Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Keep credentials out of tracked source and configuration, and provide them at runtime through environment variables or a managed secret store. Add local secret files to .gitignore before Git tracks them—but remember that ignoring a file does not remove a secret already committed. If a credential reaches a repository, treat it as exposed: revoke or rotate it promptly, then decide whether history cleanup is also needed.

How should an application get secrets?

Keep secret values separate from application code. Have the application read a named value at runtime rather than embedding the credential in source:

const token = process.env.API_TOKEN;
if (!token) throw new Error("API_TOKEN is required");

The code names the required variable but contains no credential. Environment variables provide a way to deliver values to a process; they do not, by themselves, decide who may access or provision those values. For shared deployments, a CI/CD secret store or dedicated secret manager can handle provisioning and access policy. OWASP describes centralized secret management in terms of storage, provisioning, auditing, and rotation: OWASP Secrets Management Cheat Sheet.

For local development

A local environment file or shell variable is often convenient. If you use a file such as .env, ignore it before adding it to Git. Commit a template such as .env.example that lists needed variable names and clearly fake placeholders, for example API_TOKEN=replace-me. This is a practical collaboration pattern: it communicates setup requirements without distributing working credentials.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

For automated builds and deployments

Use the CI/CD platform’s secret facility to make values available to the relevant workflow or deployment, and limit access to the jobs and people that need it. For services spanning environments or teams, a dedicated secret manager may make centralized access policy, auditing, and rotation easier. Neither option makes a secret safe if it is exposed in logs, copied into source, or granted too broadly.

What does .gitignore protect?

Git ignore rules keep matching untracked paths from being added by ordinary Git operations. They do not untrack a file already in the repository, erase its earlier versions, or neutralize a credential in it.

Rank #2
Sale
Yubico - YubiKey 5C NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

Ignore a local file before tracking it

  1. Add the local filename or path to .gitignore, for example .env.
  2. Check git status and confirm the local file does not appear as a file to add.
  3. Commit the ignore rule and the non-secret setup template, not the local values.

If Git already tracks the file

Adding it to .gitignore is not enough. Remove it from the index while keeping your working copy, then commit that change:

git rm --cached .env
git add .gitignore .env.example
git status

Review the staged changes before committing; confirm that no real credential is present in the diff. This stops the file from being tracked going forward, but does not remove credentials from previous commits. If the file contained a real secret, follow the leak-response steps below.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
Sale
Yubico - YubiKey 5 NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-A or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

How can you prevent and detect accidental commits?

  • Review the staged diff. Before each commit, inspect what Git will record and look for keys, tokens, passwords, private URLs, and sensitive configuration.
  • Use secret scanning. GitHub says secret scanning checks repository Git history for hardcoded credentials. Scanning can help find exposures, but it should not be treated as a guarantee that every credential will be detected. See About secret scanning.
  • Enable push protection where available. GitHub’s command-line push protection blocks pushes containing supported detected secrets. Coverage, setup, and eligibility depend on the hosting product and configuration; a blocked push is a useful safeguard, not a reason to put credentials in code. See Push protection from the command line.

These checks complement—not replace—keeping secrets out of tracked files and responding quickly to any exposure.

Which secret-delivery option fits your situation?

Approach Good fit What to manage
Environment variables or an ignored local env file Individual development and simple setups. Keep local files untracked; do not share actual values through source control.
CI/CD or repository secret store Automated workflows and deployments that need credentials without storing them in the repository. Restrict which workflows and people can access values, and rotate them when necessary. GitHub documents a repository “Secrets and variables” store as one example: GitHub secret-scanning guidance.
Dedicated secret manager Services or environments that need centralized provisioning, access policy, auditing, and rotation. Configure access and runtime delivery carefully; a manager does not prevent misuse or eliminate leak response. See OWASP Secrets Management Cheat Sheet.

No single method is universally safest. Choose based on where a value is needed and the access, rotation, audit, and operational controls your setup requires.

Rank #4
Yubico - Security Key NFC - Basic Compatibility - Multi-Factor Authentication (MFA) Key, Connect via USB-A or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What should you do if you committed a secret?

Assume the credential is compromised even if you delete the line or make the repository private. GitHub’s guidance is direct: “Real secrets that have been exposed must be revoked to avoid unauthorized access.” Follow the issuer’s process to revoke or rotate it, then assess what may have used it. GitHub’s remediation guidance also recommends reviewing usage and preventing another disclosure: Remediating a leaked secret in your repository.

  1. Revoke or rotate the credential with its issuer. Do this promptly; deleting a visible line does not invalidate the value.
  2. Assess possible use. Review relevant access or usage logs, identify which systems and environments could use the credential, and follow your incident process if activity is unexpected.
  3. Remove the secret from current source and prevent recurrence. Replace hardcoded configuration with runtime delivery, ignore local files, and add a safe template if collaborators need setup guidance.
  4. Decide whether history rewriting is warranted. Revocation is the urgent security action. Rewriting history can reduce casual exposure, but it may be time-consuming and disruptive; GitHub notes that history removal is often unnecessary after revocation. Consider it when the remaining exposure or organizational requirements justify the work.

If you rewrite history

Coordinate with collaborators before rewriting, update the remote after the rewrite, and arrange for other clones to be cleaned up or replaced. A force push cannot remove copies in forks or clones, cached views, or pull-request references. GitHub documents these residual copies and coordination concerns in Removing sensitive data from a repository.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
Yubico - YubiKey 5C - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB, FIDO Certified - Protect Your Online Accounts (5C)
  • POWERFUL SECURITY KEY: The YubiKey 5 is a versatile physical passkey that protects your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 secures 100+ of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 via USB and tap it to authenticate. No batteries, no internet connection, and no extra fees required.
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.