# Responding to a Leak — 1Password and Secrets Hygiene for Developers

Source: https://www.geekswithgeeks.com/en/secrets-hygiene/leak-incident-response

> Follow the right order: revoke, replace, investigate, then clean up.

## Revoke first

The moment a secret is public, assume bots have it; they scan new commits within minutes. So the first step is to **revoke or rotate** the secret. Cleaning Git history or deleting the repo comes later because it does not make the old value safe.

## Incident checklist

Write the times down; they help the investigation and the post-incident review.

```text
1. Revoke or rotate the exposed secret NOW
2. Deploy the new value to every system that used it
3. Check provider logs for use of the old key
4. Remove it from the repo and history (git filter-repo)
5. Add a scanner rule so it cannot happen again
6. Write a short blameless note: what, when, how fixed
```

## Blameless review

Fear makes people hide leaks. Treat reports as helpful and ask what process failed, not who failed. Fast reporting limits the damage.

**Quiz:** You find an API key pushed to a public repo. What is the first action?

- [ ] Rewrite Git history
- [ ] Delete the repository
- [x] Revoke or rotate the key
- [ ] Post about it in chat

*Answer:* Revoke or rotate the key. Until the key is revoked, anyone who copied it can still use it.
