Skip to main content
When an Unkey root key is pushed to a public GitHub repository, GitHub tells us and we email everyone in the workspace that owns it. We don’t revoke or disable the key. That’s up to you. Only root keys are covered. They all start with unkey_. The API keys you issue to your own users use prefixes you choose, so nobody gets emailed about them.

What happens

1

GitHub finds the key

GitHub spots a string that looks like an Unkey root key in a public repository and reports it to us with the URL where it was found.
2

We check it's a live root key

If the string matches a root key that exists and hasn’t been deleted, GitHub marks the alert as a real leak for the repository owner. Otherwise it’s marked as a false positive, and nobody is emailed.
3

Your team gets an email

Every member of the workspace gets one email naming the source and the URL where the key was found, even if GitHub finds the key in several files.

What you should do

Treat the key as compromised. Anyone could have copied it, so replacing it is the only fix:
  1. Under Settings > Root Keys, rotate the key with “revoke immediately”, or delete it.
  2. Update the service that used it.
  3. Remove the secret from the repository’s history.
Last modified on September 29, 2026