Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

If a password, API key, token, or other credential appears in a GitHub repository, treat it as compromised. Find out what it unlocks, revoke it with the issuing provider, replace it where needed, and update dependent services. Deleting the string from the current file does not invalidate it; cleaning Git history is a separate decision you can make after access is cut off.

How do I find exposed secrets in a GitHub repository?

Start with the credential’s GitHub secret-scanning alert, if one exists. Identify the secret type and provider, the repository and location where it appeared, and the person or team responsible for it. The provider—not the text’s appearance in a file—is the source of truth about whether the credential still works.

  • Read the alert’s exposure details, including whether it appeared in a public repository or more than once.
  • Check any status, validity, or use information shown. GitHub may provide validity and use details for some GitHub personal access tokens (PATs), but those details are not available for every secret type.
  • Find which applications, deployments, integrations, repository secrets, or deploy-key configurations depend on the credential.
  • Assess whether it protects production systems or sensitive data, and consider service disruption when planning replacement. An active credential exposed publicly or used in production calls for urgent action.

When an alert is unavailable, inspect the repository’s visibility, recent changes, file context, and relevant logs, and determine which provider issued the credential. Avoid copying the exposed value into public notes or messages.

What GitHub Secret Scanning can and cannot tell you

GitHub Secret Scanning checks Git history on all branches for recognized patterns and can create alerts. Public repositories receive scanning automatically at no cost. Organization-owned private and internal repositories require GitHub Secret Protection on eligible GitHub Team or Enterprise Cloud plans; see GitHub’s Secret Scanning overview and repository setup instructions for current eligibility and configuration details.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

No alert does not prove no secret was exposed: detection covers known patterns and has eligibility and scope limits. Review GitHub’s secret-scanning detection scope to understand what is covered.

How do I respond to a leaked credential?

  1. Identify the provider and dependencies. Use the alert and repository context to determine which service issued the credential and what relies on it.
  2. Revoke it with the provider. Follow that provider’s instructions. If dependent services must remain available, create a replacement and move them to it as appropriate; for high-risk credentials, prioritize revocation.
  3. Update every dependent service. Replace the value in applications, deployments, integrations, repository secrets, and deploy-key configurations that used it. Verify that the services work with the replacement.
  4. Resolve the alert and record the incident. Once the credential is revoked and dependencies are updated, close the alert as revoked and document the response.

GitHub automatically revokes GitHub PATs leaked in public repositories. For a leaked GitHub PAT in a private repository, a user can report it from the secret-scanning alert. For other supported partner patterns in a public repository, GitHub reports the leak to the provider, which may revoke it immediately. These behaviors do not replace confirmation with the provider: a report does not guarantee that every kind of credential has been disabled. See GitHub’s leaked-secret remediation guidance.

Rank #2
Yubico - YubiKey 5C NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

Is deleting a leaked API key from the file enough?

No. Removing the string in a new commit changes the current file, not the credential’s validity, and the old value may remain in earlier commits or other copies. Revoke or rotate the credential with its provider first. Do not assume that deleting a file, pushing a cleanup commit, or deleting and recreating the repository prevents use of the exposed value.

Should I remove a secret from Git history?

Rewriting history is an additional cleanup measure, not a substitute for revocation. GitHub notes that revoking or rotating a secret may be sufficient and that rewriting can be time-consuming and disruptive. Decide with the credential owner and repository security leads, weighing whether the string itself still creates risk or obligations against the impact on collaborators, forks, pull requests, signatures, automation, and existing clones.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
Yubico - YubiKey 5 NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-A or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
Option What it addresses Main trade-off
Revoke or rotate, leave history intact Stops the exposed credential from granting access once the provider has invalidated it; avoids rewriting commits. The string remains in historical commits and may persist in clones, forks, cached views, or pull requests.
Revoke or rotate and rewrite history Removes the secret from rewritten repository history, when cleanup is justified. Changes commit hashes, can invalidate signatures or tooling, disrupt pull-request diffs, and requires coordinated cleanup of old copies.

History cleanup is worth considering when the exposed text itself remains harmful, or security, compliance, or contractual requirements call for removal. It is not automatically necessary after a credential is invalidated.

If history rewriting is justified

GitHub documents using git-filter-repo to remove sensitive data. The GitHub documentation reviewed specifies version 2.47 or later for the --sensitive-data-removal flag. Removing a file by path requires accounting for renamed or moved paths; replacing secret text requires a replacement list. Follow GitHub’s sensitive-data removal procedure, including verifying the result before pushing rewritten refs.

Rank #4
Yubico - Security Key NFC - Basic Compatibility - Multi-Factor Authentication (MFA) Key, Connect via USB-A or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

A mirror force-push can overwrite branches, tags, and refs and discard concurrent changes, so coordinate the work before pushing. Rewritten history also needs a plan for collaborators: old clones can reintroduce the secret, so collaborators should clean or replace them and rebase branches rather than merge tainted history. Fork owners may need to clean their own copies. Pull requests and cached views can retain copies; GitHub Support may remove cached views and references in eligible sensitive-data cases after cleanup, but does not remove non-sensitive data and may decline when rotating the credential sufficiently mitigates the risk.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Where else should I look for copies?

After revocation or rotation, search the organization and repository for the exact secret value using GitHub code search. Also inspect deploy keys, stored secrets and variables, installed GitHub Apps, and integrations that may contain or depend on it. Keep the value out of public incident notes and communications. Resolve the alert as revoked and record what was updated.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
Yubico - YubiKey 5C - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB, FIDO Certified - Protect Your Online Accounts (5C)
  • POWERFUL SECURITY KEY: The YubiKey 5 is a versatile physical passkey that protects your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 secures 100+ of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 via USB and tap it to authenticate. No batteries, no internet connection, and no extra fees required.
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

How can I prevent another exposure?

Enable push protection

Push protection can block supported secret patterns before they enter a protected repository; user-level protection can also protect pushes to public repositories. It is a useful barrier, not complete coverage: only some patterns are blocked, older token formats may be unsupported, large pushes may time out, public-repository pushes over 50 MB are skipped, and secrets already flagged by alerts are not necessarily blocked. Secret Scanning may still create alerts after a push. Check GitHub’s detection-scope documentation for details.

Keep credentials out of source code

Do not hardcode credentials in files. GitHub recommends using environment variables or managed secret services such as Azure Key Vault, AWS Secrets Manager, and HashiCorp Vault to manage and inject secrets at runtime. A .gitignore entry can keep a local configuration file out of future commits, but it does not erase a secret already committed. Pre-commit checks such as git-secrets or gitleaks can provide another opportunity to catch mistakes before committing.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.