DEV Community

Divinelab.io
Divinelab.io

Posted on

How to Automatically Redact Leaked API Keys and .env Files at the Edge

Every developer dreads accidental secret exposure: a debug route left enabled that dumps an unredacted .env file, an uncaught database connection error that exposes credentials in a stack trace, or an internal API returning private keys to the browser.

Most Web Application Firewalls only inspect inbound requests. But protecting your backend also requires inspecting outbound responses before they leave the network.

In this tutorial, we are going to use Aegis—an open-source, self-hosted Web Application Firewall (WAF) and reverse proxy—to configure native Sensitive Data Leak Protection (DLP) and automatically redact leaked API keys, tokens, and environment variables in real time.

Aegis WAF Core


Step 1: Access Leak Protection Settings

  1. Open your Aegis Admin Console at http://server-ip:8081.
  2. In the left navigation menu, navigate to WAF Core > Leak Protection.
  3. Toggle on Enable Leak Protection.

Aegis will now stream outbound HTTP response bodies from your origin servers through in-memory pattern validators.


Step 2: Choose Your Response Action

Select how Aegis handles detected credentials and secrets:

  • Redact Matches (redact) — Recommended: Replaces sensitive values with [REDACTED] in the response stream. The web page continues to function for the user, but the secret is scrubbed before leaving the network.
  • Block Responses (block): Immediately halts delivery and returns an HTTP 403 Forbidden with a generic security block page. Best for strict regulatory environments (PCI-DSS, HIPAA).
  • Monitor Only (detect): Permits the response while logging an alert to security telemetry for auditing.

Click Save to apply the policy in memory.


Step 3: Test Real-Time Secret Redaction

Imagine an origin backend accidentally prints an AWS key or database URI in an API response:

{
  "status": "success",
  "data": {
    "provider": "aws",
    "access_key": "AKIAIOSFODNN7EXAMPLE"
  }
}
Enter fullscreen mode Exit fullscreen mode

Send a request through the Aegis proxy with Redact enabled:

curl -s http://localhost:8080/api/config
Enter fullscreen mode Exit fullscreen mode

Response received by the client:

{
  "status": "success",
  "data": {
    "provider": "aws",
    "access_key": "[REDACTED]"
  }
}
Enter fullscreen mode Exit fullscreen mode

The credential is neutralized at the network edge without requiring any code modifications or redeployments to your backend application.


Step 4: Configure Scoped Exceptions for Sandboxes

If you have specific diagnostic endpoints or test environments that legitimately need to return mock tokens:

  1. Click the Allowlist Exceptions tab.
  2. Click + Add Exception.
  3. Specify the URL path (e.g., /api/v1/sandbox/*).
  4. Set an optional expiration date.
  5. Click Save Exception.

The exception applies immediately in memory with zero service restarts.


Resources

The Community Edition is free to self-host:

Top comments (0)