Lune

CCS2026Top-tier venue

Keys on Doormats: Exposed API Credentials on the Web

Nurullah Demir, Yash Vekaria, Georgios Smaragdakis, Zakir Durumeric

2026Year
2Citations

Abstract

API (Application Programming Interface) keys allow applications to authenticate themselves to third-party services. Inadvertent public exposure of these credentials can pose significant consequences, as adversaries can use them to gain privileged access to other services. In this paper, we measure API credential exposure on the web by analyzing 10M rendered websites. Our findings reveal that API credential exposure on the web is widespread, affecting organizations such as global banks and core infrastructure providers. We identify 1,748 credentials for accessing 14 providers (e.g., cloud and payment services). Crucially, we demonstrate that these exposures are largely missed by static analysis. By characterizing web-specific exposure vectors and root causes, we find that 62% of JavaScript-based exposures manifest exclusively within compiled deployment bundles, while 16% propagate dynamically through third-party resource inclusions. Moreover, our longitudinal analysis shows these credentials often persist for months to years. We conclude by discussing our responsible disclosure efforts and outlining mitigations to secure web deployment pipelines in the future.

Ask about this paper

Your agent reads all of it.

Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.

Questions to start from

Your agent calls

Luneget_paper_fulltext

Ask in Lune

Free to start. No credit card required.

lune papers fulltext bb059ec3-b9a2-4c28-903d-9ba2f025e960

Builds on13

Related papers

Dusk over the sea between two cliffs drawn in fine vertical lines