TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Has an API key issuer ever leaked customer API keys

1 pointsby mathewpregasenalmost 2 years ago
There’s been plenty of examples where API keys were leaked due to poor API key management, such as the Algolia or Mailgun report.<p>There are also examples where API user data was compromised due to a breached employee laptop.<p>However, I’m curious if an API developer &#x2F; issuer ever has leaked their own customers’ API Keys, I.e. Stripe leaking Stripe API Keys.

2 comments

mathewpregasenalmost 2 years ago
I know 3Commas and Cloudflare’s 2017 breach is sort-of this, but curious if a company have ever leaked API keys they create &#x2F; manage and had to cycle every customer’s keys as a result
rohitpaulkalmost 2 years ago
Think this happened to Heroku recently, not sure though.