What it is
Bot tokens, database passwords and API keys are kept apart from the code: in a .env file on the server or inside the service itself. The code can then be shown or handed over without exposing access.
How we use it
Gemini keys and bot tokens are set in .env, and in n8n workflows the keys live in n8n itself, not in the workflow file. Our apps mask subscription links, keys and tokens on the device before a log is sent to the developer.
Where it matters to a business
- The project code is handed to another developer or shown to someone, and access credentials must not leak with it.
- A backup or a log must not contain passwords.
- A bot token or API key is compromised and has to be changed within minutes, without a new release.
How we use it
.env on the server. The bot token and admin ID in the birthday bot come from the environment, and Gemini keys and model lists in the finance assistant from .env, not from the code.- Keys inside the service. In n8n keys and tokens live in n8n itself, not in the workflow file.
- Nothing extra in git. In the network survey
.gitignore keeps keys, access configurations and dumps out of the repository, and service passwords are described in words. - Encryption in the database. In the IT help desk registry passwords are stored as ciphertext with the key only in the server environment: a weekly database dump goes to Telegram, and without encryption the passwords would travel in plain text.
- Masking in reports. Our apps replace subscription links, keys, UUIDs, passwords and tokens with placeholders on the device as the log is written: see the report receiver.
Common problems
- Settings in the code. In one of our bots, moving settings into
.env is still to be done; it is on the plan, not forgotten. - A secret in git history. A key that got into a repository stays in its history; it has to be rotated, not just deleted from the file.
When you do not need it
A static page with no forms or integrations has no secrets, and no .env either.