How to Automatically Redact Leaked API Keys and .env Files at the Edge
Every developer dreads accidental secret exposure: a debug route left enabled that dumps an unredacted .env file, an uncaught database connection error that exposes credentials in a stack trace, or an internal API return
Every developer dreads accidental secret exposure: a debug route left enabled that dumps an unredacted .env file, an uncaught database connection error that exposes credentials in a stack trace, or an internal API returning private keys to the browser.
Most Web Application Firewalls only inspect inbound requests. But protecting your backend also requires inspecting outbound responses before they leave the network.
In this tutorial, we are going to use Aegisβan open-source, self-hosted Web Application Firewall (WAF) and reverse proxyβto configure native Sensitive Data Leak Protection (DLP) and automatically redact leaked API keys, tokens, and environment variables in real time.
Step 1: Access Leak Protection Settings
- Open your Aegis Admin Console at
http://server-ip:8081. - In the left navigation menu, navigate to WAF Core > Leak Protection.
- Toggle on Enable Leak Protection.
Aegis will now stream outbound HTTP response bodies from your origin servers through in-memory pattern validators.
Step 2: Choose Your Response Action
Select how Aegis handles detected credentials and secrets:
-
Redact Matches (
redact) β Recommended: Replaces sensitive values with[REDACTED]in the response stream. The web page continues to function for the user, but the secret is scrubbed before leaving the network. -
Block Responses (
block): Immediately halts delivery and returns anHTTP 403 Forbiddenwith a generic security block page. Best for strict regulatory environments (PCI-DSS, HIPAA). -
Monitor Only (
detect): Permits the response while logging an alert to security telemetry for auditing.
Click Save to apply the policy in memory.
Step 3: Test Real-Time Secret Redaction
Imagine an origin backend accidentally prints an AWS key or database URI in an API response:
{
"status": "success",
"data": {
"provider": "aws",
"access_key": "AKIAIOSFODNN7EXAMPLE"
}
}
Send a request through the Aegis proxy with Redact enabled:
curl -s http://localhost:8080/api/config
Response received by the client:
{
"status": "success",
"data": {
"provider": "aws",
"access_key": "[REDACTED]"
}
}
The credential is neutralized at the network edge without requiring any code modifications or redeployments to your backend application.
Step 4: Configure Scoped Exceptions for Sandboxes
If you have specific diagnostic endpoints or test environments that legitimately need to return mock tokens:
- Click the Allowlist Exceptions tab.
- Click + Add Exception.
- Specify the URL path (e.g.,
/api/v1/sandbox/*). - Set an optional expiration date.
- Click Save Exception.
The exception applies immediately in memory with zero service restarts.
Resources
The Community Edition is free to self-host:
- Aegis GitHub Repository: https://github.com/divinelabio/aegis
- Documentation: https://divinelab.io/products/aegis/docs/waf-core/leak-protection
Originally published by Dev.to Security. Aggregated on AIWithGhost for educational purposes β full credit and traffic to the original publisher.