for apps built with Replit

Built it with Replit?
Let's check what it shows strangers.

Replit apps usually come with a real server (Express, Flask, FastAPI) behind the pages. That is a lot of power, and a few more places for a key or a loose setting to slip out. We check the live app and the GitHub repo your Repl syncs to.

Free for one app. No card, no install.

what usually goes wrong

Where Replit apps leak

Keys in the code, not in Secrets

Replit's Secrets pane keeps keys on the server. A key typed into the code does not stay put: it ends up in the repo, and sometimes in the front-end files every visitor downloads.

live app + repo: hard-coded secret keys

Code that is more public than you think

If a Repl or its GitHub repo is public, anyone can read the source, so any key written into it is everyone's key. Connect the repo and we look for them file by file, with the line number.

repo: committed secrets and .env files

Express CORS left wide open

cors({ origin: true, credentials: true }) lets any website call your API with your users' cookies attached. A page they visit somewhere else could read their data through your server.

repo: CORS open to any origin with credentials

Server shortcuts agents take

Routes that change data without checking who is calling, login tokens read without checking their signature, Stripe webhooks that anyone could fake. We flag them in your server code.

repo: risky code patterns

the fix is a prompt

Worded for Replit Agent

Replit Agent is good at reworking server code when the prompt says exactly what to change. Like this:

criticalrepo-secrets.stripe-secret-key

Stripe secret key committed to your code

A live Stripe secret key is written into a server file instead of being kept in Replit's Secrets pane, so anyone who can see the repo can use it.

file
server/payments.ts
line
7
key
sk_live_51H…a9Q

Rotate the key in your Stripe dashboard first. Removing it from the code does not remove it from the repo's history.

Paste into Replit Agent click to select

Security fix: my Stripe secret key is hard-coded in server/payments.ts.
Read it from an environment variable named STRIPE_SECRET_KEY instead, and tell me to add that name in the Secrets pane (I will paste the new key there myself).
Remove the key from every file, including any .env file in the project. Do not change anything else.

then rescan to confirm it is gone

verify your app

Proving it is yours, on Replit

On Replit it depends on how your app serves files, so the prompt asks the agent for both the file and the meta tag. Either one is enough.

  • Paste the prompt into Replit Agent. We give you yours, with your own token, when you add the app.
  • Redeploy. Deployments serve a snapshot, so the file only shows up after you deploy again.
  • Got your home page back instead of the file? Your server answers every path with the app. Ask the agent to serve /.well-known/vibeprotect.txt as plain text, or rely on the meta tag.
Paste into Replit Agent click to select

Add a site verification for VibeProtect. Create the file public/.well-known/vibeprotect.txt containing exactly this single line:
vibeprotect-verify=3kQ9xZr1VbN0aT7mYw2cLp8e
Also add this tag inside <head> in index.html (or the root layout's metadata):
<meta name="vibeprotect-verification" content="vibeprotect-verify=3kQ9xZr1VbN0aT7mYw2cLp8e" />
Do not change anything else.

Your real token is in the app once you add it. The file ends up at /.well-known/vibeprotect.txt.

questions

Replit questions

Do you read my Secrets pane?

No. We never see your Secrets. We look at what your live app serves to anyone, and, if you connect it, what is committed to the GitHub repo.

Which address should I add?

The one your users visit: your .replit.app deployment or your custom domain. Workspace preview addresses change and go to sleep, so a deployment is the better target.

My app is Python, not Node. Does that matter?

Not for the live app scan, which looks at what your app serves, whatever it is written in. The repo scan reads Python as well as JavaScript, and checks Poetry and pyproject files for vulnerable packages.

See what your Replit app is showing strangers.

One app is free, no card. The hardest part is asking Replit Agent to add a file.