criticalexposed-stripe-secretchecked on every page we scan

Stripe Secret Key Exposed

A live secret key for your payment provider is readable in your public JavaScript.

Why it matters

A live secret key for your payment provider is readable in your public JavaScript. Note that this key prefix (sk_live_) is used by BOTH Stripe and Clerk, so check which of the two it belongs to and rotate it there. Either way it grants live API access under your account: with Stripe that means reading customer records and payment history and moving money; with Clerk it means full control of your user directory, including impersonating any user.

How ShipReady detects it

Detects credentials that reached the browser. Scans the page HTML and every linked JavaScript bundle for the literal shapes real provider keys take — `sk_live_`, `AKIA`, `ghp_`, a JWT with a service_role claim — rather than guessing from entropy. High-entropy string detection finds build hashes, CSS class names and base64 images on almost every site; provider prefixes are unambiguous, which is why this check reports only what it can name. A match is evidence, not inference: the value was served to anyone who loaded the page. Evidence records the variable NAME and a ten-character prefix, never the key, because a report that quoted the secret would republish it. Bundles are fetched once per scan and shared across pages, so a key present in a chunk loaded on ten routes is reported once.

Detection is deterministic. ShipReady reports this only when it observes the condition directly, and prefers to miss a real problem over inventing one. Rule version 1.4.0.

How to fix it

This is the prompt ShipReady puts in your report — written to be pasted straight into Cursor, Claude Code, or whichever assistant built the app.

Rotate this key first — it is public and automated scrapers find keys in JavaScript bundles within minutes. The sk_live_ prefix is used by BOTH Stripe and Clerk, so identify which it is: for Stripe, go to Dashboard -> Developers -> API keys and roll the secret key; for Clerk, go to Dashboard -> API keys and regenerate the secret key. Then move the key out of the browser entirely: keep only the publishable key (pk_live_ for Stripe, pk_live_ for Clerk) in frontend code, and call the provider from a server route, route handler, or server action that holds the secret key.

Frequently asked questions

What does "Stripe Secret Key Exposed" mean?
A live secret key for your payment provider is readable in your public JavaScript.
How serious is it?
ShipReady rates this critical. Fix before launch. On its own, this is enough to compromise the application.
How do I fix it?
Paste the fix prompt on this page into Cursor, Claude Code or your AI editor. It is the same prompt ShipReady puts in your report.
Can I check my own site?
Yes — ShipReady scans up to ten pages of any public site for free and reports this alongside every other check.

Related checks

Does your site have this?

ShipReady checks this and 73 other things across up to ten pages of your site. Free, no signup.

Scan my site