ProphetKey Security Research · 2026
API Key Exposure Report 2026
28.6M+ secrets leaked on public GitHub in 2025. AI-service key leaks up 81%. The year AI adoption changed software engineering — and made API key leaks worse.
The short answer
Because this question keeps coming up: yes, API keys leak at scale. GitGuardian detected 28.6M+ new secrets in public GitHub commits in 2025 — up 34% year-over-year — and AI-service credentials were the fastest-growing category, up 81%. The problem is not whether a key will leak; it is whether yours already has.
Key findings
Secrets sprawl is accelerating faster than developers
Secrets have been growing about 1.6x faster than the active developer population since 2021. Public commits grew 43% in 2025, and leaked secrets grew with them — GitHub now hosts 4.6% repos containing at least one secret.
Source: GitGuardian State of Secrets Sprawl 2026
AI assistance doubled the leak rate
Claude Code-assisted commits leaked secrets at ~3.2%, roughly double the ~1.5% GitHub-wide baseline across 2025. More code being written faster means more tokens, keys, and service identities embedded without equivalent governance.
Source: GitGuardian State of Secrets Sprawl 2026
AI service keys are the fastest-growing leak category
Leaks tied to AI services rose 81% year-over-year to 1,275,105 secrets. AI-service credentials are more likely to slip past protections built for conventional developer workflows because they lack standardized prefixes.
Source: GitGuardian State of Secrets Sprawl 2026
The new leak vector: MCP and agent config files
As MCP became the standard way to connect LLMs to external APIs, researchers found 24,008 unique secrets exposed in MCP configuration files. Top types: Google API keys (19.2%), PostgreSQL connection strings (14%), Firecrawl keys (11.9%), Perplexity.ai API keys (11.2%), and Brave Search keys (11%).
Source: GitGuardian State of Secrets Sprawl 2026
Leaked keys stay usable for years
70% of secrets leaked in 2022 were still valid in 2024. By 2026, 64% of those valid secrets still had not been revoked. A single unrevoked key is an open door.
Source: GitGuardian State of Secrets Sprawl 2025 & 2026
Secrets managers do not stop sprawl
A study of 2,584 repositories using secrets managers found a 5.1% leakage rate — higher than the 4.6% public GitHub average. Secrets get copied out of managers and hardcoded elsewhere.
Source: GitGuardian State of Secrets Sprawl 2025
Where secrets leak
Secrets sprawl extends well beyond code repositories. Roughly 28% of incidents originate from collaboration and productivity tools — Slack (2.4% of analyzed channels contained leaked secrets), Jira (6.1% of tickets), and container registries (7,000+ valid AWS keys exposed on Docker Hub).
| Leak vector | Measured exposure |
|---|---|
| Public GitHub commits (2025) | 28.6M+ new secrets · +34% YoY |
| AI-service credentials (2025) | 1.28M+ · +81% YoY |
| MCP configuration files (2025) | 24,008 unique secrets |
| Claude Code-assisted commits (2025) | ~3.2% leak rate vs. ~1.5% baseline |
| Public repos with ≥1 secret (2024) | 4.6% |
| Repos with secrets managers that still leaked (2024) | 5.1% |
| Valid 2022 secrets never revoked (2026) | 64% |
How to actually protect your keys
- Encrypt keys locally, never in config files. Plaintext keys in
.env, MCP configs, or agent setup files are exactly what automation scans for. - Use per-tool virtual keys. When one leaks, rotate the virtual key — your real provider key stays untouched.
- Treat any exposed key as compromised. Since 64% of valid leaked secrets are never revoked, assume attackers have already copied it.
- Monitor for your own keys. Public-repo scanning catches accidental commits the moment they ship.
Sources
- GitGuardian — State of Secrets Sprawl 2026
- GitGuardian — State of Secrets Sprawl 2025
- Verizon — Data Breach Investigations Report 2024
- IBM — Cost of a Data Breach
FAQ
How many API keys leak every year?
28.6M+ new secrets were detected in public GitHub commits in 2025 (GitGuardian State of Secrets Sprawl 2026), a 34% increase over 2024. In 2024 the figure was 23.8M.
Are AI-generated or AI-assisted projects more likely to leak API keys?
Yes. Claude Code-assisted commits leaked secrets at ~3.2% in 2025, roughly double the ~1.5% GitHub-wide baseline. AI-service key leaks specifically surged 81% year-over-year.
Do API keys leak through MCP or AI agent configuration files?
Yes. GitGuardian found 24,008 unique secrets exposed in MCP configuration files in 2025, including Google API keys (19.2%), Firecrawl keys (11.9%), and Perplexity.ai API keys (11.2%).
How long do leaked API keys stay usable?
70% of secrets leaked in 2022 were still valid in 2024, and 64% of valid secrets from 2022 were still not revoked by 2026 (GitGuardian). Leaked keys routinely remain active for years.
Do secrets managers prevent API key leaks?
No. Repositories using secrets managers leaked at 5.1% in 2024 — higher than the 4.6% GitHub-wide average (GitGuardian), because secrets are extracted from managers and hardcoded elsewhere.
How can developers protect their API keys?
Store keys in a vault encrypted locally (XChaCha20-Poly1305 + Argon2id), never paste them into config or MCP files, use per-tool virtual keys so a leaked key can be rotated without reissuing the real one, and monitor public code for your own keys.