THE SHORT ANSWER

API keys, access tokens, passwords and private keys are credentials or cryptographic material that can authorize systems or people. Store them in approved secret-management or server-side environments, grant minimum scope, rotate when exposed and never publish them.

Know what the credential can do

Credentials and secrets
TermPlain meaning
API keyIdentifier or credential used to call an API
TokenA credential representing scoped access, often for a limited context
Secret/passwordConfidential value used to authenticate or sign
Public/private keyA public value can be shared; the paired private key must remain protected

Public places are not secret stores

  • Client-side code and generated assets
  • Source repositories and commit history
  • Screenshots and screen recordings
  • Public or shared logs
  • Chat messages and tickets
  • Uncontrolled documents and spreadsheets

Treat exposure as compromise

Revoke or rotate the credential, investigate its use, replace dependent configuration and learn how it entered the exposed location. Simply deleting the visible copy may not remove history.

Turn guidance into an owned business action

Choose one relevant account, system, data set or workflow. Record the owner, current control, most important failure, detection signal, response step and recovery dependency. Escalate specialist, legal or regulatory questions to qualified advisers for the applicable context.

Sources & further reading

  1. Secrets Management Cheat Sheet

    OWASP Foundation. Security guidance on secret creation, storage, distribution, rotation and revocation. It supports the principle that private credentials do not belong in public client code.

  2. Authorization Cheat Sheet

    OWASP Foundation. Security guidance emphasizing least privilege, deny-by-default behavior and authorization checks on every request. Implementation details depend on the application's threat model.

Examples and exercises are illustrative unless attributed to a source. No independent expert review is claimed.

A correction, a counterexample or an experience worth sharing?

Join the conversation ↗