TOOLS
Keep private values out of source code
Use Secrets for tokens, API keys, database credentials, and other sensitive configuration.
What belongs here
- Bot tokens.
- API keys.
- Database passwords.
- Private service credentials.
- Environment values that must not be committed to code.
Read values in the app
Configure the application to read these values from environment variables rather than hard-coding them.
Rotation
If a credential is exposed, replace it at the provider and update the matching Secret.
Do not log secrets
Avoid printing secret values to Console, deployment logs, screenshots, or support messages.
Warning
A secret that was publicly exposed should be treated as compromised even if you delete the message later.