THE SHORT ANSWER
API keys, access tokens, passwords and private keys are credentials or cryptographic material that can authorize systems or people. Store them in approved secret-management or server-side environments, grant minimum scope, rotate when exposed and never publish them.
Know what the credential can do
| Term | Plain meaning |
|---|---|
| API key | Identifier or credential used to call an API |
| Token | A credential representing scoped access, often for a limited context |
| Secret/password | Confidential value used to authenticate or sign |
| Public/private key | A public value can be shared; the paired private key must remain protected |
Public places are not secret stores
- Client-side code and generated assets
- Source repositories and commit history
- Screenshots and screen recordings
- Public or shared logs
- Chat messages and tickets
- Uncontrolled documents and spreadsheets
Treat exposure as compromise
Revoke or rotate the credential, investigate its use, replace dependent configuration and learn how it entered the exposed location. Simply deleting the visible copy may not remove history.
Turn guidance into an owned business action
Choose one relevant account, system, data set or workflow. Record the owner, current control, most important failure, detection signal, response step and recovery dependency. Escalate specialist, legal or regulatory questions to qualified advisers for the applicable context.
Sources & further reading
- Secrets Management Cheat Sheet
OWASP Foundation. Security guidance on secret creation, storage, distribution, rotation and revocation. It supports the principle that private credentials do not belong in public client code.
- Authorization Cheat Sheet
OWASP Foundation. Security guidance emphasizing least privilege, deny-by-default behavior and authorization checks on every request. Implementation details depend on the application's threat model.
Examples and exercises are illustrative unless attributed to a source. No independent expert review is claimed.
A correction, a counterexample or an experience worth sharing?
Join the conversation ↗