← All field notes

Field notes · Secrets · 3 min

Your .env file might be public. Here’s how to check.

How secret keys leak from .env files, how to check your own site in five minutes, and what to do if they already have.

Almost every modern app keeps its secrets in a file called .env: the database password, the Stripe secret key, the email provider’s API key. It’s meant to stay on the server. Sometimes it doesn’t, and when it leaks, whoever finds it can act as you: read your database, issue refunds, send email in your name.

How it ends up public

Check your own site in five minutes

  1. Open https://yourdomain.com/.env in a private browser window. You want a 404 or 403 page. If you see your variables, stop reading and go to the next section.
  2. Do the same for /.git/config. If that loads, your whole git history may be downloadable, including old secrets.
  3. Search your repository’s history for the file:
    git log --all --oneline -- .env
    Any output means it was committed at some point.
  4. Open your live site, view the page source and the main JavaScript files, and search for the start of your secret keys. Stripe secret keys begin with sk_live_. A Supabase service_role key should never appear in the browser. The public anon key is meant to.

If you found something

Hiding the file is not enough. Assume anything that was public has been copied.

  1. Rotate every key in the file. Create new keys in each provider’s dashboard, deploy them, then revoke the old ones. This is the step that actually protects you.
  2. Block the file. Move .env out of the folder your web server shares, or add a rule that refuses to serve any file whose name starts with a dot.
  3. Keep secrets on the server. Anything with a public prefix is public. Calls that need a secret key belong in a server route or function, not in the browser.
  4. Stop it happening again. Add .env to .gitignore, and turn on your git host’s secret scanning. GitHub’s push protection can block a commit that contains a known key format.
  5. Look at the logs. Check each provider’s activity log for requests you don’t recognise from the time the key was exposed.
The quick ruleIf a value would hurt you on a billboard, it must never be in a file the web server shares or in a variable with a public prefix.