TOOLS/Secrets
TOOLS

Keep private values out of source code

Use Secrets for tokens, API keys, database credentials, and other sensitive configuration.

What belongs here

  • Bot tokens.
  • API keys.
  • Database passwords.
  • Private service credentials.
  • Environment values that must not be committed to code.

Read values in the app

Configure the application to read these values from environment variables rather than hard-coding them.

Rotation

If a credential is exposed, replace it at the provider and update the matching Secret.

Do not log secrets

Avoid printing secret values to Console, deployment logs, screenshots, or support messages.

Warning

A secret that was publicly exposed should be treated as compromised even if you delete the message later.