Launch offer: the first 1,000 users get Settl free for a year*Claim your spot
settlbuilding in public

Respond to Leaked Secrets and Reduce API Key Blast Radius

Deleting a secret from the latest commit does not revoke it. A leaked key and an overpowered key are two halves of the same credential problem: exposure time multiplied by blast radius.

This guide belongs to reel R084. Comment SECRET or LEASTPRIV for the matching module and runnable starter.

Define the boundary before building

Input: credential type, leak location, provider audit events, current scopes, allowed resources, environments, rotation support, and credential owner.

Output: a leaked-secret response runbook, least-privilege scope plan, rotation evidence, exposure findings, and prevention checks.

The starter keeps exact checks in code and gives Claude only the reviewable drafting work. Dry-run is the default. Live mode can call Anthropic's Messages API, but it still returns a draft and performs no external action.

Paste this boundary into Claude Code before asking for implementation:

Workflow: Respond to Leaked Secrets and Reduce API Key Blast Radius
Input: credential type, leak location, provider audit events, current scopes, allowed resources, environments, rotation support, and credential owner
Output: a leaked-secret response runbook, least-privilege scope plan, rotation evidence, exposure findings, and prevention checks

Map the trigger, strict input fields, deterministic code checks, Claude drafting step, approval gate, failure queue, and saved evidence. Use null for missing facts. Do not change code or call an external service yet.

The modules that matter

R084 leaked-secret response

Revoke or rotate first. Record the earliest possible exposure, search provider audit logs for use, update every dependant, and prove the old credential fails. Rewrite Git history only when the repository owner has a coordinated reason to do it.

R086 least-privilege key design

Give each environment and workload its own credential. Restrict actions, resources, network source, expiry, and spend where the provider supports them. Name the owner and rotation path before issuing the replacement.

Prevention after recovery

Add pre-commit and CI secret scanning with a fictional canary, keep real values out of logs and workflow exports, and document the emergency rotation command somewhere operators can reach without the compromised system.

Rules worth keeping beside the code

The dangerous version is treating git deletion as revocation, exposing secret values in logs, rotating without updating dependants, or creating one unrestricted key for every service. The pack deliberately stops at a draft so a person can inspect those boundaries before enabling anything real.

Test the ugly paths

The final verification is concrete: Prove the old credential is rejected, the replacement can perform only the required operation, forbidden operations fail, and automated secret scanning catches a fictional canary.

Use this prompt to turn the evidence into acceptance tests:

Design tests for Respond to Leaked Secrets and Reduce API Key Blast Radius using only the attached fictional fixtures.
Cover the normal path, missing input, malformed input, a repeated event, a permission failure, a dependency failure, and the named safety boundary.
For each test return: input, expected state, prohibited side effect, and evidence to save.
Do not execute external actions.

Run the pack locally

The ZIP is a complete Node 22 starter with no third-party npm dependency. It includes an importable n8n webhook, Docker Compose, GitHub Actions validation and manual-run workflows, deterministic samples, and tests.

npm test
npm run validate
npm run sample
cp .env.example .env
docker compose up --build

Only set WORKFLOW_MODE=live, ANTHROPIC_API_KEY, and ANTHROPIC_MODEL after the dry-run output and tests make sense for your system. Keep real secrets in the environment, never in the n8n export.

Download the runnable pack

Start with the fictional dry-run. It validates the input and returns a reviewable draft without changing code, production data, customer accounts, or an external service.

Before enabling a real action

Replace every fictional fixture, assign the approval owner, define the duplicate key, set a timeout and retry rule, and save the original evidence. Then test one failure on purpose. If the workflow cannot stop visibly and replay safely, it is not ready to act.

Get the next one in your inbox