Replit Security Basics
Overview
Security best practices for Replit: Secrets (AES-256 encrypted env vars), REPL_IDENTITY token verification, Auth header trust model, public Repl exposure risks, and Secret Scanner protection.
Prerequisites
- Replit account with Workspace access
- Understanding of environment variables
- Deployed app (for Auth security)
Instructions
Step 1: Secrets Management
Replit Secrets are AES-256 encrypted at rest with TLS in transit. Keys rotate regularly. Two scopes:
App-level secrets: Specific to one Repl (lock icon in sidebar)
Account-level secrets: Apply across all your Repls (Account Settings > Secrets)
const REQUIRED = ['DATABASE_URL', 'JWT_SECRET', 'API_KEY'];
const missing = REQUIRED.filter(k => !process.env[k]);
if (missing.length) {
console.error(`Missing secrets: ${missing.join(', ')}`);
console.error('Add them in the Secrets tab (lock icon in sidebar)');
process.exit(1);
}
Secret Scanner: Replit detects when you paste API keys into code files and warns you to store them as Secrets instead. Never dismiss this warning.
Step 2: Public Repl Safety
Replit Repls are public by default on free plans. Your source code is visible to anyone.
API_KEY = "sk-live-abc123"
import os
API_KEY = os.environ.get("API_KEY")
# .gitignore (also applies if you connect Repl to GitHub)
.env
.env.local
*.pem
*.key
Step 3: REPL_IDENTITY Token Verification
Every Repl gets a REPL_IDENTITY environment variable — a PASETO token signed by Replit infrastructure. Use it for service-to-service authentication between Repls.
import { verify } from '@replit/repl-auth';
function verifyReplIdentity(identityToken: string): boolean {
try {
const pubkeys = JSON.parse(process.env.REPL_PUBKEYS || '{}');
const payload = verify(identityToken, pubkeys);
return !!payload;
} catch {
return false;
}
}
app.post('/internal/api', (req, res) => {
const identity = req.headers['x-repl-identity'] as string;
if (!verifyReplIdentity(identity)) {
return res.status(403).json({ error: 'Invalid Repl identity' });
}
});
Step 4: Auth Header Trust Model
Replit Auth headers (X-Replit-User-*) are injected by Replit's proxy. They can be trusted on deployed apps but NOT on external networks.
const AUTH_HEADERS = [
'x-replit-user-id',
'x-replit-user-name',
'x-replit-user-bio',
'x-replit-user-url',
'x-replit-user-profile-image',
'x-replit-user-roles',
'x-replit-user-teams',
] as const;
function isSecureContext(): boolean {
return !!process.env.REPL_SLUG;
}
Step 5: Database Security
const result = await pool.query(`SELECT * FROM users WHERE name = '${name}'`);
const result = await pool.query('SELECT * FROM users WHERE name = $1', [name]);
Step 6: Security Checklist
## Replit Security Audit Checklist
### Secrets
- [ ] All API keys stored in Replit Secrets (never in code)
- [ ] Required secrets validated at startup
- [ ] No secrets in console.log() or error responses
- [ ] Secret Scanner warnings not dismissed
### Access
- [ ] Repl visibility appropriate (public vs private)
- [ ] Auth headers validated on protected routes
- [ ] Database queries use parameterized statements
- [ ] Error responses don't expose stack traces in production
### Deployment
- [ ] Production uses Deployments (not just "Run")
- [ ] Custom domains have SSL (auto-provisioned by Replit)
- [ ] Health endpoint doesn't expose sensitive info
- [ ] NODE_ENV set to "production" in deployment config
### Team
- [ ] Roles assigned with least privilege
- [ ] Inactive members removed (seat audit)
- [ ] SSO enforced (Enterprise)
- [ ] Deployment permissions restricted to admins
Error Handling
| Security Issue | Detection | Mitigation |
|---|
| Secret in source code | Secret Scanner alert | Move to Secrets tab immediately |
| Public Repl with secrets | Code review | Make Repl private or use Secrets |
| Auth header spoofing | Custom domain without proxy | Only trust headers on Replit domains |
| SQL injection | Code audit | Use parameterized queries exclusively |
| Stack trace exposure | Error handler review | Catch all errors, return safe messages |
Resources
Next Steps
For production deployment, see replit-prod-checklist.