Blog
What your build actually ships
Writing from KeyDrift on client-side secret exposure, build-time environment variables, and the difference between a key that leaked and one that belongs there.
The false-positive problem: why scanners get ignored
Alert fatigue mechanics, the placeholder paradox, and the signal engineering that keeps leak-detection channels trusted instead of muted.
12 min readLLM API keys in the wild: the cost-abuse mechanics
What OpenAI- and Anthropic-class keys expose — spend, quota, stored data — plus the caps and org controls that bound damage, and downtime-free rotation.
12 min readHow keys migrate from .env into source in AI workflows
The paste-and-iterate loop traced step by step: how assistants move secrets from environment files into bundles through diffs nobody thinks to question.
12 min readWhat a leaked Stripe key can do: permission by permission
Secret vs restricted vs publishable, live vs test — the exact capability differences from Stripe's own docs, plus the rotation path that limits downtime.
12 min readScanning versus monitoring: why point-in-time isn't enough
A scan certifies one artifact at one moment. Deploys create new artifacts continuously — here's the drift argument for continuous detection.
12 min readWhat a prompt-built app actually deploys
We built a small application from a prompt, deployed it, and read every file the browser received. Three strings were worth looking at. Only one of them mattered.
aisecrets4 min readGit history: why deleting the file never deletes the key
Git's object model makes removal impossible by design: blobs survive deletion, rewrites, force-pushes, and GC. Rotation is the only real fix.
13 min readSix ways a secret reaches a Next.js client
Six routes by which a server-side value ends up in a Next.js client bundle, including four that never involve the NEXT_PUBLIC_ prefix at all.
nextjsbundles6 min readSource maps: the file you forgot you published
A source map reconstructs your original code from the minified bundle, comments and all. If it is served in production, so is everything the minifier removed.
bundlesbuilds4 min readI found a key in my bundle. What now?
Rotate first. The string is already public, removing it from the next deploy changes nothing about that, and the order of the four steps after it matters.
incidentrotation4 min readSupabase keys: anon versus service-role, and the blast radius of each
Why the anon/publishable key is public only while RLS actually enforces policies, and why service-role exposure is total — with tests for both.
13 min readFive searches that tell you what you are shipping
A manual check you can run on any deployed site with nothing but a browser — five searches, what each one finds, and how to tell a real finding from a false positive.
bundleshowto5 min readThe anon key and the service_role key
One is a public identifier constrained by row-level security. The other bypasses every policy you have ever written. They look almost identical.
supabasesecrets5 min readBrowser bundles: how secrets end up in JavaScript your users download
The exact mechanisms — framework prefixes, compile-time substitution, source maps — plus a five-minute procedure to audit your own bundle.
13 min readA field guide to credential prefixes
The credential formats you will find in a JavaScript bundle — what each prefix means, what it grants, and whether it belongs in a browser at all.
secretsreference7 min readWhat NEXT_PUBLIC_ actually does
NEXT_PUBLIC_ is not a security feature. It is a build instruction that writes the literal value into the JavaScript you serve, and the consequences follow from that one fact.
nextjsbundles5 min readYour AI just put a secret key in the browser
Six moments between a failing query and a credential on a CDN. At every one of them, every tool involved reported success.
secretsai5 min readThe open-source secret scanner landscape
trufflehog, gitleaks, and detect-secrets compared by detection approach: verification versus rules versus baselines, and their shared blind spot.
12 min readSecret-leak incident response: the first hour and the first day
A working runbook — contain, decide revoke-vs-overlap, assess usage from provider logs, handle downstream secrets, document honestly.
13 min readNEXT_PUBLIC_ and friends: the framework conventions that publish your config
The definitive guide to public-by-prefix environment conventions across major frameworks — the mechanism, the promise, and the accidents.
12 min readThe key-rotation playbook: provider by provider, downtime-free
The dual-key overlap pattern generalized, then applied provider by provider with verification steps: credential rotation without downtime.
13 min readClean repo, leaky build: the definitive guide
How secrets that never appear in git end up in production JavaScript: bundler inlining, source maps, and deploy artifacts — with a demo you can run.
13 min readYour .env file is not the problem
Git-ignoring your environment file protects the repository, not the bundle. Here is what actually ends up in the JavaScript you serve.
secretsbundles4 min read