Secrets and credentials
Before production, move database passwords, Discord tokens, webhook URLs, captcha keys, and mail credentials out of source-controlled files.
- Use environment variables or server-level secret storage where your host supports it.
- Never expose bot source, SQL schemas, project files, or credential examples publicly.
- Rotate any token that was ever committed, shared, or placed in a public web directory.