sk_live_ found in frontend JavaScript — severity and response
Any sk_live_ string reachable from the browser is a full account compromise. Rotate now; verify with a free scan.
One string separates your payment infrastructure from everyone else’s curiosity. This page is deliberately short on drama and long on order of operations.
What the Stripe live secret key is
sk_live_ is Stripe’s full-access secret key for live mode — the credential server code uses to charge cards, refund payments, and read customer records.
sk_live_FAKE000000000000000000000
Prefix family matters at a glance: rk_live_ (restricted), pk_live_ (publishable, browser-safe), sk_test_ (test mode). The first characters decide severity; scanners check them first for good reason.
What it grants
Holding this key equals holding the dashboard for money movement:
- Create charges and payment intents.
- Issue refunds to any payment.
- Read customer objects and PII attached to them.
How it ends up in a bundle
Three arrival routes cover nearly every case we see:
- A client component attempted direct API calls and gained the prefix to compile.
- Copy-paste from a backend snippet during debugging stayed past review.
- Template/starter shipped a demo checkout wired with real env names.
Does it belong in a browser?
Never legitimate in a browser. Publishable keys exist precisely so secret ones never need to travel client-side.
Rotate it
dashboard.stripe.com/apikeys → Create new secret key → deploy all server consumers → revoke exposed key. Sequence preserves uptime while closing exposure.
Find it in seconds
Open DevTools on the deployed site and search the built assets for sk_live_. If the search hits, the credential shipped; if it does not, check the chunks loaded on authenticated or interactive views, not just the landing page — the calling code often sits behind a route.
Manual searching proves one page on one day. KeyDrift fetches the deployment the way a browser would, follows chunks named only in route manifests, reads streamed hydration payloads, and classifies what it finds — secret, or public-by-design — so an anon key never shows up dressed as an emergency.
Make sure it stays gone
One more thing worth knowing before you close the tab: fixing this once does not end the story. Agents imitate whatever pattern is already in the repo, templates carry their own defaults, and the next feature request can reintroduce the same shape of code. Continuous monitoring re-scans every deploy and alerts only on change — new, regressed, resolved — so the comeback attempt is a notification instead of a quarter-end surprise.
The bigger picture
Zoom out and the pattern is bigger than one repo. AI-assisted output has outgrown review capacity everywhere at once, which means thousands of teams are making the same reasonable-looking tradeoffs in the same week. Nobody using modern tooling is uniquely exposed. The failure mode documented above is the modal outcome of velocity without verification, not evidence of carelessness.
How KeyDrift reports this exact finding
Report anatomy matters during incidents, so it is worth reading once calmly: masked string (never the live value — it ceases to exist outside the detection engine), salted fingerprint (trackable within your workspace, useless to strangers), chunk path (your starting point for a "git log -S" hunt), disposition (secret versus public-by-design), confidence (matches below 0.5 never reach the page at all).
Manual check, step by step
The full manual drill, for readers who want zero dependence on any tool: open the deployed site in a private window; launch DevTools → Sources; use Search-all-files (Ctrl/Cmd+Shift+F) for sk_live_; then repeat for the other marker families — eyJ, sk_live_, sk-proj-, AKIA, postgres, BEGIN PRIVATE KEY. Decode anything JWT-shaped before reacting, and classify public-by-design formats as expected guests rather than intruders.
Close the loop with monitoring
If you take one operational step from this page, make it this: put the URL under continuous monitoring (free tier covers one project daily). The first scan tells you whether you have a problem today; the schedule tells you whether the problem comes back next month after someone re-adds the convenient line.
Common questions
Found rk_live_ instead?
Scoped but serious — see the restricted-key page for permission inventory before rotating.
Was it used?
Stripe event exports answer that; audit before/after rotation windows.
Run a free scan at keydrift.dev/scan — paste a URL or the bundle source itself, no account. Findings arrive masked, with the exact chunk they live in.