# Leaked Twilio API Key? Delete It and Check for Toll Fraud

> Twilio API key (SK...) exposed on GitHub? Delete the key, rotate the Auth Token, check call and SMS logs. Step-by-step guide.

Source: https://leakwatch.net/secrets/twilio-api-key

---

[LeakWatch](/)

[Product](/product)[Live feed](/leaks)[Guides](/secrets)[Blog](/blog)[Free scan](/)

1.  [Home](/)
2.  [Secrets](/secrets)
3.  Twilio API Key

Messaging · Secret guide

# Leaked Twilio API Key: what to do in the first hour

Medium severityDetected onlyLast verified October 2, 2026 · 5 min read

A Twilio API key is a credential for placing calls, sending SMS and using the rest of the Twilio APIs as your account. Calls and messages are billed per use, and some destinations are expensive, which is why a stolen Twilio credential is a favorite for toll fraud and SMS pumping: the attacker sends traffic to numbers they profit from and you pay the carrier charges. The first thing to do is work out which of Twilio’s several credentials you actually exposed.

[Check your GitHub account for leaked secrets — free](/)

Provider

Twilio

Severity

Medium

Impact

SaaS account access and billing

Checked live by LeakWatch

No

## What a Twilio API key looks like

A Twilio API key is a pair. The identifier, called the API Key SID, starts with `SK` and is followed by hexadecimal characters. The key secret is shown once, when the key is created.

```text
SK…XXXX   Twilio API Key SID (masked)
```

Twilio has other credentials that look similar and are easy to mix up:

-   **Account SID** (`AC…`) identifies the account. It is an identifier, not a secret on its own.
-   **Auth Token** is the account’s master secret. Used with the Account SID it grants full access, so it is more powerful than a standard API key. Rotate it if it was exposed.
-   **API Key Secret** pairs with the `SK…` SID. The SID alone cannot authenticate, but the two usually sit next to each other in the same file.

Detection flags the `SK…` SID because that is the part with a recognizable shape. If it appears in a file, assume the secret may be in the same file and check.

## How Twilio API keys get leaked

-   **Config next to the SID.** `TWILIO_ACCOUNT_SID`, `TWILIO_API_KEY` and `TWILIO_API_SECRET` or `TWILIO_AUTH_TOKEN` in a committed `.env`, Docker or serverless config.
-   **Sample code.** Quickstarts show the Auth Token inline; people replace the placeholders and push the file.
-   **Mobile and web apps.** A client application that creates Twilio tokens needs the key, but if it is bundled in the client, every user can extract it. Access tokens must be generated by a server.
-   **Notebooks, scripts and webhooks.** Notification scripts for alerts and two-factor codes, kept in a repository.
-   **CI logs and screenshots.** Debug output of API calls with credentials in basic authentication.

## What to do in the first hour

1.  **Create a replacement API key.** In the Twilio Console, go to *Account* → *API keys & tokens* and create a new API key. Copy the secret straight into your secret manager, because Twilio will not show it again.
2.  **Deploy the replacement** and test a call or SMS through the new credentials.
3.  **Delete the exposed key** from the same *API keys & tokens* page. If the Auth Token was exposed too, create a secondary Auth Token, update your apps to use it, then promote it so the old token stops working.
4.  **Audit usage.** Open the Console’s *Monitor* → *Logs* section for Messaging and Voice and review activity since the exposure. Look for destinations you never serve, countries unusual for your business, bursts of messages and calls with very short durations.
5.  **Check billing and usage.** Compare current spend with your normal level in the billing usage view. Set usage triggers or alerts so a spike emails you.
6.  **Harden the account.** Restrict which countries your account can call or text to (geographic permissions for Voice and Messaging), use restricted API keys where Twilio offers them, and keep each app on its own key.
7.  **Then clean the repository**: remove the value and rewrite history if you want to. See [I accidentally pushed an API key to GitHub](/blog/i-accidentally-pushed-an-api-key-to-github).

Not sure what else leaked? [Run a free scan](/).

[Not sure what else leaked? Run a free scan.](/)

## Revoke it at Twilio

Sign in to the Twilio Console and go to *Account* → *API keys & tokens*. Find the key by the SID shown in the list, open it, and delete it. Deleted keys stop authenticating immediately. If your account uses subaccounts, the key may live in the subaccount that created it, so switch to the right one using the account selector. To retire an exposed Auth Token, use the Auth Token section of the same page and its secondary-token flow rather than deleting anything, since the primary token cannot simply be removed.

## How LeakWatch detects it

The rule is called “Twilio API Key”. It looks for the uppercase letters `SK` followed by exactly 32 hexadecimal characters, which is the format of an API Key SID. It does not look for the secret that goes with it, so a finding means the SID is exposed and that the secret may be nearby. Because 32 hex characters can also appear in other contexts, a match with an unrelated hash is possible. LeakWatch detects this format but does not check it live: it can tell you the key is exposed, not whether it still works. Assume it does until you have revoked it.

LeakWatch detects this format but does **not** check it live: it can tell you the key is exposed, not whether it still works. Assume it does until you have revoked it.

## FAQ

Is the SID alone dangerous?

Not by itself, since authenticating needs the secret too. But the two are normally stored together, and a repository that leaks one often leaks the other. Treat the key as compromised and delete it.

What is SMS pumping and how do I notice it?

It is traffic generated to premium or attacker-controlled numbers so that the fraudster receives a share of the carrier fees. Signs are many messages to a few unusual country prefixes, verification codes nobody requested, and a bill that grows without a matching increase in users.

Does deleting the key cancel the charges already made?

No. Deleting stops new traffic only. For charges you did not cause, contact Twilio support with your logs as soon as possible.

## Related

-   [Telegram Bot Token](/secrets/telegram-bot-token)
-   [Discord Bot Token](/secrets/discord-bot-token)
-   [Mailgun API Key](/secrets/mailgun-api-key)
-   [I accidentally pushed an API key to GitHub](/blog/i-accidentally-pushed-an-api-key-to-github)
-   [Which vendors leak most this week](/leaks/trends)
-   [All secret guides](/secrets)

[Get alerted next time a secret leaks — create a free account](/)

LeakWatch is not affiliated with Twilio.

![Gabriel Diyan, founder of LeakWatch](/brand/Photo-Gabriel-Diyan.webp)

Gabriel Diyan (0xCr0c0)

Cybersecurity student, founder of LeakWatch. I built and run the scanner described here — the detection patterns, the false-positive classifier and the provider validators are mine. [More about who I am](/about).

[GitHub](https://github.com/Leakwatch-Scan) · [X](https://x.com/LeakwatchScan) · [LinkedIn](https://www.linkedin.com/in/gabriel-diyan-80a378375) · [GitHub (personal)](https://github.com/crocogab)

LeakWatch

Secrets leak into public commits every minute. This watches the forges for yours. Built and run by [Gabriel Diyan](/about), a cybersecurity student — [why LeakWatch exists](/about).

Scan

-   [Product](/product)
-   [Live feed](/leaks)
-   [Trends](/leaks/trends)
-   [API docs](/docs)
-   [CI/CD](/docs?tab=ci)

Read

-   [Blog](/blog)
-   [Secret guides](/secrets)
-   [Changelog](/changelog)
-   [About](/about)

Verify

-   [Security](/security)
-   [Privacy](/privacy)
-   [Terms](/terms)
-   [Legal](/legal)
-   [Contact](/contact)
-   [Status](https://status.leakwatch.net)

© 2026 LeakWatch

[GitHub](https://github.com/Leakwatch-Scan)[X](https://x.com/LeakwatchScan)
