API keys show up in source code when they are hardcoded or saved in tracked configuration files; in browser requests when frontend code sends them to users; and in logs when requests, URLs, or diagnostic data record them. Treat a credibly exposed key as compromised: revoke or rotate it, replace it using server-side secret storage or an appropriate identity flow, check for misuse, and clean up the copies.
Why API keys appear in places users can see
Hardcoded or tracked files
A key written directly into application code or stored in a file inside the source tree can be committed, shared, or published along with the project. Google advises against embedding API keys in code or keeping them in files within an application’s source tree (Google Cloud: API key best practices).
Frontend bundles and browser requests
Browser-delivered code is available to the people using the application. If a build inserts a key into frontend JavaScript, or the browser sends the key in a request, a user can inspect it. Moving a value into a frontend environment variable does not make it private when the build places it in client-side code. Google warns that embedding a Google Cloud API key in an application makes it publicly available (Google Cloud: API key best practices; Google Cloud: Using API keys).
URLs, logs, and diagnostic data
A key included in a URL query string can be captured by logs and URL-scanning systems. Google recommends using an API-key header or client library rather than a query parameter for Google APIs (Google Cloud: API key best practices). Keys can also be retained in application or infrastructure logs, proxy captures, error reports, and debugging output when those systems record credential-bearing requests. Logging defaults depend on the application and infrastructure, so check the systems that handle your traffic and configure redaction where needed.
Quick wins for a faster PC:
Clear out junk files and repair common Windows errorsFree Scan →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Repair Windows errors before they cause bigger problemsFix Now →#1 Best Overall
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Copies remain after the visible one is removed
Once committed or copied, a key may remain in Git history, another branch, a build artifact, a ticket, or a log. Removing it from the current file does not invalidate it. GitHub secret scanning can scan repository history across branches, but provider-side revocation and investigation are still necessary (GitHub: About secret scanning).
What to do when you discover an exposed key
- Revoke or rotate it promptly. Use the credential issuer’s process as soon as exposure is credible. Do not wait until every copy has been located: deleting code does not disable a credential that has already been disclosed. AWS and GitHub both advise immediate rotation or revocation for compromised credentials (AWS Secrets Manager: Rotating secrets; GitHub: About secret scanning).
- Put the replacement somewhere protected. Store private credentials in a secrets manager or protected runtime configuration, then update the service to retrieve the replacement. Google recommends Secret Manager for sensitive values; AWS describes using Secrets Manager or Systems Manager Parameter Store (Google Cloud: Secret Manager best practices; AWS Secrets Manager: Rotating secrets).
- Check for unauthorized use. Review the provider’s available audit events and usage records for unfamiliar sources or actions during the period the key may have been exposed. GitHub recommends looking for audit events associated with a compromised token and reviewing secret-scanning findings. What details are available depends on the provider and its logging configuration (GitHub: About secret scanning).
- Find and clean up copies. Check current files, Git history, branches, build artifacts, logs, tickets, and other places the value may have been copied. History rewriting can improve repository hygiene, but it does not replace revocation. GitHub notes that history removal can be time-intensive and is often unnecessary after revocation; AWS includes history removal in its remediation steps (GitHub: About secret scanning; AWS Secrets Manager: Rotating secrets).
- Verify the change. Confirm deployed services use the replacement and work correctly, then monitor for suspicious activity.
Choose a fix that matches where the key is exposed
| Exposure location | Most important fix | Additional control |
|---|---|---|
| Tracked source file or repository history | Revoke or rotate the key, then move the replacement out of tracked source files. | Scan repository history and branches; review other copies such as artifacts and tickets. |
| Frontend bundle or browser request | Move privileged calls to a backend that adds the credential before contacting the API. | If the API requires a public-client key, restrict it to intended apps or origins and APIs where supported. |
| URL query parameter | Stop sending the key in the URL; use the provider-recommended header or client library. | Review URL logs and scanning systems that may have captured it. |
| Application or infrastructure logs | Rotate the key and configure the relevant logging and observability systems to redact credentials. | Check retained logs, proxy captures, and error reports for copies. |
The right design also depends on the credential’s privilege and lifetime, whether the caller can be moved behind a server, and which restrictions, identity options, audit records, and scanning controls the provider supports. API-key types and provider procedures differ, so identify the exact credential and API before applying console-specific steps.
Rank #2
- POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
Keep private credentials out of browser code
For a privileged API call from a web application, have the browser call your backend and let that server attach the credential when it calls the provider. Google Cloud documentation puts the pattern plainly: “The client should pass requests to the server, which can add the credential and issue the request.” (Google Cloud: API key best practices.)
Where the service supports it, consider identity-based authorization or short-lived credentials instead of a long-lived production authorization key. Google recommends considering IAM policies and short-lived service-account credentials in applicable cases, but the right option depends on the product and API; follow the provider’s guidance for the service you use (Google Cloud: API key best practices).
Rank #3
- POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
When a key is intentionally public
Some browser-based integrations require a key in a public client. In that case, treat it as visible rather than secret. Apply the restrictions supported by the provider—such as limiting use to specified websites, apps, IP addresses, or APIs—keep permissions narrow, monitor usage, and remove keys that are no longer needed. Restrictions can reduce the opportunities for misuse; they do not conceal the key or make it secret (Google Cloud: API key best practices; Google Cloud: Using API keys).
Quick Recap
Best Value
- POWERFUL SECURITY KEY: The YubiKey 5 is a versatile physical passkey that protects your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 secures 100+ of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 via USB and tap it to authenticate. No batteries, no internet connection, and no extra fees required.
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Rank #4
- POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Prevent the next exposure
- Keep private credentials outside tracked source trees and retrieve them at runtime from a secrets manager or protected environment.
- Add secret scanning to repositories and development or CI workflows. GitHub secret scanning can check Git history across branches; AWS recommends regular repository scans and detection in local development or CI/CD (GitHub: About secret scanning; AWS Secrets Manager: Rotating secrets).
- Use the provider-recommended header or client library instead of putting keys in URL query parameters.
- Configure logging and observability tools to redact credentials from request data, traces, and diagnostic output.
- Review restrictions and usage periodically, and delete unused keys.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




