# Secrets Management — OWASP Top 10

Source: https://www.skillbyai.com/en/owasp-top-10/c-secrets

> Keys and tokens outside code.

## Store, rotate and scope secrets

API keys, database passwords and signing keys must not live in source code, images or client-side bundles. Store them in a **secrets manager** (cloud secret stores, HashiCorp Vault) or at least injected environment variables, grant each service only the secrets it needs, rotate them regularly and immediately after exposure, and prefer short-lived credentials (workload identity, OIDC federation) over static keys. Scan repositories and CI logs for leaked secrets.

## Reading a secret at runtime

Python sketch; the secret value never appears in the repository.

```python
import os

# VULNERABLE: committed to git forever
STRIPE_KEY = "sk_live_51H..."

# BETTER: injected at runtime by the platform or a secrets manager
STRIPE_KEY = os.environ["STRIPE_API_KEY"]

# Add secret scanning (for example gitleaks or your git host's scanning)
# to pre-commit hooks and CI so leaks are caught before merge.
```

## Rotate after any leak, even private repos

Deleting a commit does not remove a secret from clones, forks or caches; revoke and rotate it.

**Quiz:** What should you do first when a secret is committed to a repository?

- [ ] Only delete the file in the next commit
- [x] Revoke and rotate the secret
- [ ] Make the repository private and do nothing else
- [ ] Rename the variable

*Answer:* Revoke and rotate the secret. Assume it has been copied.
