# GitGuardian/APISecurityBestPractices

Resources to help you keep secrets (API keys, database credentials, certificates, ...) out of source code and remediate the issue in case of a leaked API key. Made available by GitGuardian.

Repository: https://github.com/GitGuardian/APISecurityBestPractices
Canonical: https://ross.abutalabs.com/products/apisecuritybestpractices
Homepage: https://www.gitguardian.com
License: NOASSERTION
License Family: other
Topics: api, keys, leaked, security, security-tools
Last push: 2019-07-08T17:23:17+00:00

## Health v2 (maintenance only)
Score: 32/100 (v2, computed 2026-09-03T02:20:16.233290+00:00)
- activity 0, release rhythm 35, longevity 100
- inputs: {"age_days": 3036, "days_push": 2613, "days_rel": null, "gap_med": null, "n_releases_24m": 0}
- flags: no_releases, no_license
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 1980, forks 97 (observed 2026-08-28T04:06:01.720501+00:00)

## What it is
A curated collection of guides and checklists from GitGuardian on keeping secrets like API keys, database credentials, and certificates out of source code, plus a leak mitigation checklist for remediating exposed credentials. It is educational documentation rather than a runnable tool.

## Use cases
- how to keep api keys out of source code
- what to do after leaking an api key on github
- secrets management best practices for developers
- checklist for remediating leaked credentials
- how to prevent committing database credentials to git
- guide to securing api tokens in repositories

## When to choose
- you want to learn or teach secure secrets-handling practices
- you need a step-by-step checklist to respond to a leaked credential
- you want vendor-backed reference material on secrets sprawl

## When to avoid
- you need an actual scanning tool - use GitGuardian's ggshield CLI or platform instead
- you want runnable open-source software rather than documentation
- you need vendor-neutral or standards-based guidance only

## Facets
- artifact type: learning-resource
- maturity: maintenance
- function: security, documentation, developer-tools
- domain: security, developer-tools, apis
- platform: cross-platform
- tags: secrets-management, api-keys, leak-remediation, best-practices, checklist, gitguardian

## Member repositories
- GitGuardian/APISecurityBestPractices (main) score 32

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:06:01.720501+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T03:03:59.573348+00:00, confidence not recorded.
  - readme: https://github.com/GitGuardian/APISecurityBestPractices (fetched 2026-08-28T04:06:01.720501+00:00, sha 347d4e783e87)
  - homepage: https://www.gitguardian.com (fetched 2026-08-29T10:43:57.178936+00:00, sha dd85e3d8c054)
  - site_page: https://www.gitguardian.com/about-us (fetched 2026-08-29T10:43:57.188035+00:00, sha 21022ae64ad9)
  - site_page: https://docs.gitguardian.com/ (fetched 2026-08-29T10:43:57.190714+00:00, sha 951b7cd32322)
  - site_page: https://api.gitguardian.com/docs (fetched 2026-08-29T10:43:57.192644+00:00, sha d19b9ee52779)
  - site_page: https://www.gitguardian.com/integrations (fetched 2026-08-29T10:43:57.181747+00:00, sha 3450bd0c36f3)
  - site_page: https://www.gitguardian.com/pricing (fetched 2026-08-29T10:43:57.183507+00:00, sha ee1d82d33483)
  - site_page: https://www.gitguardian.com/faq (fetched 2026-08-29T10:43:57.185525+00:00, sha d5dcc376f555)
- Data as of 2026-08-30T08:39:29.467469+00:00.
