> ## Documentation Index
> Fetch the complete documentation index at: https://unkey.com/docs/llms.txt
> Use this file to discover all available pages before exploring further.

> ## Agent Instructions
> Unkey is two separate products. Compute builds, deploys, and runs apps behind a gateway. API Management issues API keys, enforces rate limits, manages identities and permissions, and reports usage. Say which product a page belongs to; a reader can use either without the other.
> Every Unkey API endpoint is an HTTP POST to https://api.unkey.com/v2/{service}.{procedure} with a root key in the Authorization: Bearer header. Root keys are workspace scoped.
> Error codes have the form err:{system}:{category}:{specific} and each has a page at /errors/{system}/{category}/{specific}.
> The word environment means production or preview in Compute. Rate limiting has four meanings on this site; the glossary lists them.

# GitHub secret scanning

> Learn what happens when a root key leaks into a public GitHub repository.

When an Unkey [root key](/docs/platform/root-keys/overview) is pushed to a public GitHub repository, GitHub tells us and we email everyone in the workspace that owns it. We don't revoke or disable the key. That's up to you.

Only root keys are covered. They all start with `unkey_`. The API keys you issue to your own users use prefixes you choose, so nobody gets emailed about them.

## What happens

<Steps titleSize="h3">
  <Step title="GitHub finds the key">
    GitHub spots a string that looks like an Unkey root key in a public repository and reports it to us with the URL where it was found.
  </Step>

  <Step title="We check it's a live root key">
    If the string matches a root key that exists and hasn't been deleted, GitHub marks the alert as a real leak for the repository owner. Otherwise it's marked as a false positive, and nobody is emailed.
  </Step>

  <Step title="Your team gets an email">
    Every member of the workspace gets one email naming the source and the URL where the key was found, even if GitHub finds the key in several files.
  </Step>
</Steps>

## What you should do

Treat the key as compromised. Anyone could have copied it, so replacing it is the only fix:

1. Under **Settings > Root Keys**, rotate the key with "revoke immediately", or delete it.
2. Update the service that used it.
3. Remove the secret from the repository's history.
