The API Key Problem
API keys are often as powerful as passwords, sometimes more so. A leaked key can cause catastrophic financial and security damage. A common mistake is committing keys to a Git repository, or sharing them via Slack, leaving a permanent record.
Secrets Management vs. Transmission
There is a difference between long-term team storage and one-off transmission. - Secrets Managers: Tools like Doppler or AWS Secrets Manager are the correct choice for ongoing, team-wide secrets management. - Transmission Tools: If you must send a key to an external contractor or teammate once, you need a safe transmission method like Hush. Hush is not a secrets manager; it is a one-time transmission tool.
API Key Sharing Checklist
- Scope Permissions: Never share a master key. Always create a restricted key with the minimum necessary permissions.
- Set Expiry Dates: Always configure the API key to expire automatically in your cloud provider.
- Test the Scope: Verify the restricted key cannot perform destructive actions before sharing it.
How to Transmit
When using Hush, the key is encrypted in your browser before upload. Once the developer opens the link, the key is destroyed from our servers.
Hush ensures the transmission doesn't leave a permanent log, but remember that a compromised device on either end can still expose the plaintext key. Always revoke keys if you suspect a breach.