Skip to content
KitploitKITPLOIT
أدواتعمليات الاستغلالالمدونة
Log in
إرسال
أدواتعمليات الاستغلالالمدونة
إرسال

أدوات الاختراق واختبار الاختراق والأمن السيبراني لترسانتك الأمنية!

Kitploit هو دليل لأدوات الاختراق والأمن السيبراني واختبار الاختراق. اكتشف آخر تحديثات المشاريع للعثور على الثغرات وتحليل الأنظمة وأتمتة الاختبارات وتعزيز أمنك.

··الخلاصات·اتصال·الخصوصية·© 2026 Kitploit

دليل الأدوات

الفئات

عرض جميع الفئات
Loading categories
keyhacks — مجموعة منسقة من الأوامر للتحقق من صحة مفاتيح API المسربة من برامج مكافآت الاختراق واختبارات الاختراق، تغطي أكثر من 80 خدمة بما في ذلك AWS وGitHub وSlack وTwilio. | Kitploit
أدوات/GitHubGitHub/streaak/keyhacks
تحليل الثغرات الأمنيةاختبار الاختراقكشف الأسرارأمن واجهات برمجة التطبيقات
GitHubstreaak/keyhacks

keyhacks

مجموعة منسقة من الأوامر للتحقق من صحة مفاتيح API المسربة من برامج مكافآت الاختراق واختبارات الاختراق، تغطي أكثر من 80 خدمة بما في ذلك AWS وGitHub وSlack وTwilio.

عرض المستودع
6.3k1.2k38منذ شهر واحدتمت المراجعة من قبل Kitploit

الأكثر شعبية

عرض الكل →

اكتشف الأدوات الأكثر استخدامًا من قبل مجتمعنا.

استكشف جميع الأدوات

تصفح مجموعتنا من الأدوات

عرض جميع الأدوات →
مشاركة
<p align="center">
  <img src="https://assets.kitploit.com/production/public/readmes/4653/0b5b34d5398000ecc5e0743d278876caf96f87191f91a06860c706905996a642.png" width="300px">
</p>
</br>

KeyHacks يعرض طرقًا للتحقق من مفاتيح API المختلفة التي يتم العثور عليها في برنامج Bug Bounty أو اختبار الاختراق.

@Gwen001 قام بكتابة سيناريو العملية بأكملها المتاحة هنا ويمكن العثور عليها [هنا](https://github.com/gwen001/pentest-tools/blob/master/keyhacks.sh)

# جدول المحتويات

- [مفتاح API لـ ABTasty](#ABTasty-API-Key)
- [مفتاح API لـ Algolia](#Algolia-API-key)
- [مفاتيح API لـ Amplitude](#Amplitude-API-Keys)
- [رمز وصول Asana](#Asana-Access-Token)
- [معرف مفتاح الوصول AWS والسر](#AWS-Access-Key-ID-and-Secret)
- [معرف تطبيق Azure Application Insights ومفتاح API](#Azure-Application-Insights-APP-ID-and-API-Key)
- [مفتاح Bazaarvoice](#Bazaarvoice-Passkey)
- [مفتاح API لخرائط Bing](#Bing-Maps-API-Key)
- [رمز وصول Bit.ly](#Bitly-Access-token)
- [مفتاح Branch.io والسر](#BranchIO-Key-and-Secret)
- [مفتاح الوصول لـ BrowserStack](#BrowserStack-Access-Key)
- [رمز وصول Buildkite](#Buildkite-Access-token)
- [مفتاح API لـ ButterCMS](#ButterCMS-API-Key)
- [مفتاح API لـ Calendly](#Calendly-API-Key)
- [رمز الوصول لـ Contentful](#Contentful-access-token)
- [رمز الوصول لـ CircleCI](#CircleCI-Access-Token)
- [مفتاح API لـ Cloudflare](#cloudflare-api-key)
- [مفتاح تسجيل Cypress](#Cypress-record-key)
- [مفتاح API لـ DataDog](#DataDog-API-key)
- [مفتاح API لـ Delighted](#Delighted-api-key)
- [رمز وصول Deviant Art](#Deviant-Art-Access-Token)
- [سر Deviant Art](#Deviant-Art-Secret)
- [API لـ Dropbox](#Dropbox-API)
- [رمز وصول Facebook](#Facebook-Access-Token)
- [سر تطبيق Facebook](#Facebook-AppSecret)
- [Firebase](#Firebase)
- [Firebase Cloud Messaging (FCM)](#Firebase-Cloud-Messaging)
- [مفتاح API لـ FreshDesk](#FreshDesk-API-key)
- [معرف العميل وسر العميل لـ Github](#Github-client-id-and-client-secret)
- [مفتاح SSH الخاص بـ GitHub](#GitHub-private-SSH-key)
- [رمز Github](#Github-Token)
- [رمز الوصول الشخصي لـ Gitlab](#Gitlab-personal-access-token)
- [رمز تسجيل مشغل GitLab](#Gitlab-runner-registration-token)
- [بيانات اعتماد حساب خدمة Google Cloud](#Google-Cloud-Service-Account-credentials)
- [مفتاح API لخرائط Google](#Google-Maps-API-key)
- [مفتاح Recaptcha من Google](#Google-Recaptcha-key)
- [رمز وصول Grafana](#Grafana-Access-Token)
- [OAUTH لـ Help Scout](#Help-Scout-OAUTH)
- [مفتاح API لـ Heroku](#Heroku-API-key)
- [مفتاح API لـ HubSpot](#Hubspot-API-key)
- [مفتاح API لـ Infura](#Infura-API-key)
- [رمز وصول Instagram](#Instagram-Access-Token)
- [API العرض الأساسي لـ Instagram](#Instagram-Basic-Display-API-Access-Token)
- [Instagram Graph API](#Instagram-Graph-Api-Access-Token)
- [مفتاح API لـ Ipstack](#Ipstack-API-Key)
- [مفتاح API لـ Iterable](#Iterable-API-Key)
- [مفتاح API لـ JumpCloud](#JumpCloud-API-Key)
- [مفتاح API لـ Keen.io](#Keenio-API-Key)
- [OAUTH لـ LinkedIn](#LinkedIn-OAUTH)
- [مفتاح API لـ Lokalise](#Lokalise-API-Key)
- [مفتاح API لـ Loqate](#Loqate-API-key)
- [مفتاح API لـ MailChimp](#MailChimp-API-Key)
- [المفتاح الخاص لـ MailGun](#MailGun-Private-Key)
- [مفتاح API لـ Mapbox](#Mapbox-API-Key)
- [مستأجر Microsoft Azure](#Microsoft-Azure-Tenant)
- [توقيعات الوصول المشترك لـ Microsoft (SAS)](#Microsoft-Shared-Access-Signatures-(SAS))
- [Webhook لـ Microsoft Teams](#Microsoft-Teams-Webhook)
- [مفتاح API الشخصي لـ New Relic (NerdGraph)](#New-Relic-Personal-API-Key-(NerdGraph))
- [REST API لـ New Relic](#New-Relic-REST-API)
- [رمز NPM](#NPM-token)
- [مفتاح API لـ OpsGenie](#OpsGenie-API-Key)
- [رمز API لـ Pagerduty](#Pagerduty-API-token)
- [معرف العميل والمفتاح السري لـ PayPal](#Paypal-client-id-and-secret-key)
- [مفتاح التكامل لـ Pendo](#Pendo-Integration-Key)
- [رمز API لـ PivotalTracker](#PivotalTracker-API-Token)
- [مفتاح API والمفتاح السري لـ Razorpay](#Razorpay-keys)
- [مفتاح API لـ Salesforce](#Salesforce-API-key)
- [اسم المستخدم ومفتاح الوصول لـ SauceLabs](#SauceLabs-Username-and-access-Key)
- [رمز API لـ SendGrid](#SendGrid-API-Token)
- [مفتاح API لـ Shodan](#Shodan-Api-Key)
- [رمز API لـ Slack](#Slack-API-token)
- [Webhook لـ Slack](#Slack-Webhook)
- [رمز Sonarcloud](#Sonarcloud-Token)
- [رمز وصول Spotify](#Spotify-Access-Token)
- [Square](#Square)
- [الرمز المباشر لـ Stripe](#Stripe-Live-Token)
- [رمز API لبوت Telegram](#Telegram-Bot-API-Token)
- [رمز API لـ Travis CI](#Travis-CI-API-token)
- [معرف الحساب ورمز المصادقة لـ Twilio](#Twilio-Account_sid-and-Auth-token)
- [سر API لـ Twitter](#Twitter-API-Secret)
- [رمز الحامل لـ Twitter](#Twitter-Bearer-token)
- [رمز API لـ Visual Studio App Center](#Visual-Studio-App-Center-API-Token)
- [مفتاح API لـ WakaTime](#WakaTime-API-Key)
- [مفتاح API لـ WeGlot](#weglot-api-key)
- [مفتاح API لـ WPEngine](#WPEngine-API-Key)
- [مفتاح API لـ YouTube](#YouTube-API-Key)
- [رمز Webhook لـ Zapier](#Zapier-Webhook-Token)
- [رمز وصول Zendesk](#Zendesk-Access-Token)
- [مفتاح API لـ Zendesk](#Zendesk-api-key)

# معلومات مفصلة

## [Slack Webhook](https://api.slack.com/incoming-webhooks)

إذا أرجع الأمر التالي `missing_text_or_fallback_or_attachments`، فهذا يعني أن عنوان URL صالح، وأي ردود أخرى تعني أن عنوان URL غير صالح.```
curl -s -X POST -H "Content-type: application/json" -d '{"text":""}' "https://hooks.slack.com/services/T00000000/B00000000/XXXXXXXXXXXXXXXXXXXXXXXX"
```
## [رمز Slack API](https://api.slack.com/web)```
curl -sX POST "https://slack.com/api/auth.test?token=xoxp-TOKEN_HERE&pretty=1"
```
أو```
curl -sX POST "https://slack.com/api/auth.test" -H "Accept: application/json; charset=utf-8" -H "Authorization: Bearer xoxb-TOKEN_HERE"
```
## [اسم المستخدم ومفتاح الوصول لـ SauceLabs](https://wiki.saucelabs.com/display/DOCS/Account+Methods)```
curl -u USERNAME:ACCESS_KEY https://saucelabs.com/rest/v1/users/USERNAME
```
## Facebook AppSecret

يمكنك إنشاء رموز الوصول عن طريق زيارة الرابط أدناه.```
https://graph.facebook.com/oauth/access_token?client_id=ID_HERE&client_secret=SECRET_HERE&redirect_uri=&grant_type=client_credentials
```
## رمز وصول فيسبوك```
https://developers.facebook.com/tools/debug/accesstoken/?access_token=ACCESS_TOKEN_HERE&version=v3.2
```
## [Firebase](https://firebase.google.com/)
يتطلب **رمزًا مخصصًا** و**مفتاح API**.

1. احصل على رمز ID ورمز التحديث من الرمز المخصص ومفتاح API: `curl -s -XPOST -H 'content-type: application/json' -d '{"token":":custom_token","returnSecureToken":True}' 'https://identitytoolkit.googleapis.com/v1/accounts:signInWithCustomToken?key=:api_key'`
2. استبدل رمز ID برمز المصادقة: `curl -s -XPOST -H 'content-type: application/json' -d '{"idToken":":id_token"}' https://www.googleapis.com/identitytoolkit/v3/relyingparty/verifyCustomToken?key=:api_key'`

## [Github Token](https://developer.github.com/v3/)```
curl -s -u "user:apikey" https://api.github.com/user
curl -s -H "Authorization: token TOKEN_HERE" "https://api.github.com/users/USERNAME_HERE/orgs"
# Check scope of your api token
curl "https://api.github.com/rate_limit" -i -u "user:apikey" | grep "X-OAuth-Scopes:"
```
## [معرف عميل GitHub وسر العميل](https://developer.github.com/v3/#oauth2-keysecret)```
curl 'https://api.github.com/users/whatever?client_id=xxxx&client_secret=yyyy'
```
## [إشعارات Firebase السحابية](https://firebase.google.com/docs/cloud-messaging)

المرجع: https://abss.me/posts/fcm-takeover```
curl -s -X POST --header "Authorization: key=AI..." --header "Content-Type:application/json" 'https://fcm.googleapis.com/fcm/send' -d '{"registration_ids":["1"]}'
```
## مفتاح SSH الخاص بـ GitHub

يمكن اختبار مفاتيح SSH الخاصة ضد github.com لمعرفة ما إذا كانت مسجلة مقابل حساب مستخدم موجود. إذا كان المفتاح موجودًا، فسيتم توفير اسم المستخدم المقابل للمفتاح. ([المصدر](https://github.com/streaak/keyhacks/issues/2))```
$ ssh -i <path to SSH private key> -T [email protected]
Hi <username>! You've successfully authenticated, but GitHub does not provide shell access.
```
## [Twilio Account_sid and Auth token](https://www.twilio.com/docs/iam/api/account)```
curl -X GET 'https://api.twilio.com/2010-04-01/Accounts.json' -u ACCOUNT_SID:AUTH_TOKEN
```
## [سر API تويتر](https://developer.twitter.com/en/docs/basics/authentication/guides/bearer-tokens.html)```
curl -u 'API key:API secret key' --data 'grant_type=client_credentials' 'https://api.twitter.com/oauth2/token'
```
## [رمز Twitter الحامل](https://developer.twitter.com/en/docs/accounts-and-users/subscribe-account-activity/api-reference/aaa-premium)```
curl --request GET --url https://api.twitter.com/1.1/account_activity/all/subscriptions/count.json --header 'authorization: Bearer TOKEN'
```
## [مفتاح API الخاص بـ HubSpot](https://developers.hubspot.com/docs/methods/owners/get_owners)

الحصول على جميع المالكين:```
https://api.hubapi.com/owners/v2/owners?hapikey={keyhere}
```
احصل على جميع تفاصيل الاتصال:```
https://api.hubapi.com/contacts/v1/lists/all/contacts/all?hapikey={keyhere}

```
## [مفتاح API لـ Infura](https://docs.infura.io/infura/networks/ethereum/how-to/secure-a-project/project-id)```
curl https://mainnet.infura.io/v3/<YOUR-API-KEY> -X POST -H "Content-Type: application/json" -d '{"jsonrpc":"2.0","method":"eth_accounts","params":[],"id":1}'
```
## [Deviant Art سر](https://www.deviantart.com/developers/authentication)```
curl https://www.deviantart.com/oauth2/token -d grant_type=client_credentials -d client_id=ID_HERE -d client_secret=mysecret
```
## [رمز الوصول لـ Deviant Art](https://www.deviantart.com/developers/authentication)```
curl https://www.deviantart.com/api/v1/oauth2/placebo -d access_token=Alph4num3r1ct0k3nv4lu3
```
## [Pendo Integration Key](https://help.pendo.io/resources/support-library/api/index.html?bash#authentication)```
curl -X GET https://app.pendo.io/api/v1/feature -H 'content-type: application/json' -H 'x-pendo-integration-key:KEY_HERE'
curl -X GET https://app.pendo.io/api/v1/metadata/schema/account -H 'content-type: application/json' -H 'x-pendo-integration-key:KEY_HERE'
```
## [SendGrid API Token](https://docs.sendgrid.com/api-reference)```
curl -X "GET" "https://api.sendgrid.com/v3/scopes" -H "Authorization: Bearer SENDGRID_TOKEN-HERE" -H "Content-Type: application/json"
```
## [Square](https://squareup.com/)
**الكشف:**

معرف التطبيق/السر الخاص بالعميل:  `sq0[a-z]{3}-[0-9A-Za-z\-_]{22,43}`
رمز المصادقة: `EAAA[a-zA-Z0-9]{60}`

**معرف التطبيق وسر العميل للاختبار:**```
curl "https://squareup.com/oauth2/revoke" -d '{"access_token":"[RANDOM_STRING]","client_id":"[APP_ID]"}'  -H "Content-Type: application/json" -H "Authorization: Client [CLIENT_SECRET]"
```
الاستجابة التي تشير إلى بيانات اعتماد صالحة:```
empty
```
الاستجابة التي تشير إلى بيانات اعتماد غير صالحة:```
{
  "message": "Not Authorized",
  "type": "service.not_authorized"
}
```
**رمز المصادقة الاختباري:**```
curl https://connect.squareup.com/v2/locations -H "Authorization: Bearer [AUHT_TOKEN]"
```
استجابة تشير إلى بيانات اعتماد صالحة:```
{"locations":[{"id":"CBASELqoYPXr7RtT-9BRMlxGpfcgAQ","name":"Coffee \u0026 Toffee SF","address":{"address_line_1":"1455 Market Street","locality":"San Francisco","administrative_district_level_1":"CA","postal_code":"94103","country":"US"},"timezone":"America/Los_Angeles"........
```
الاستجابة التي تشير إلى بيانات اعتماد غير صالحة:```
{"errors":[{"category":"AUTHENTICATION_ERROR","code":"UNAUTHORIZED","detail":"This request could not be authorized."}]}
```
## [Contentful Access Token](https://www.contentful.com/developers/docs/references/authentication)```
curl -v https://cdn.contentful.com/spaces/SPACE_ID_HERE/entries\?access_token\=ACCESS_TOKEN_HERE
```
## [واجهة برمجة تطبيقات Dropbox](https://www.dropbox.com/developers/documentation/http/documentation)```
curl -X POST https://api.dropboxapi.com/2/users/get_current_account --header "Authorization: Bearer TOKEN_HERE"
```
## [معرف مفتاح الوصول AWS والمفتاح السري](https://docs.aws.amazon.com/cli/latest/userguide/cli-configure-profiles.html)

قم بتثبيت [awscli](https://aws.amazon.com/cli/)، واضبط [مفتاح الوصول والمفتاح السري كمتغيرات بيئة](https://docs.aws.amazon.com/cli/latest/userguide/cli-configure-envvars.html)، ثم نفّذ الأمر التالي:```
AWS_ACCESS_KEY_ID=xxxx AWS_SECRET_ACCESS_KEY=yyyy aws sts get-caller-identity
```
يمكن تحديد أذونات بيانات اعتماد AWS باستخدام [Enumerate-IAM](https://github.com/andresriancho/enumerate-iam). وهذا يعطي نظرة أوسع على امتيازات بيانات اعتماد AWS المكتشفة بدلاً من مجرد فحص حاويات S3.```
git clone https://github.com/andresriancho/enumerate-iam
cd  enumerate-iam
./enumerate-iam.py --access-key AKIA... --secret-key StF0q...
```
## [مفتاح API لـ Lokalise](https://app.lokalise.com/api2docs/curl/#resource-authentication)```curl --request GET \
  --url https://api.lokalise.com/api2/projects/ \
  --header 'x-api-token: [API-KEY-HERE]'
```
## [مفتاح MailGun الخاص](https://documentation.mailgun.com/en/latest/api_reference.html)```
curl --user 'api:YOUR_API_KEY' "https://api.mailgun.net/v3/domains"
```
## [مفتاح API لـ FreshDesk](https://developers.freshdesk.com/api/#getting-started)```
curl -v -u [email protected]:test -X GET 'https://domain.freshdesk.com/api/v2/groups/1'
This requires the API key in '[email protected]', pass in 'test' and 'domain.freshdesk.com' to be the instance url of the target. In case you get a 403, try the endpoint api/v2/tickets, which is accessible for all keys.

```
## [مفتاح API لـ JumpCloud](https://docs.jumpcloud.com/1.0/authentication-and-authorization/authentication-and-authorization-overview)

#### [v1](https://docs.jumpcloud.com/1.0/systemusers)```
List systems:
curl -H "x-api-key: APIKEYHERE" "https://console.jumpcloud.com/api/systems"
curl -H "x-api-key: APIKEYHERE" "https://console.jumpcloud.com/api/systemusers"
curl -H "x-api-key: APIKEYHERE" "https://console.jumpcloud.com/api/applications"
```
#### [v2](https://docs.jumpcloud.com/2.0/systems/list-the-associations-of-a-system)```
List systems:
curl -X GET https://console.jumpcloud.com/api/v2/systems/{System_ID}/memberof \
  -H 'Accept: application/json' \
  -H 'Content-Type: application/json' \
  -H 'x-api-key: {API_KEY}'
```
## Microsoft Azure Tenant
التنسيق:```
CLIENT_ID: [0-9a-z\-]{36}
CLIENT_SECRET: [0-9A-Za-z\+\=]{40,50}
TENANT_ID: [0-9a-z\-]{36}
```
التحقق:```
curl -X POST -H "Content-Type: application/x-www-form-urlencoded" -d 'client_id=<CLIENT_ID>&scope=https%3A%2F%2Fgraph.microsoft.com%2F.default&client_secret=<CLIENT_SECRET>&grant_type=client_credentials' 'https://login.microsoftonline.com/<TENANT_ID>/oauth2/v2.0/token'
```
## [Microsoft Shared Access Signatures (SAS)](https://github.com/MicrosoftDocs/azure-docs/blob/master/articles/storage/common/storage-dotnet-shared-access-signature-part-1.md)

يمكن استخدام powershell التالي لاختبار رمز Shared Access Signature:```powershell
static void UseAccountSAS(string sasToken)
{
    // Create new storage credentials using the SAS token.
    StorageCredentials accountSAS = new StorageCredentials(sasToken);
    // Use these credentials and the account name to create a Blob service client.
    CloudStorageAccount accountWithSAS = new CloudStorageAccount(accountSAS, "account-name", endpointSuffix: null, useHttps: true);
    CloudBlobClient blobClientWithSAS = accountWithSAS.CreateCloudBlobClient();

    // Now set the service properties for the Blob client created with the SAS.
    blobClientWithSAS.SetServiceProperties(new ServiceProperties()
    {
        HourMetrics = new MetricsProperties()
        {
            MetricsLevel = MetricsLevel.ServiceAndApi,
            RetentionDays = 7,
            Version = "1.0"
        },
        MinuteMetrics = new MetricsProperties()
        {
            MetricsLevel = MetricsLevel.ServiceAndApi,
            RetentionDays = 7,
            Version = "1.0"
        },
        Logging = new LoggingProperties()
        {
            LoggingOperations = LoggingOperations.All,
            RetentionDays = 14,
            Version = "1.0"
        }
    });

    // The permissions granted by the account SAS also permit you to retrieve service properties.
    ServiceProperties serviceProperties = blobClientWithSAS.GetServiceProperties();
    Console.WriteLine(serviceProperties.HourMetrics.MetricsLevel);
    Console.WriteLine(serviceProperties.HourMetrics.RetentionDays);
    Console.WriteLine(serviceProperties.HourMetrics.Version);
}
```
## [Microsoft Teams Webhook](https://learn.microsoft.com/en-us/microsoftteams/platform/webhooks-and-connectors/how-to/connectors-using)
إذا أعاد الأمر التالي `Summary or Text is required.`، فهذا يعني أن عنوان URL صالح. إذا أعاد `Invalid webhook URL` أو أي استجابة أخرى، فهذا يعني أن عنوان URL غير صالح.```
curl -H "Content-Type:application/json" -d "{'text':''}" "YOUR_WEBHOOK_URL"
```
## [مفتاح API الشخصي لـ New Relic (NerdGraph)](https://docs.newrelic.com/docs/apis/nerdgraph/get-started/introduction-new-relic-nerdgraph#endpoint)```
curl -X POST https://api.newrelic.com/graphql \
-H 'Content-Type: application/json' \
-H 'API-Key: YOUR_API_KEY' \
-d '{ "query":  "{ requestContext { userId apiKey } }" } '
```
## [New Relic REST API](https://docs.newrelic.com/docs/apis/rest-api-v2/application-examples-v2/list-your-app-id-metric-timeslice-data-v2)```
curl -X GET 'https://api.newrelic.com/v2/applications.json' \
     -H "X-Api-Key:${APIKEY}" -i
```
إذا كان صالحًا، اختبر أكثر لترى ما إذا كان [مفتاح مسؤول](https://docs.newrelic.com/docs/apis/get-started/intro-apis/types-new-relic-api-keys#admin)

## [مفتاح Heroku API](https://devcenter.heroku.com/articles/platform-api-quickstart)```
curl -X POST https://api.heroku.com/apps -H "Accept: application/vnd.heroku+json; version=3" -H "Authorization: Bearer API_KEY_HERE"
```
## [مفتاح Mapbox API](https://docs.mapbox.com/api/)

تبدأ مفاتيح Mapbox السرية بـ `sk`، وباقي المفاتيح تبدأ بـ `pk` (رمز عام)، `sk` (رمز سري)، أو `tk` (رمز مؤقت).```
curl "https://api.mapbox.com/geocoding/v5/mapbox.places/Los%20Angeles.json?access_token=ACCESS_TOKEN"

#Check token validity
curl "https://api.mapbox.com/tokens/v2?access_token=YOUR_MAPBOX_ACCESS_TOKEN"

#Get list of all tokens associated with an account. (only works if the token is a Secret Token (sk), and has the appropiate scope)
curl "https://api.mapbox.com/tokens/v2/MAPBOX_USERNAME_HERE?access_token=YOUR_MAPBOX_ACCESS_TOKEN"
```
## [مفتاح Salesforce API](https://developer.salesforce.com/docs/atlas.en-us.api_rest.meta/api_rest/quickstart_oauth.htm)```
curl https://instance_name.salesforce.com/services/data/v20.0/ -H 'Authorization: Bearer access_token_here'
```
## [مفتاح API Algolia](https://www.algolia.com/doc/rest-api/search/#overview)

إذا كان المفتاح لديه صلاحية `listIndexes`، يمكنك سرد الفهارس باستخدام:```
curl --request GET \
  --url https://<example-app-id>-1.algolianet.com/1/indexes/ \
  --header 'content-type: application/json' \
  --header 'x-algolia-api-key: <example-key>' \
  --header 'x-algolia-application-id: <example-appid>'
```
وإلا فسيتعين عليك معرفة اسم الفهرس (تحقق من الكود المصدري للتطبيق أو الطلبات التي يقوم بها). ثم لتعداد محتواه:```
curl --request GET \
  --url https://<example-app-id>-1.algolianet.com/1/indexes/<example-index> \
  --header 'content-type: application/json' \
  --header 'x-algolia-api-key: <example-key>' \
  --header 'x-algolia-application-id: <example-appid>'
```
كن حذرًا عند تشغيل هذا الأمر، لأن الحمولة (payload) قد تُنفذ ضمن بيئة إدارية، اعتمادًا على الفهرس الذي تقوم بتحرير `highlightPreTag` فيه. يُوصى باستخدام حمولة أكثر هدوءًا (مثل XSS Hunter) لإثبات هجوم البرمجة النصية عبر المواقع (cross-site scripting) المحتمل.```
curl --request PUT \
  --url https://<application-id>-1.algolianet.com/1/indexes/<example-index>/settings \
  --header 'content-type: application/json' \
  --header 'x-algolia-api-key: <example-key>' \
  --header 'x-algolia-application-id: <example-application-id>' \
  --data '{"highlightPreTag": "<script>alert(1);</script>"}'
```
## [Zapier Webhook Token](https://zapier.com/help/how-get-started-webhooks-zapier/)```
curl -H "Accept: application/json" -H "Content-Type: application/json" -X POST -d '{"name":"streaak"}' "webhook_url_here"
```
## [رمز API Pagerduty](https://support.pagerduty.com/docs/using-the-api)```
curl -H "Accept: application/vnd.pagerduty+json;version=2"  -H "Authorization: Token token=TOKEN_HERE" -X GET  "https://api.pagerduty.com/schedules"
```
## [مفتاح الوصول لـ BrowserStack](https://www.browserstack.com/automate/rest-api)```
curl -u "USERNAME:ACCESS_KEY" https://api.browserstack.com/automate/plan.json
```
## [مفتاح واجهة برمجة تطبيقات خرائط Google](https://developers.google.com/maps/documentation/javascript/get-api-key)

**يتم تعيين قيود المفتاح لكل خدمة. عند اختبار المفتاح، إذا كان المفتاح مقيدًا/غير نشط على خدمة واحدة، جربه مع أخرى.**

| الاسم| نقطة النهاية| التسعير|
| ------------- |:-------------:| -----:|
| خرائط ثابتة     | https://maps.googleapis.com/maps/api/staticmap?center=45%2C10&zoom=7&size=400x400&key=KEY_HERE| $2 |
| عرض الشارع     | https://maps.googleapis.com/maps/api/streetview?size=400x400&location=40.720032,-73.988354&fov=90&heading=235&pitch=10&key=KEY_HERE| $7 |
| تضمين | https://www.google.com/maps/embed/v1/place?q=place_id:ChIJyX7muQw8tokR2Vf5WBBk1iQ&key=KEY_HERE| يختلف |
| الاتجاهات | https://maps.googleapis.com/maps/api/directions/json?origin=Disneyland&destination=Universal+Studios+Hollywood4&key=KEY_HERE| $5 |
| الترميز الجغرافي | https://maps.googleapis.com/maps/api/geocode/json?latlng=40,30&key=KEY_HERE| $5 |
| مصفوفة المسافات| https://maps.googleapis.com/maps/api/distancematrix/json?units=imperial&origins=40.6655101,-73.89188969999998&destinations=40.6905615%2C-73.9976592%7C40.6905615%2C-73.9976592%7C40.6905615%2C-73.9976592%7C40.6905615%2C-73.9976592%7C40.6905615%2C-73.9976592%7C40.6905615%2C-73.9976592%7C40.659569%2C-73.933783%7C40.729029%2C-73.851524%7C40.6860072%2C-73.6334271%7C40.598566%2C-73.7527626%7C40.659569%2C-73.933783%7C40.729029%2C-73.851524%7C40.6860072%2C-73.6334271%7C40.598566%2C-73.7527626&key=KEY_HERE | $5 |
|البحث عن مكان من النص | https://maps.googleapis.com/maps/api/place/findplacefromtext/json?input=Museum%20of%20Contemporary%20Art%20Australia&inputtype=textquery&fields=photos,formatted_address,name,rating,opening_hours,geometry&key=KEY_HERE | يختلف |
| الإكمال التلقائي | https://maps.googleapis.com/maps/api/place/autocomplete/json?input=Bingh&types=%28cities%29&key=KEY_HERE| يختلف |
| الارتفاع | https://maps.googleapis.com/maps/api/elevation/json?locations=39.7391536,-104.9847034&key=KEY_HERE | $5 |
| المنطقة الزمنية | https://maps.googleapis.com/maps/api/timezone/json?location=39.6034810,-119.6822510&timestamp=1331161200&key=KEY_HERE | $5 |
| الطرق | https://roads.googleapis.com/v1/nearestRoads?points=60.170880,24.942795\|60.170879,24.942796\|60.170877,24.942796&key=KEY_HERE | $10|
| تحديد الموقع الجغرافي | https://www.googleapis.com/geolocation/v1/geolocate?key=KEY_HERE| $5 |

*\*التسعير بالدولار الأمريكي لكل 1000 طلب (لأول 100 ألف طلب)*

مزيد من المعلومات متاح هنا-

https://medium.com/@ozguralp/unauthorized-google-maps-api-key-usage-cases-and-why-you-need-to-care-1ccb28bf21e

https://github.com/ozguralp/gmapsapiscanner/

https://developers.google.com/maps/api-key-best-practices

## [مفتاح Google Recaptcha](https://developers.google.com/recaptcha/docs/verify)

أرسل طلب POST إلى عنوان URL التالي:```
https://www.google.com/recaptcha/api/siteverify
```
`secret` و `response` هما معلمتا POST مطلوبتان، حيث `secret` هو المفتاح و `response` هو الرد الذي سيتم اختباره.

التعبير المنتظم: `^6[0-9a-zA-Z_-]{39}$`. يبدأ مفتاح API دائمًا بـ 6 ويتكون من 40 حرفًا. اقرأ المزيد هنا: https://developers.google.com/recaptcha/docs/verify.

## [بيانات اعتماد حساب الخدمة في Google Cloud](https://cloud.google.com/docs/authentication/production)

قد توجد بيانات اعتماد حساب الخدمة في ملف JSON مثل هذا:```
$ cat service_account.json
{
  "type": "service_account",
  "project_id": "...",
  "private_key_id": "...",
  "private_key": "-----BEGIN PRIVATE KEY-----...-----END PRIVATE KEY-----\n",
  "client_email": "...",
  "client_id": "...",
  "auth_uri": "https://accounts.google.com/o/oauth2/auth",
  "token_uri": "https://oauth2.googleapis.com/token",
  "auth_provider_x509_cert_url": "https://www.googleapis.com/oauth2/v1/certs",
  "client_x509_cert_url": "https://www.googleapis.com/robot/v1/metadata/x509/..."
}
```
إذا كانت هذه هي حالتك، يمكنك التحقق من هذه البيانات باستخدام أداة `gcloud` ([كيفية تثبيت `gcloud`](https://cloud.google.com/sdk/docs/quickstart-debian-ubuntu)):```
$ gcloud auth activate-service-account --key-file=service_account.json
Activated service account credentials for: [...]
$ gcloud auth print-access-token
ya29.c...
```
في حالة النجاح، سترى رمز الوصول مطبوعًا في الطرفية. يُرجى ملاحظة أنه بعد التحقق من صحة بيانات الاعتماد، قد ترغب في تعداد صلاحيات هذه البيانات، وهو أمر يختلف عن ذلك.

## [مفتاح وسري Branch.IO](https://docs.branch.io/pages/apps/deep-linking-api/#app-read)

قم بزيارة الرابط التالي للتحقق من الصلاحية:```
https://api2.branch.io/v1/app/KEY_HERE?branch_secret=SECRET_HERE
```
## [مفتاح API خرائط بينج](https://docs.microsoft.com/en-us/bingmaps/rest-services/locations/find-a-location-by-address)

قم بزيارة هذا الرابط للتحقق من صلاحية المفتاح. يجب أن يبدأ الرد الخاص بالمفتاح الصالح بـ `authenticationResultCode:	"ValidCredentials"````
https://dev.virtualearth.net/REST/v1/Locations?CountryRegion=US&adminDistrict=WA&locality=Somewhere&postalCode=98001&addressLine=100%20Main%20St.&key=API_KEY
```
## [رمز وصول Bit.ly](https://dev.bitly.com/authentication.html)

قم بزيارة الرابط التالي للتحقق من الصلاحية:```
https://api-ssl.bitly.com/v3/shorten?access_token=ACCESS_TOKEN&longUrl=https://www.google.com
```
## [Buildkite رمز الوصول](https://buildkite.com/docs/apis/rest-api)```
curl -H "Authorization: Bearer ACCESS_TOKEN" \
https://api.buildkite.com/v2/access-token
```
## [ButterCMS-API-Key](https://buttercms.com/docs/api/#authentication)```
curl -X GET 'https://api.buttercms.com/v2/posts/?auth_token=your_api_token'
```
## [Asana رمز الوصول](https://asana.com/developers/documentation/getting-started/auth#personal-access-token)```
curl -H "Authorization: Bearer ACCESS_TOKEN" https://app.asana.com/api/1.0/users/me
```
## [Zendesk رمز الوصول](https://support.zendesk.com/hc/en-us/articles/203663836-Using-OAuth-authentication-with-your-application)```
curl https://{subdomain}.zendesk.com/api/v2/tickets.json \
  -H "Authorization: Bearer ACCESS_TOKEN"
```
## [Zendesk Api Key](https://developer.zendesk.com/api-reference/ticketing/introduction/)
رموز API تختلف عن رموز OAuth، رموز API هي كلمات مرور مولدة تلقائياً في واجهة إدارة Support.```
curl https://{target}.zendesk.com/api/v2/users.json \  -u support@{target}.com/token:{here your token}
```
## [MailChimp API Key](https://developer.mailchimp.com/documentation/mailchimp/reference/overview/)```
curl --request GET --url 'https://<dc>.api.mailchimp.com/3.0/' --user 'anystring:<API_KEY>' --include
```
## [مفتاح WPEngine API](https://wpengineapi.com/)

يمكن استغلال هذه المشكلة بشكل أكبر من خلال الاطلاع على [@hateshape](https://github.com/hateshape/)'s gist https://gist.github.com/hateshape/2e671ea71d7c243fac7ebf51fb738f0a.```
curl "https://api.wpengine.com/1.2/?method=site&account_name=ACCOUNT_NAME&wpe_apikey=WPENGINE_APIKEY"
```
## [مفتاح API الخاص بـ DataDog](https://docs.datadoghq.com/api/)```
curl "https://api.datadoghq.com/api/v1/dashboard?api_key=<api_key>&application_key=<application_key>"
```
## [مفتاح Delighted API](https://app.delighted.com/docs/api)
لا تحذف `:` في النهاية.```
curl https://api.delighted.com/v1/metrics.json \
  -H "Content-Type: application/json" \
  -u YOUR_DELIGHTED_API_KEY:
```
## [رمز API لـ Travis CI](https://developer.travis-ci.com/gettingstarted)```
curl -H "Travis-API-Version: 3" -H "Authorization: token <TOKEN>" https://api.travis-ci.org/repos
```
## [توكن API بوت تيليغرام](https://core.telegram.org/bots/api#making-requests)```
curl https://api.telegram.org/bot<TOKEN>/getMe
```
## [مفتاح API WakaTime](https://wakatime.com/developers)```
curl "https://wakatime.com/api/v1/users/current?api_key=KEY_HERE"
```
## [رمز Sonarcloud](https://sonarcloud.io/web_api)```
curl -u <token>: "https://sonarcloud.io/api/authentication/validate"
```
## [Spotify Access Token](https://developer.spotify.com/documentation/general/guides/authorization-guide/)```
curl -H "Authorization: Bearer <ACCESS_TOKEN>" https://api.spotify.com/v1/me
```
## [رمز الوصول لواجهة برمجة التطبيقات (API) للعرض الأساسي في Instagram](https://developers.facebook.com/docs/instagram-basic-display-api/getting-started)
E.g.: IGQVJ...```
curl -X GET 'https://graph.instagram.com/{user-id}?fields=id,username&access_token={access-token}'
```
## [رمز الوصول لـ Instagram Graph API](https://developers.facebook.com/docs/instagram-api/getting-started)
مثال: EAAJjmJ...```
curl -i -X GET 'https://graph.facebook.com/v8.0/me/accounts?access_token={access-token}'
```
## [رمز الوصول الشخصي لجيتلاب](https://docs.gitlab.com/ee/api/README.html#personal-access-tokens)```
curl "https://gitlab.example.com/api/v4/projects?private_token=<your_access_token>"
```
## [GitLab runner registration token](https://docs.gitlab.com/runner/register/)```
docker run --rm gitlab/gitlab-runner register \
  --non-interactive \
  --executor "docker" \
  --docker-image alpine:latest \
  --url "https://gitlab.com/" \
  --registration-token "PROJECT_REGISTRATION_TOKEN" \
  --description "keyhacks-test" \
  --maintenance-note "Testing token with keyhacks" \
  --tag-list "docker,aws" \
  --run-untagged="true" \
  --locked="false" \
  --access-level="not_protected"
```
## [معرف عميل Paypal والمفتاح السري](https://developer.paypal.com/docs/api/get-an-access-token-curl/)```
curl -v https://api.sandbox.paypal.com/v1/oauth2/token \
   -H "Accept: application/json" \
   -H "Accept-Language: en_US" \
   -u "client_id:secret" \
   -d "grant_type=client_credentials"
```
يمكن استخدام رمز الوصول (access token) بشكل إضافي لاستخراج البيانات من واجهة برمجة تطبيقات PayPal. مزيد من المعلومات: https://developer.paypal.com/docs/api/overview/#make-rest-api-calls.

يمكن التحقق من ذلك باستخدام:```
curl -v -X GET "https://api.sandbox.paypal.com/v1/identity/oauth2/userinfo?schema=paypalv1.1" -H "Content-Type: application/json" -H "Authorization: Bearer [ACCESS_TOKEN]"
```
## [رمز Stripe المباشر](https://stripe.com/docs/api/authentication)```
curl https://api.stripe.com/v1/charges -u token_here:
```
احتفظ بنقطتين في نهاية الرمز المميز لمنع `cURL` من طلب كلمة مرور.

الرمز المميز دائمًا بالتنسيق التالي: `sk_live_24charshere`، حيث يحتوي الجزء `24charshere` على 24 حرفًا من `a-z A-Z 0-9`. يوجد أيضًا مفتاح اختبار يبدأ بـ `sk_test`، لكن هذا المفتاح لا قيمة له لأنه يُستخدم فقط لأغراض الاختبار وعلى الأرجح لا يحتوي على أي معلومات حساسة. من ناحية أخرى، يمكن استخدام المفتاح الحي لاستخراج/استرداد الكثير من المعلومات — بدءًا من الرسوم وصولاً إلى قائمة المنتجات الكاملة.

ضع في اعتبارك أنك لن تتمكن أبدًا من الحصول على معلومات بطاقة الائتمان الكاملة لأن Stripe يعطيك فقط آخر 4 أرقام.

المزيد من المعلومات/التوثيق الكامل: https://stripe.com/docs/api/authentication.

## [مفتاح واجهة برمجة تطبيقات Razorpay والمفتاح السري](https://razorpay.com/docs/api/)

يمكن التحقق من ذلك باستخدام:```
curl -u <YOUR_KEY_ID>:<YOUR_KEY_SECRET> \
  https://api.razorpay.com/v1/payments
```
## [CircleCI رمز الوصول](https://circleci.com/docs/api/#api-overview)```
curl https://circleci.com/api/v1.1/me?circle-token=<TOKEN>
```
## [مفتاح API لـ Cloudflare](https://api.cloudflare.com/#user-api-tokens-verify-token)```
curl -X GET "https://api.cloudflare.com/client/v4/user/tokens/verify" \
  -H "Authorization: Bearer <YOUR_API_TOKEN>"
```
## [Loqate API key](https://www.loqate.com/resources/support/apis)```
curl 'http://api.addressy.com/Capture/Interactive/Find/v1.00/json3.ws?Key=<KEY_HERE>&Countries=US,CA&Language=en&Limit=5&Text=BHAR'
```
## [Ipstack API Key](https://ipstack.com/documentation)```
curl 'https://api.ipstack.com/{ip_address}?access_key={keyhere}'
```
## [رمز NPM](https://docs.npmjs.com/about-authentication-tokens)

يمكنك التحقق من رمز NPM [باستخدام `npm`](https://medium.com/bugbountywriteup/one-token-to-leak-them-all-the-story-of-a-8000-npm-token-79b13af182a3) (مع استبدال `00000000-0000-0000-0000-000000000000` برمز NPM):```
export NPM_TOKEN="00000000-0000-0000-0000-000000000000"
echo "//registry.npmjs.org/:_authToken=${NPM_TOKEN}" > .npmrc
npm whoami
```
طريقة أخرى للتحقق من token هي الاستعلام مباشرة عن API:```
curl -H 'authorization: Bearer 00000000-0000-0000-0000-000000000000' 'https://registry.npmjs.org/-/whoami'
```
ستحصل على اسم المستخدم في الرد في حالة النجاح، `401 Unauthorized` في حالة عدم وجود التوكن، و `403 Forbidden` في حالة عدم إدراج عنوان IP الخاص بك في القائمة البيضاء.

يمكن أن يكون توكن NPM [مقيدًا بـ CIDR](https://docs.npmjs.com/creating-and-viewing-authentication-tokens#creating-tokens-with-the-cli). لذلك إذا كنت تستخدم توكنًا من CIDR *غير مدرج في القائمة البيضاء*، فستحصل على `403 Forbidden` في الرد. لذا حاول التحقق من توكن NPM من نطاقات IP مختلفة!.

ملاحظة: بعض الشركات [تستخدم سجلات غير `registry.npmjs.org`](https://medium.com/bugbountywriteup/one-token-to-leak-them-all-the-story-of-a-8000-npm-token-79b13af182a3). إذا كان الأمر كذلك، استبدل جميع تكرارات `registry.npmjs.org` باسم نطاق سجل NPM الخاص بالشركة.

## [مفتاح OpsGenie API](https://docs.opsgenie.com/docs/api-overview)```
curl https://api.opsgenie.com/v2/alerts -H 'Authorization: GenieKey API_KEY'
```
## [مفتاح API لـ Keen.io](https://keen.io/docs/api/)

الحصول على جميع المجموعات لمشروع معين:```
curl "https://api.keen.io/3.0/projects/PROJECT_ID/events?api_key=READ_KEY"
```
>ملاحظة: احتفظ بنقطتين رأسيتين في نهاية الرمز لمنع cURL من طلب كلمة مرور.
معلومات: الرمز دائمًا بالتنسيق التالي: sk_live_34charshere، حيث يحتوي الجزء 34charshere على 34 حرفًا من a-z A-Z 0-9
يوجد أيضًا مفتاح اختبار يبدأ بـ sk_test، لكن هذا المفتاح لا قيمة له لأنه يُستخدم فقط لأغراض الاختبار وعلى الأرجح لا يحتوي على أي معلومات حساسة.
أما المفتاح الحي، من ناحية أخرى، فيمكن استخدامه لاستخراج/استرداد الكثير من المعلومات. بدءًا من الرسوم، وصولاً إلى قائمة المنتجات الكاملة.
ضع في اعتبارك أنك لن تتمكن أبدًا من الحصول على معلومات بطاقة الائتمان الكاملة لأن stripe يعطيك فقط آخر 4 أرقام.
مزيد من المعلومات / الوثائق الكاملة: https://stripe.com/docs/api/authentication
=======

## [مفتاح Calendly API](https://developer.calendly.com/docs/)

الحصول على معلومات المستخدم:````
curl --header "X-TOKEN: <your_token>" https://calendly.com/api/v1/users/me
````
قائمة اشتراكات Webhook:````
curl --header "X-TOKEN: <your_token>" https://calendly.com/api/v1/hooks
````
## [Azure Application Insights APP ID and API Key](https://dev.applicationinsights.io/reference)

احصل على العدد الإجمالي للطلبات التي تم إجراؤها في آخر 24 ساعة:```
curl -H "x-api-key: {API_Key}" "https://api.applicationinsights.io/v1/apps/{APP_ID}/metrics/requests/count"
```
## [مفتاح تسجيل Cypress](https://docs.cypress.io/guides/dashboard/projects.html#Record-key)

للتحقق من صلاحية `recordKey` ستحتاج إلى `projectId` وهي قيمة عامة يمكن عادةً العثور عليها في ملف `cypress.json`. استبدل `{recordKey}` و`{projectId}` في نص JSON بقيمك.```
curl -i -s -k -X $'POST' \
    -H $'x-route-version: 4' -H $'x-os-name: darwin' -H $'x-cypress-version: 5.5.0' -H $'host: api.cypress.io' -H $'accept: application/json' -H $'content-type: application/json' -H $'Content-Length: 1433' -H $'Connection: close' \
    --data-binary $'{\"ci\":{\"params\":null,\"provider\":null},\"specs\":[\"cypress/integration/examples/actions.spec.js\",\"cypress/integration/examples/aliasing.spec.js\",\"cypress/integration/examples/assertions.spec.js\",\"cypress/integration/examples/connectors.spec.js\",\"cypress/integration/examples/cookies.spec.js\",\"cypress/integration/examples/cypress_api.spec.js\",\"cypress/integration/examples/files.spec.js\",\"cypress/integration/examples/local_storage.spec.js\",\"cypress/integration/examples/location.spec.js\",\"cypress/integration/examples/misc.spec.js\",\"cypress/integration/examples/navigation.spec.js\",\"cypress/integration/examples/network_requests.spec.js\",\"cypress/integration/examples/querying.spec.js\",\"cypress/integration/examples/spies_stubs_clocks.spec.js\",\"cypress/integration/examples/traversal.spec.js\",\"cypress/integration/examples/utilities.spec.js\",\"cypress/integration/examples/viewport.spec.js\",\"cypress/integration/examples/waiting.spec.js\",\"cypress/integration/examples/window.spec.js\"],\"commit\":{\"sha\":null,\"branch\":null,\"authorName\":null,\"authorEmail\":null,\"message\":null,\"remoteOrigin\":null,\"defaultBranch\":null},\"group\":null,\"platform\":{\"osCpus\":[],\"osName\":\"darwin\",\"osMemory\":{\"free\":1153744896,\"total\":17179869184},\"osVersion\":\"19.6.0\",\"browserName\":\"Electron\",\"browserVersion\":\"85.0.4183.121\"},\"parallel\":null,\"ciBuildId\":null,\"projectId\":\"{projectId}\",\"recordKey\":\"{recordKey}\",\"specPattern\":null,\"tags\":[\"\"]}' \
    $'https://api.cypress.io/runs'
```
نعم، يجب أن يكون هذا الطلب بهذا الحجم. سيعرض رمز `200 OK` مع بعض المعلومات حول التشغيل إذا كان كل من `projectId` و`recordKey` صالحين، و`404 Not Found` مع `{"message":"Project not found. Invalid projectId."}` إذا كان `projectId` غير صالح، أو `401 Unauthorized` مع `{"message":"Invalid Record Key."}` إذا كان `recordKey` غير صالح.

مثال على `projectId` هو `1yxykz` ومثال على `recordKey` هو `a216e7b4-4819-4713-b9c2-c5da60a1c48c`.

## [YouTube API Key](https://developers.google.com/youtube/v3/docs/)
جلب تفاصيل المحتوى لقناة يوتيوب (حيث يشير `channelId` في هذه الحالة إلى قناة PewDiePie).```
curl -iLk 'https://www.googleapis.com/youtube/v3/activities?part=contentDetails&maxResults=25&channelId=UC-lHJZR3Gqxm24_Vd_AJ5Yw&key={KEY_HERE}'
```
## [مفتاح API لـ ABTasty](https://developers.abtasty.com/server-side.html#authentication)```
curl "api_endpoint_here" -H "x-api-key: your_api_key"
```
## [مفتاح API الخاص بـ Iterable](https://api.iterable.com/api/docs)
تصدير بيانات تحليلات الحملات بتنسيق JSON، إدخال واحد لكل سطر. مطلوب استخدام إما 'range' أو 'startDateTime' و 'endDateTime'.```
curl -H "Api_Key: {API_KEY}" https://api.iterable.com/api/export/data.json?dataTypeName=emailSend&range=Today&onlyFields=List.empty
```
## [مفاتيح Amplitude API](https://help.amplitude.com/hc/en-us/articles/205406637-Export-API-Export-Your-Project-s-Event-Data)
الاستجابة عبارة عن أرشيف مضغوط من ملفات JSON، مع احتمالية وجود ملفات متعددة لكل ساعة. لاحظ أن الأحداث التي تسبق تاريخ 2014-11-12 سيتم تجميعها حسب اليوم بدلاً من الساعة. إذا قمت بطلب بيانات لنطاق زمني لم يتم فيه جمع أي بيانات للمشروع، فستتلقى استجابة 404 من الخادم.```
curl -u API_Key:Secret_Key 'https://amplitude.com/api/2/export?start=20200201T5&end=20210203T20' >> yourfilename.zip
```
## [رمز API لـ Visual Studio App Center](https://docs.microsoft.com/en-us/appcenter/api-docs/)
   
   1. قائمة بجميع مشاريع التطبيقات لرمز API:  ```
  curl -sX GET  "https://api.appcenter.ms/v0.1/apps" \
 -H "Content-Type: application/json" \
 -H "X-Api-Token: {your_api_token}"
  ```
2. جلب أحدث معلومات بناء التطبيق لمشروع معين:
   > استخدم `name` و `owner.name` اللذان تم الحصول عليهما في الرد في الخطوة [1](#438).  ```
  curl -sX GET  "https://api.appcenter.ms/v0.1/apps/{owner.name}/{name}/releases/latest" \
-H "Content-Type: application/json" \
-H "X-Api-Token: {your_api_token}"
  ```
## [WeGlot مفتاح API](https://weglot.com/)```
curl -X POST \
  'https://api.weglot.com/translate?api_key=my_api_key' \
  -H 'Content-Type: application/json' \
  -d '{  
   "l_from":"en",
   "l_to":"fr",
   "request_url":"https://www.website.com/",
   "words":[  
      {"w":"This is a blue car", "t": 1},
      {"w":"This is a black car", "t": 1}
   ]
}'
```
## [رمز API لـ PivotalTracker](https://www.pivotaltracker.com/help/api/#top)

   1. قم بإدراج معلومات المستخدم باستخدام رمز API:   ```
   curl -X GET -H "X-TrackerToken: $TOKEN" "https://www.pivotaltracker.com/services/v5/me?fields=%3Adefault"
   ```
1. احصل على رمز API باستخدام بيانات اعتماد مستخدم صالحة:   ```
   curl -s -X GET --user 'USER:PASSWORD' "https://www.pivotaltracker.com/services/v5/me -o pivotaltracker.json"
   jq --raw-output .api_token pivotaltracker.json
   ```
## [LinkedIn OAUTH](https://docs.microsoft.com/en-us/linkedin/shared/authentication/client-credentials-flow?context=linkedin/context)
يؤدي طلب رمز الوصول الناجح إلى إرجاع كائن JSON يحتوي على access_token, expires_in.```
curl -XPOST -H "Content-type: application/x-www-form-urlencoded" -d 'grant_type=client_credentials&client_id=<client-ID>&client_secret=<client-secret>' 'https://www.linkedin.com/oauth/v2/accessToken'

```
## [Help Scout OAUTH](https://developer.helpscout.com/mailbox-api/overview/authentication/)
يُرجع طلب رمز الوصول الناجح كائن JSON يحتوي على token_type، access_token، expires_in.```
curl -X POST https://api.helpscout.net/v2/oauth2/token \
    --data "grant_type=client_credentials" \
    --data "client_id={application_id}" \
    --data "client_secret={application_secret}"
```
## [Shodan Api Key](https://developer.shodan.io/api/requirements)```
curl "https://api.shodan.io/shodan/host/8.8.8.8?key=TOKEN_HERE"
```
## [Bazaarvoice Passkey](https://developer.bazaarvoice.com/conversations-api/home)
يعيد طلب Passkey الناجح كائن JSON يحتوي على اسم الشركة```
curl 'https://which-cpv-api.bazaarvoice.com/clientInfo?conversationspasskey=<Passkey>' --insecure 

```
## [رمز وصول Grafana](https://grafana.com/docs/grafana/latest/developers/http_api/user/)
يدعم Grafana API مخططات التوثيق Bearer و Basic. Bearer:```
curl -s -H "Authorization: Bearer your-api-key" http://your-grafana-server-url.com/api/user
```
أساسي:```
curl -u username:password http://your-grafana-server-url.com/api/user
```
# المساهمة

أرحب بالمساهمات من الجمهور.

### استخدام متتبع المشكلات 💡

متتبع المشكلات هو القناة المفضلة لتقارير الأخطاء وطلبات الميزات.

### المشكلات والعلامات 🏷

يستخدم متتبع الأخطاء عدة علامات للمساعدة في تنظيم وتحديد المشكلات.

### إرشادات لتقارير الأخطاء 🐛

استخدم بحث مشكلات GitHub — تحقق مما إذا كان قد تم الإبلاغ عن المشكلة بالفعل.

# ⚠ إخلاء المسؤولية القانوني

تم إنشاء هذا المشروع لأغراض تعليمية واختبار أخلاقي فقط. استخدام هذه الأداة لمهاجمة أهداف دون موافقة متبادلة مسبقة غير قانوني. المطورون لا يتحملون أي مسؤولية ولا يتحملون مسؤولية أي إساءة استخدام أو ضرر ناتج عن هذه الأداة.
تنزيل الأداة