HACKER Q&A
📣 mathewpregasen

Has an API key issuer ever leaked their own customers’ API keys


There’s been plenty of examples where API keys were leaked due to poor API key management, such as the Algolia or Mailgun report.

There are also examples where user data was compromised due to bad authentication rules or logic of an API

However, I’m curious if an API developer / issuer ever has leaked their own customers’ API Keys while their APIs security is otherwise airtight, I.e. Stripe leaking Stripe API Keys.


  👤 amrb Accepted Answer ✓
Anything can end up in logs, then it depends on getting access to hosted splunk via employee creds, for a hypothetical breach.