# SECRET\_KEY commit on GitHub

**URL:** <https://forum.djangoproject.com/t/secret-key-commit-on-github/14926>\
**Category:** Getting Started\
**Created:** [July 20, 2022, 9:11pm UTC](https://forum.djangoproject.com/t/secret-key-commit-on-github/14926 "2022-07-20T21:11:38Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![DoriDoro](https://sea2.discourse-cdn.com/flex026/user_avatar/forum.djangoproject.com/doridoro/32/5014_2.png) [@DoriDoro](https://forum.djangoproject.com/u/DoriDoro)\
**Post date:** [July 20, 2022, 9:11pm UTC](https://forum.djangoproject.com/t/secret-key-commit-on-github/14926/1 "2022-07-20T21:11:38Z")

</div>

Hello everyone,

I manage to replace the SECRET\_KEY in my project. Put it into a .env file and replace it in the settings.py file with:

```auto
from decouple import config

SECRET_KEY = config("SECRET_KEY") # this is to replace the secret key you cut away before

```

What do I have to put into the README file as instructions if someone will pull the repository and install it on her/his computer? Do they need to do something or is the SECRET\_KEY generated automatically? (Perhaps I should do this to find out by myself, to pull a repository of someone else and see what is happening. Just in this moment when I wrote this post I got the idea.) I would be happy if someone could answer me that please.

Are these instructions necessary?

```auto
$ pip install django-secret-key
$ django-secret-key

```

Thanks in advance  
Doro

---

<div class="post-metadata">

**Author:** ![60hz](https://sea2.discourse-cdn.com/flex026/user_avatar/forum.djangoproject.com/60hz/32/5843_2.png) [@60hz](https://forum.djangoproject.com/u/60hz)\
**Post date:** [July 21, 2022, 4:45am UTC](https://forum.djangoproject.com/t/secret-key-commit-on-github/14926/2 "2022-07-21T04:45:42Z")

</div>

What you are doing with .env is standard practice for keeping secrets out of the settings.py file, and is a great way to avoid committing secrets to version controll. If you are not doing this with your DB credentials too, you may want to do that.  
You can read about what SECRET\_KEY does in [the docs](https://docs.djangoproject.com/en/4.0/ref/settings/#secret-key).  
If you remove the key, users will have to generate a new on in settings.py, so you may want to leave the pip package instructions in there. Probably try to download and build the project from your instructions in the repo. If you expect people to download and try to run the project, that’s the best way to find problems! Good luck!
