorp Terraform API Token” and “Terraform Cloud Personal Token”. If what leaked was a cloud provider key found in a Terraform file, use the AWS access key, Azure client secret or GCP service account key guide instead.

How Terraform Cloud tokens get leaked

  • The credentials file created by terraform login. The token is stored in plain text in credentials.tfrc.json inside the .terraform.d directory of your home folder, and that folder gets copied into repositories, backups and Docker images.
  • CLI configuration. A credentials block in .terraformrc or terraform.rc, committed along with the rest of the dotfiles.
  • Environment variables in CI. TF_TOKEN_app_terraform_io or TFE_TOKEN set in a workflow file or a build log that prints the environment.
  • Scripts that call the API. A curl command with an Authorization: Bearer header in a README, a Makefile or a deployment script.
  • Variable files. A *.tfvars file that passes the token to the tfe provider.

What to do in the first hour

  1. Revoke the token. For a user token, open User settings → Tokens and delete it. For a team token, go to Organization settings → Teams, select the team and regenerate or delete its team token. For an organization token, go to Organization settings → API tokens and regenerate or delete it. Regenerating replaces the old value immediately. If you cannot tell which token leaked, delete or regenerate all the ones that could be involved.
  2. Replace it, and shrink it. Create a new token for the specific job, owned by a team with the minimum permissions. For automation, prefer a team token over a personal one so it does not die when a person leaves.
  3. Check recent runs. Open each workspace’s Runs list and look for runs you did not queue since the exposure, especially ones with changed code or a different configuration version. A run can execute arbitrary commands, so an unknown apply is a serious sign.
  4. Check the workspace variables. Look for changed, added or removed variables and for changed variable sets. Check workspace settings for new run triggers, notifications and VCS connections.
  5. Treat the credentials stored in workspaces as exposed. Cloud keys kept as workspace variables are readable by any code a run executes, even if marked sensitive. State files can also hold secrets in plain text, and a token with state access can download them. Rotate cloud keys and any secret that appears in state.
  6. Check the audit trail. If your plan includes audit trails, review events for the period; otherwise check the organization’s team and token lists for anything you did not create.
  7. Then clean the repository: remove the value and rewrite history if you want. See I accidentally pushed an API key to GitHub.

Not sure what else leaked from the same repository? Run a free scan.

Not sure what else leaked? Run a free scan.

Revoke it at HCP Terraform

Sign in to HCP Terraform (or your Terraform Enterprise host). User tokens are under User settings → Tokens; team and organization tokens are under Organization settings. Delete or regenerate the token and the old value stops working. If you run Terraform Enterprise on your own domain, the same pages exist on that host. Which menu items you see depends on your role, and organization owners can see the team and organization tokens.

How LeakWatch detects it

LeakWatch recognizes the .atlasv1. marker between a short prefix and a long body. LeakWatch detects this format but does not check it live: it can tell you the token is exposed, not whether it still works. Assume it does until you have revoked it.

LeakWatch detects this format but does not check it live: it can tell you the key is exposed, not whether it still works. Assume it does until you have revoked it.

FAQ

Does a Terraform Cloud token give access to my AWS or Azure account?

Not directly. But a token that can queue runs can make a workspace execute code with the cloud credentials configured there, and state files can contain secrets. In practice, the cloud credentials behind the workspace should be rotated too.

I only used the token with terraform login on my laptop. Should I still revoke it?

Yes, if the credentials file or its folder ever left your machine. A user token carries your full permissions in every organization you belong to.

Is a team token safer than a user token?

It is limited to one team’s permissions, and it does not depend on one person’s account. But its permissions can still include running applies, so a leak is still an incident.

Get alerted next time a secret leaks — create a free account

LeakWatch is not affiliated with HashiCorp Terraform.