TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Ask HN: Has an API key issuer ever leaked their own customers’ API keys

1 pointsby mathewpregasenalmost 2 years ago
There’s been plenty of examples where API keys were leaked due to poor API key management, such as the Algolia or Mailgun report.<p>There are also examples where user data was compromised due to bad authentication rules or logic of an API<p>However, I’m curious if an API developer &#x2F; issuer ever has leaked their own customers’ API Keys while their APIs security is otherwise airtight, I.e. Stripe leaking Stripe API Keys.

1 comment

amrbalmost 2 years ago
Anything can end up in logs, then it depends on getting access to hosted splunk via employee creds, for a hypothetical breach.