# What Counts as a Secret — 1Password and Secrets Hygiene for Developers

Source: https://www.geekswithgeeks.com/en/secrets-hygiene/sh-what-is-secret

> Identify passwords, API keys, tokens and private keys, and tell them apart from ordinary configuration.

## Anything that grants access

A **secret** is a value that gives access to something: a password, an API key, an access token, a database connection string with a password, or a private key. If someone else holding it could act as you, it is a secret.

## The life of a secret

A secret is created, stored, used and eventually rotated or revoked. Leaks happen at every stage.

![Four stages: create, store, use, rotate.](assets/figures/secrets-hygiene/section-1-map.svg) — Figure 1.1 — Create, store, use, rotate.

## Config or secret?

The port number is ordinary config and is safe to commit. The password and key are secrets and must live somewhere else.

```bash
PORT=3000                 # config: safe to commit
DB_PASSWORD=...           # secret
STRIPE_SECRET_KEY=sk_...  # secret
APP_NAME=shop             # config
```

## House keys

Your house address is public information, like config. The key is a secret. You would not tape a spare key to the front door, yet pasting a key into a public repo does the same thing.

**Quiz:** Which of these is a secret?

- [ ] The app's display name
- [x] A cloud API access token
- [ ] The HTTP port number
- [ ] The log level

*Answer:* A cloud API access token. A token grants access to a service. Names, ports and log levels do not.
