Replit· 9 JunKeeping Your API Keys Safe
Replit scans published Repls for exposed API keys and revokes them.
Safety or policy
Replit describes how it protects users' API keys by scanning published Repls for exposed keys from OpenAI, GitHub, npm, PyPI, Discord, and Sendgrid.
When an exposed key is found, Replit unpublishes the Repl and revokes the key using a method supported by the third-party service.
The post also explains how users should respond to a notification of a revoked key.
From the source
Whenever a Repl is published to our Community, we automatically scan it to make sure that an API key has not been inadvertently included in the Repl’s code. In addition to API keys from OpenAI, we also scan for API keys from a number of other popular service platforms, including GitHub, npm, PyPI, Discord, and Sendgrid.
replit.com