Hush by Umikflow
← Back to Blog
Developer Security5 min read•By Umikflow•Last updated: September 26, 2026

Securely Share API Keys with Remote Developers

API keys give full access to your infrastructure. Learn how to share them safely without committing them to Git.

The API Key Problem

API keys are often as powerful as passwords, sometimes more so. A leaked key can cause catastrophic financial and security damage. A common mistake is committing keys to a Git repository, or sharing them via Slack, leaving a permanent record.

Secrets Management vs. Transmission

There is a difference between long-term team storage and one-off transmission. - Secrets Managers: Tools like Doppler or AWS Secrets Manager are the correct choice for ongoing, team-wide secrets management. - Transmission Tools: If you must send a key to an external contractor or teammate once, you need a safe transmission method like Hush. Hush is not a secrets manager; it is a one-time transmission tool.

API Key Sharing Checklist

  1. Scope Permissions: Never share a master key. Always create a restricted key with the minimum necessary permissions.
  2. Set Expiry Dates: Always configure the API key to expire automatically in your cloud provider.
  3. Test the Scope: Verify the restricted key cannot perform destructive actions before sharing it.

How to Transmit

When using Hush, the key is encrypted in your browser before upload. Once the developer opens the link, the key is destroyed from our servers.

Hush ensures the transmission doesn't leave a permanent log, but remember that a compromised device on either end can still expose the plaintext key. Always revoke keys if you suspect a breach.

Need to share a secret securely?

Hush encrypts your data in the browser before sending it.

Create a Hush Secret