KeyDrift
Free scan

Your Bolt.new app is serving its webhook signing secret to every visitor

Lets an attacker forge webhook events your backend will accept as genuine.

Why Bolt does this

Bolt scaffolds Vite projects inside a WebContainer, where everything runs in the browser by definition. Code that works in the preview keeps the key client-side when it is deployed, because nothing in the generated project ever moved it to a server.

Confirm it first

Before rotating anything, check whether the key is actually being served. Paste your deployed URL — KeyDrift downloads the same JavaScript a visitor gets and tells you what is in it.

No account. Read-only — the scanner only ever issues GET requests, and never stores a key: findings carry a masked prefix and a fingerprint.

Rotate the key

Do this before changing any code. The key has been served to browsers, cached by CDNs and very likely scraped already — removing it from the source does not un-publish it.

  1. 1Roll the key in the Stripe dashboard. Rolling issues a replacement and revokes the old key.
  2. 2Review recent charges, refunds and payouts for anything you did not initiate.
  3. 3Move the Stripe call into a server route. The browser only ever needs the publishable key.
Open the revocation page

Move the call to a server

The replacement key must not follow the old one into the bundle, which means the code that uses it cannot live in the browser. Any variable named VITE_ is inlined at build time by design — the prefix is the mechanism, not a mistake.

Before — shipped to the browser

// src/components/Chat.tsx
// Vite substitutes the literal value here at build time.
const key = import.meta.env.VITE_STRIPE_SECRET_KEY;
const result = await new Stripe(key).checkout.sessions.create(body);

After — stays on a serverless function on your deploy target

// supabase/functions/checkout/index.ts  — runs on a serverless function on your deploy target
Deno.serve(async (request) => {
  const key = Deno.env.get('STRIPE_SECRET_KEY')!; // never sent to the browser
  const result = await new Stripe(key).checkout.sessions.create(body);
  return Response.json(result);
});

// src/components/Chat.tsx
const result = await fetch('/functions/v1/checkout', { method: 'POST' }).then((r) => r.json());

How KeyDrift detects it

Matches the `whsec_` prefix. Often overlooked because it is not an API key — but it is the only thing standing between your endpoint and forged events.

It will happen again

Bolt scaffolds Vite projects inside a WebContainer, where everything runs in the browser by definition. That has not changed because you fixed this one file — the next feature request produces the same shape of code. Continuous monitoring re-scans every deploy and tells you the moment a key comes back.