API Key Exposed in Your AI Application: How to Fix It Immediately
Discovered that API keys, database credentials, or secrets are exposed in your AI-built application's frontend code or repository? This is urgent. Here's exactly what to do right now.
If you've just discovered that API keys or secrets are exposed in your AI-generated application's frontend code, browser console, or public repository — this requires immediate action. Every minute a secret is exposed is a minute an attacker could be using it to make API calls on your account, access your database, or incur costs on your services. Here's your step-by-step emergency response plan.
Step 1: Revoke the Exposed Secret Immediately
Before doing anything else — before reading the rest of this article — go to the service that issued the exposed secret and revoke it. Don't think about what this will break. Don't wait to understand the full situation. Revoke it now.
- OpenAI API key: Go to platform.openai.com → API keys → Delete the key
- Google API key: Go to console.cloud.google.com → Credentials → Delete or restrict the key
- Stripe key: Go to dashboard.stripe.com → Developers → API keys → Roll key
- Database URL: Go to your database provider and rotate the password or connection credentials
- GitHub token: Go to github.com → Settings → Developer settings → Personal access tokens → Delete
After revoking, create a new secret. Do not reuse the exposed one.
Step 2: Assess the Exposure Window
Once the immediate threat is contained, understand what happened:
- How long was the secret exposed? Check your deployment history or Git commit timestamps.
- Was the repository public? If the secret was in a public GitHub repository at any point, assume it was found by automated scanning bots within minutes of being committed.
- Was the secret in frontend code? If it was in JavaScript that ran in the browser, it was visible to every user who visited your application.
- Check your API usage logs. Look for unusual activity — API calls from unexpected IP addresses, calls at unusual hours, or unusually high usage volumes.
Step 3: Remove the Secret from All Code
Simply removing the secret from current code is not enough if it was ever committed to a Git repository — Git preserves all history, and the secret remains visible in past commits even after deletion.
To permanently remove a secret from Git history, you need to use tools like git-filter-repo or BFG Repo Cleaner to rewrite your repository history. This is a destructive operation that requires careful execution — consider getting professional help if you're unfamiliar with Git history rewriting.
Step 4: Implement Proper Secrets Management
After the immediate crisis is resolved, implement proper secrets management to ensure this never happens again:
Rule 1: No Secrets in Frontend Code — Ever
Secrets should never appear in client-side code (JavaScript that runs in the browser). Browser code is publicly visible. Any secret in frontend code is effectively public. If your AI-generated frontend includes API calls that require secret keys (like direct calls to OpenAI or a database), these calls must be moved to a backend server that the frontend calls instead.
Rule 2: Use Environment Variables
All secrets should be stored in environment variables, never hardcoded in source files. Your .env file should be in .gitignore and never committed to your repository. In production, configure secrets through your hosting platform's environment variable management (not in your code).
Rule 3: Use a Secrets Manager for Production
For production applications, consider using a dedicated secrets management service (AWS Secrets Manager, HashiCorp Vault, Doppler) that provides audit trails, rotation capabilities, and access control for your secrets.
Rule 4: Scan Before Every Commit
Use a tool like git-secrets or detect-secrets as a pre-commit hook to automatically scan your code for potential secrets before they're committed. GitHub also offers secret scanning on public repositories that will alert you if known secret patterns are detected.
Common AI-Generated Secret Exposure Patterns
Pattern 1: Direct API Calls in Frontend
AI tools often generate code where the frontend calls OpenAI, Anthropic, or other APIs directly — embedding the API key in the JavaScript. The fix is to create a backend route that makes the API call, and have the frontend call your backend instead.
Pattern 2: Database Connection in Frontend
Some AI-generated applications include database connection strings in frontend code. The database should never be directly accessible from the browser — always through a backend API.
Pattern 3: Secrets in Console Logs
AI debugging code sometimes logs entire request objects to the console, inadvertently logging secrets. Audit all console.log statements for sensitive data.
Frequently Asked Questions
If I revoked the exposed key and no unusual activity occurred, am I safe?
Revocation is essential and the absence of obvious misuse is a good sign. However, sophisticated attackers may not make immediately obvious API calls — they may harvest credentials for later use. Monitor your usage logs for the next several weeks and consider additional security hardening.
My repository is private. Am I still at risk?
A private repository reduces the risk significantly but doesn't eliminate it. People with repository access (contributors, CI systems, acquired tools) can still see the secrets. Additionally, repositories sometimes get accidentally made public. Use environment variables regardless of repository visibility.
How do I fix AI-generated frontend API calls without rebuilding the app?
Create a new backend endpoint (e.g., /api/chat), move the API call with the secret key to this endpoint, and update the frontend to call your backend endpoint instead of the third-party API directly. This is a structural change that may require engineering assistance.
Conclusion
An exposed API key or secret is a security incident that requires immediate response: revoke the exposed secret, assess the exposure window, remove it from all code, and implement proper secrets management. The good news is that with the right architecture, this is entirely preventable.
If you've discovered exposed secrets in your AI-built application and need help assessing the impact and securing your application properly, SynapseTech can help. We'll review your entire secrets management approach and ensure your application handles sensitive credentials safely.
Ready to Build Something Like This?
Our team turns complex ideas into production-ready software. Let's talk about your project.