# Django Secret Key Management

**URL:** <https://forum.djangoproject.com/t/django-secret-key-management/22004>\
**Category:** Deployment\
**Created:** [July 1, 2023, 7:19pm UTC](https://forum.djangoproject.com/t/django-secret-key-management/22004 "2023-07-01T19:19:12Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![strikeouts27](https://sea2.discourse-cdn.com/flex026/user_avatar/forum.djangoproject.com/strikeouts27/32/13899_2.png) [@strikeouts27](https://forum.djangoproject.com/u/strikeouts27)\
**Post date:** [July 1, 2023, 7:19pm UTC](https://forum.djangoproject.com/t/django-secret-key-management/22004/1 "2023-07-01T19:19:12Z")

</div>

I have just restarted the django polls tutorial out of pure frustration. I was trying to restart the project and establish github version control. when I pushed my project up to github it told me that there were secret keys uploaded. apparently this is a big no no. I went to stack overflow and found this article: [Access GitHub Secret Key - Stack Overflow](https://stackoverflow.com/questions/65932260/access-github-secret-key) it is talking about a .github/workflows directory I have not made such a file. is that somethign that github makes on its own when I push up the code to the repository? How do I, upon startup prevent this from happening in the future? Do I write my secret key code down or something? (edited)

Stack Overflow

[Access GitHub Secret Key](https://stackoverflow.com/questions/65932260/access-github-secret-key)

---

<div class="post-metadata">

**Author:** ![strikeouts27](https://sea2.discourse-cdn.com/flex026/user_avatar/forum.djangoproject.com/strikeouts27/32/13899_2.png) [@strikeouts27](https://forum.djangoproject.com/u/strikeouts27)\
**Post date:** [July 1, 2023, 7:20pm UTC](https://forum.djangoproject.com/t/django-secret-key-management/22004/2 "2023-07-01T19:20:02Z")

</div>

I have been informed that I need to make a .env file or a .txt file and name that file during startup going forward.

---

<div class="post-metadata">

**Author:** ![strikeouts27](https://sea2.discourse-cdn.com/flex026/user_avatar/forum.djangoproject.com/strikeouts27/32/13899_2.png) [@strikeouts27](https://forum.djangoproject.com/u/strikeouts27)\
**Post date:** [July 1, 2023, 9:08pm UTC](https://forum.djangoproject.com/t/django-secret-key-management/22004/3 "2023-07-01T21:08:29Z")

</div>

Run django-admin start project command project name.

Set up the project environment pip install django, pip upgrade pipp, pip install psycopg

Create a passwords.txt and grab the secret key and store that variable in.

Python3 -m venv project\_env

Source project\_env/bin/activate

Pip3 install django

Pip install psycopg3

Create an empty repository on github but do not execute the final command where it tells you to push everything.

Create a gitignore file and put your product\_env and password.txt file in there.

Push the code.

My question is this, when I grab the secret key should I just transfer the whole variable into the file and completely remove it from settings.py? Or shoudl I copy it over to the passwords.txt file and than delete the key but leave the variable empty?

---

<div class="post-metadata">

**Author:** ![strikeouts27](https://sea2.discourse-cdn.com/flex026/user_avatar/forum.djangoproject.com/strikeouts27/32/13899_2.png) [@strikeouts27](https://forum.djangoproject.com/u/strikeouts27)\
**Post date:** [July 1, 2023, 9:19pm UTC](https://forum.djangoproject.com/t/django-secret-key-management/22004/4 "2023-07-01T21:19:30Z")

</div>

![Screen Shot 2023-07-01 at 4.18.43 PM](https://us1.discourse-cdn.com/flex026/uploads/djangoproject/original/2X/1/168c277a6f05eeb46706e8951727bcbbf61d1c7c.png)

When I tried to run the polls app I got this error message. I think it is related to the variable being missing.

---

<div class="post-metadata">

**Author:** ![strikeouts27](https://sea2.discourse-cdn.com/flex026/user_avatar/forum.djangoproject.com/strikeouts27/32/13899_2.png) [@strikeouts27](https://forum.djangoproject.com/u/strikeouts27)\
**Post date:** [July 1, 2023, 9:43pm UTC](https://forum.djangoproject.com/t/django-secret-key-management/22004/5 "2023-07-01T21:43:57Z")

</div>

07:01/23 1pm  
C: Yeah and then you just need to make sure you set an environment variable called SECRET\_KEY with a random string when you run your code, there are a few ways to do that automatically or you can just set it manually

strikeouts27: 1. my issue is i cannot upload my secret key into github. I could repaste the secret key code back in, but I fear I would have the same problem

C: 1. yeah so your secret key never goes into git, I would add an instruction to your readme to say “generate a secret key and save it as an environment variable called SECRET\_KEY” or something like that

striketous27: like this?  
[Hastebin](https://hastebin.com/share/ugoledovey.python). thank you for your help by the way!

C: Yeah you got it 🙂  
strikeouts27: KeyError: ‘SECRET\_KEY’

C: 1. You need to set the environment variable

strikeouts27: 1. import os and secret\_key = os.enviornm[“SECRET\_KEY”] was accomplished

C:  
Windows: `set SECRET_KEY=123`  
Mac/Linux: `export SECRET_KEY=123`

Strikeouts27:  
Yes! Wooho!

C: So you will need to run that every time you restart your PC, but there are ways to set it automatically  
[4:52 PM]  
Like a tool called dotenv  
This SO post describes the setup with dotenv so is a good starting point

> <https://stackoverflow.com/questions/15209978/where-to-store-secret-keys-django>

if I follow the stack over flow instructions I can confirm that I do not need to run the export command all by myself.

---

<div class="post-metadata">

**Author:** ![abbasj](https://sea2.discourse-cdn.com/flex026/user_avatar/forum.djangoproject.com/abbasj/32/11876_2.png) [@abbasj](https://forum.djangoproject.com/u/abbasj)\
**Post date:** [July 2, 2023, 4:11pm UTC](https://forum.djangoproject.com/t/django-secret-key-management/22004/6 "2023-07-02T16:11:21Z")

</div>

![SK](https://us1.discourse-cdn.com/flex026/uploads/djangoproject/original/2X/0/025bc855fe6d6ee4dab8f70879c948b2e406f425.png)

![Key](https://us1.discourse-cdn.com/flex026/uploads/djangoproject/original/2X/1/111da4432a6ca94b56f4d7358c7bafdcf51ed1ec.png)

This is one way to do it.

---

<div class="post-metadata">

**Author:** ![strikeouts27](https://sea2.discourse-cdn.com/flex026/user_avatar/forum.djangoproject.com/strikeouts27/32/13899_2.png) [@strikeouts27](https://forum.djangoproject.com/u/strikeouts27)\
**Post date:** [October 10, 2024, 9:10pm UTC](https://forum.djangoproject.com/t/django-secret-key-management/22004/7 "2024-10-10T21:10:00Z")

</div>

To generate a secret key…

In the terminal, run the following command:

python -c ‘from django.core.management.utils import get\_random\_secret\_key; print(get\_random\_secret\_key())’

This command will output a new secret key that you can place in your env file.
