
버그 바운티 프로그램 및 침투 테스트에서 유출된 API 키를 검증하기 위한 명령어 모음입니다. AWS, GitHub, Slack, Twilio 등 80개 이상의 서비스를 다룹니다.
<p align="center">
<img src="https://assets.kitploit.com/production/public/readmes/4653/0b5b34d5398000ecc5e0743d278876caf96f87191f91a06860c706905996a642.png" width="300px">
</p>
</br>
KeyHacks는 버그 바운티 프로그램이나 침투 테스트에서 발견된 다양한 API 키를 검증하는 방법을 보여줍니다.
@Gwen001가 전체 프로세스를 스크립트로 작성했으며, [여기](https://github.com/gwen001/pentest-tools/blob/master/keyhacks.sh)에서 찾을 수 있습니다.
# 목차
- [ABTasty API 키](#ABTasty-API-Key)
- [Algolia API 키](#Algolia-API-key)
- [Amplitude API 키](#Amplitude-API-Keys)
- [Asana 액세스 토큰](#Asana-Access-Token)
- [AWS 액세스 키 ID 및 시크릿](#AWS-Access-Key-ID-and-Secret)
- [Azure Application Insights 앱 ID 및 API 키](#Azure-Application-Insights-APP-ID-and-API-Key)
- [Bazaarvoice 패스키](#Bazaarvoice-Passkey)
- [Bing Maps API 키](#Bing-Maps-API-Key)
- [Bit.ly 액세스 토큰](#Bitly-Access-token)
- [Branch.io 키 및 시크릿](#BranchIO-Key-and-Secret)
- [BrowserStack 액세스 키](#BrowserStack-Access-Key)
- [Buildkite 액세스 토큰](#Buildkite-Access-token)
- [ButterCMS API 키](#ButterCMS-API-Key)
- [Calendly API 키](#Calendly-API-Key)
- [Contentful 액세스 토큰](#Contentful-access-token)
- [CircleCI 액세스 토큰](#CircleCI-Access-Token)
- [Cloudflare API 키](#cloudflare-api-key)
- [Cypress 레코드 키](#Cypress-record-key)
- [DataDog API 키](#DataDog-API-key)
- [Delighted API 키](#Delighted-api-key)
- [Deviant Art 액세스 토큰](#Deviant-Art-Access-Token)
- [Deviant Art 시크릿](#Deviant-Art-Secret)
- [Dropbox API](#Dropbox-API)
- [Facebook 액세스 토큰](#Facebook-Access-Token)
- [Facebook 앱 시크릿](#Facebook-AppSecret)
- [Firebase](#Firebase)
- [Firebase Cloud Messaging (FCM)](#Firebase-Cloud-Messaging)
- [FreshDesk API 키](#FreshDesk-API-key)
- [Github 클라이언트 ID 및 클라이언트 시크릿](#Github-client-id-and-client-secret)
- [GitHub 프라이빗 SSH 키](#GitHub-private-SSH-key)
- [Github 토큰](#Github-Token)
- [Gitlab 개인 액세스 토큰](#Gitlab-personal-access-token)
- [GitLab 러너 등록 토큰](#Gitlab-runner-registration-token)
- [Google Cloud 서비스 계정 자격 증명](#Google-Cloud-Service-Account-credentials)
- [Google Maps API 키](#Google-Maps-API-key)
- [Google Recaptcha 키](#Google-Recaptcha-key)
- [Grafana 액세스 토큰](#Grafana-Access-Token)
- [Help Scout OAUTH](#Help-Scout-OAUTH)
- [Heroku API 키](#Heroku-API-key)
- [HubSpot API 키](#Hubspot-API-key)
- [Infura API 키](#Infura-API-key)
- [Instagram 액세스 토큰](#Instagram-Access-Token)
- [Instagram Basic Display API](#Instagram-Basic-Display-API-Access-Token)
- [Instagram Graph API](#Instagram-Graph-Api-Access-Token)
- [Ipstack API 키](#Ipstack-API-Key)
- [Iterable API 키](#Iterable-API-Key)
- [JumpCloud API 키](#JumpCloud-API-Key)
- [Keen.io API 키](#Keenio-API-Key)
- [LinkedIn OAUTH](#LinkedIn-OAUTH)
- [Lokalise API 키](#Lokalise-API-Key)
- [Loqate API 키](#Loqate-API-key)
- [MailChimp API 키](#MailChimp-API-Key)
- [MailGun 프라이빗 키](#MailGun-Private-Key)
- [Mapbox API 키](#Mapbox-API-Key)
- [Microsoft Azure 테넌트](#Microsoft-Azure-Tenant)
- [Microsoft 공유 액세스 서명 (SAS)](#Microsoft-Shared-Access-Signatures-(SAS))
- [Microsoft Teams 웹훅](#Microsoft-Teams-Webhook)
- [New Relic 개인 API 키 (NerdGraph)](#New-Relic-Personal-API-Key-(NerdGraph))
- [New Relic REST API](#New-Relic-REST-API)
- [NPM 토큰](#NPM-token)
- [OpsGenie API 키](#OpsGenie-API-Key)
- [Pagerduty API 토큰](#Pagerduty-API-token)
- [Paypal 클라이언트 ID 및 시크릿 키](#Paypal-client-id-and-secret-key)
- [Pendo 통합 키](#Pendo-Integration-Key)
- [PivotalTracker API 토큰](#PivotalTracker-API-Token)
- [Razorpay API 키 및 시크릿 키](#Razorpay-keys)
- [Salesforce API 키](#Salesforce-API-key)
- [SauceLabs 사용자 이름 및 액세스 키](#SauceLabs-Username-and-access-Key)
- [SendGrid API 토큰](#SendGrid-API-Token)
- [Shodan.io](#Shodan-Api-Key)
- [Slack API 토큰](#Slack-API-token)
- [Slack 웹훅](#Slack-Webhook)
- [Sonarcloud](#Sonarcloud-Token)
- [Spotify 액세스 토큰](#Spotify-Access-Token)
- [Square](#Square)
- [Stripe 라이브 토큰](#Stripe-Live-Token)
- [Telegram 봇 API 토큰](#Telegram-Bot-API-Token)
- [Travis CI API 토큰](#Travis-CI-API-token)
- [Twilio 계정 SID 및 인증 토큰](#Twilio-Account_sid-and-Auth-token)
- [Twitter API 시크릿](#Twitter-API-Secret)
- [Twitter 베어러 토큰](#Twitter-Bearer-token)
- [Visual Studio App Center API 토큰](#Visual-Studio-App-Center-API-Token)
- [WakaTime API 키](#WakaTime-API-Key)
- [WeGlot API 키](#weglot-api-key)
- [WPEngine API 키](#WPEngine-API-Key)
- [YouTube API 키](#YouTube-API-Key)
- [Zapier 웹훅 토큰](#Zapier-Webhook-Token)
- [Zendesk 액세스 토큰](#Zendesk-Access-Token)
- [Zendesk API 키](#Zendesk-api-key)
# 상세 정보
## [Slack 웹훅](https://api.slack.com/incoming-webhooks)
아래 명령어가 `missing_text_or_fallback_or_attachments`를 반환하면 URL이 유효하다는 뜻이며, 다른 응답이 오면 URL이 유효하지 않다는 의미입니다.```
curl -s -X POST -H "Content-type: application/json" -d '{"text":""}' "https://hooks.slack.com/services/T00000000/B00000000/XXXXXXXXXXXXXXXXXXXXXXXX"
```
## [Slack API 토큰](https://api.slack.com/web)```
curl -sX POST "https://slack.com/api/auth.test?token=xoxp-TOKEN_HERE&pretty=1"
```
또는```
curl -sX POST "https://slack.com/api/auth.test" -H "Accept: application/json; charset=utf-8" -H "Authorization: Bearer xoxb-TOKEN_HERE"
```
## [SauceLabs 사용자 이름 및 액세스 키](https://wiki.saucelabs.com/display/DOCS/Account+Methods)```
curl -u USERNAME:ACCESS_KEY https://saucelabs.com/rest/v1/users/USERNAME
```
## Facebook AppSecret
액세스 토큰은 아래 URL을 방문하여 생성할 수 있습니다.```
https://graph.facebook.com/oauth/access_token?client_id=ID_HERE&client_secret=SECRET_HERE&redirect_uri=&grant_type=client_credentials
```
## Facebook 액세스 토큰```
https://developers.facebook.com/tools/debug/accesstoken/?access_token=ACCESS_TOKEN_HERE&version=v3.2
```
## [Firebase](https://firebase.google.com/)
**사용자 지정 토큰**과 **API 키**가 필요합니다.
1. 사용자 지정 토큰과 API 키로부터 ID 토큰과 갱신 토큰을 획득: `curl -s -XPOST -H 'content-type: application/json' -d '{"token":":custom_token","returnSecureToken":True}' 'https://identitytoolkit.googleapis.com/v1/accounts:signInWithCustomToken?key=:api_key'`
2. ID 토큰을 인증 토큰으로 교환: `curl -s -XPOST -H 'content-type: application/json' -d '{"idToken":":id_token"}' https://www.googleapis.com/identitytoolkit/v3/relyingparty/verifyCustomToken?key=:api_key'`
## [Github Token](https://developer.github.com/v3/)```
curl -s -u "user:apikey" https://api.github.com/user
curl -s -H "Authorization: token TOKEN_HERE" "https://api.github.com/users/USERNAME_HERE/orgs"
# Check scope of your api token
curl "https://api.github.com/rate_limit" -i -u "user:apikey" | grep "X-OAuth-Scopes:"
```
## [Github 클라이언트 ID 및 클라이언트 시크릿](https://developer.github.com/v3/#oauth2-keysecret)```
curl 'https://api.github.com/users/whatever?client_id=xxxx&client_secret=yyyy'
```
## [Firebase Cloud Messaging](https://firebase.google.com/docs/cloud-messaging)
참조: https://abss.me/posts/fcm-takeover```
curl -s -X POST --header "Authorization: key=AI..." --header "Content-Type:application/json" 'https://fcm.googleapis.com/fcm/send' -d '{"registration_ids":["1"]}'
```
## GitHub 개인 SSH 키
SSH 개인 키는 github.com에 대해 테스트하여 기존 사용자 계정에 등록되었는지 확인할 수 있습니다. 키가 존재하면 해당 키에 대응하는 사용자 이름이 제공됩니다. ([출처](https://github.com/streaak/keyhacks/issues/2))```
$ ssh -i <path to SSH private key> -T [email protected]
Hi <username>! You've successfully authenticated, but GitHub does not provide shell access.
```
## [Twilio Account_sid 및 Auth token](https://www.twilio.com/docs/iam/api/account)```
curl -X GET 'https://api.twilio.com/2010-04-01/Accounts.json' -u ACCOUNT_SID:AUTH_TOKEN
```
## [트위터 API 비밀](https://developer.twitter.com/en/docs/basics/authentication/guides/bearer-tokens.html)```
curl -u 'API key:API secret key' --data 'grant_type=client_credentials' 'https://api.twitter.com/oauth2/token'
```
## [트위터 Bearer 토큰](https://developer.twitter.com/en/docs/accounts-and-users/subscribe-account-activity/api-reference/aaa-premium)```
curl --request GET --url https://api.twitter.com/1.1/account_activity/all/subscriptions/count.json --header 'authorization: Bearer TOKEN'
```
## [HubSpot API key](https://developers.hubspot.com/docs/methods/owners/get_owners)
모든 소유자 가져오기:```
https://api.hubapi.com/owners/v2/owners?hapikey={keyhere}
```
모든 연락처 세부 정보 가져오기:```
https://api.hubapi.com/contacts/v1/lists/all/contacts/all?hapikey={keyhere}
```
## [Infura API 키](https://docs.infura.io/infura/networks/ethereum/how-to/secure-a-project/project-id)```
curl https://mainnet.infura.io/v3/<YOUR-API-KEY> -X POST -H "Content-Type: application/json" -d '{"jsonrpc":"2.0","method":"eth_accounts","params":[],"id":1}'
```
## [Deviant Art Secret](https://www.deviantart.com/developers/authentication)```
curl https://www.deviantart.com/oauth2/token -d grant_type=client_credentials -d client_id=ID_HERE -d client_secret=mysecret
```
## [Deviant Art 액세스 토큰](https://www.deviantart.com/developers/authentication)```
curl https://www.deviantart.com/api/v1/oauth2/placebo -d access_token=Alph4num3r1ct0k3nv4lu3
```
## [Pendo 통합 키](https://help.pendo.io/resources/support-library/api/index.html?bash#authentication)```
curl -X GET https://app.pendo.io/api/v1/feature -H 'content-type: application/json' -H 'x-pendo-integration-key:KEY_HERE'
curl -X GET https://app.pendo.io/api/v1/metadata/schema/account -H 'content-type: application/json' -H 'x-pendo-integration-key:KEY_HERE'
```
## [SendGrid API 토큰](https://docs.sendgrid.com/api-reference)```
curl -X "GET" "https://api.sendgrid.com/v3/scopes" -H "Authorization: Bearer SENDGRID_TOKEN-HERE" -H "Content-Type: application/json"
```
## [스퀘어](https://squareup.com/)
**탐지:**
앱 ID/클라이언트 시크릿: `sq0[a-z]{3}-[0-9A-Za-z\-_]{22,43}`
인증 토큰: `EAAA[a-zA-Z0-9]{60}`
**테스트 앱 ID 및 클라이언트 시크릿:**```
curl "https://squareup.com/oauth2/revoke" -d '{"access_token":"[RANDOM_STRING]","client_id":"[APP_ID]"}' -H "Content-Type: application/json" -H "Authorization: Client [CLIENT_SECRET]"
```
유효한 자격 증명을 나타내는 응답:```
empty
```
잘못된 자격 증명을 나타내는 응답:```
{
"message": "Not Authorized",
"type": "service.not_authorized"
}
```
**테스트 인증 토큰:**```
curl https://connect.squareup.com/v2/locations -H "Authorization: Bearer [AUHT_TOKEN]"
```
유효한 자격 증명을 나타내는 응답:```
{"locations":[{"id":"CBASELqoYPXr7RtT-9BRMlxGpfcgAQ","name":"Coffee \u0026 Toffee SF","address":{"address_line_1":"1455 Market Street","locality":"San Francisco","administrative_district_level_1":"CA","postal_code":"94103","country":"US"},"timezone":"America/Los_Angeles"........
```
잘못된 자격 증명을 나타내는 응답:```
{"errors":[{"category":"AUTHENTICATION_ERROR","code":"UNAUTHORIZED","detail":"This request could not be authorized."}]}
```
## [Contentful 액세스 토큰](https://www.contentful.com/developers/docs/references/authentication)```
curl -v https://cdn.contentful.com/spaces/SPACE_ID_HERE/entries\?access_token\=ACCESS_TOKEN_HERE
```
## [Dropbox API](https://www.dropbox.com/developers/documentation/http/documentation)```
curl -X POST https://api.dropboxapi.com/2/users/get_current_account --header "Authorization: Bearer TOKEN_HERE"
```
## [AWS 액세스 키 ID 및 시크릿](https://docs.aws.amazon.com/cli/latest/userguide/cli-configure-profiles.html)
[awscli](https://aws.amazon.com/cli/)를 설치하고, [액세스 키와 시크릿을 환경 변수로 설정](https://docs.aws.amazon.com/cli/latest/userguide/cli-configure-envvars.html)한 후, 다음 명령을 실행하십시오:```
AWS_ACCESS_KEY_ID=xxxx AWS_SECRET_ACCESS_KEY=yyyy aws sts get-caller-identity
```
AWS 자격 증명의 권한은 [Enumerate-IAM](https://github.com/andresriancho/enumerate-iam)을 사용하여 확인할 수 있습니다. 이는 S3 버킷만 확인하는 대신 발견된 AWS 자격 증명 권한에 대한 더 넓은 시야를 제공합니다.```
git clone https://github.com/andresriancho/enumerate-iam
cd enumerate-iam
./enumerate-iam.py --access-key AKIA... --secret-key StF0q...
```
## [Lokalise API Key](https://app.lokalise.com/api2docs/curl/#resource-authentication)```curl --request GET \
--url https://api.lokalise.com/api2/projects/ \
--header 'x-api-token: [API-KEY-HERE]'
```
## [MailGun 개인 키](https://documentation.mailgun.com/en/latest/api_reference.html)```
curl --user 'api:YOUR_API_KEY' "https://api.mailgun.net/v3/domains"
```
## [FreshDesk API 키](https://developers.freshdesk.com/api/#getting-started)```
curl -v -u [email protected]:test -X GET 'https://domain.freshdesk.com/api/v2/groups/1'
This requires the API key in '[email protected]', pass in 'test' and 'domain.freshdesk.com' to be the instance url of the target. In case you get a 403, try the endpoint api/v2/tickets, which is accessible for all keys.
```
## [JumpCloud API 키](https://docs.jumpcloud.com/1.0/authentication-and-authorization/authentication-and-authorization-overview)
#### [v1](https://docs.jumpcloud.com/1.0/systemusers)```
List systems:
curl -H "x-api-key: APIKEYHERE" "https://console.jumpcloud.com/api/systems"
curl -H "x-api-key: APIKEYHERE" "https://console.jumpcloud.com/api/systemusers"
curl -H "x-api-key: APIKEYHERE" "https://console.jumpcloud.com/api/applications"
```
#### [v2](https://docs.jumpcloud.com/2.0/systems/list-the-associations-of-a-system)```
List systems:
curl -X GET https://console.jumpcloud.com/api/v2/systems/{System_ID}/memberof \
-H 'Accept: application/json' \
-H 'Content-Type: application/json' \
-H 'x-api-key: {API_KEY}'
```
## Microsoft Azure 테넌트
형식:```
CLIENT_ID: [0-9a-z\-]{36}
CLIENT_SECRET: [0-9A-Za-z\+\=]{40,50}
TENANT_ID: [0-9a-z\-]{36}
```
검증:```
curl -X POST -H "Content-Type: application/x-www-form-urlencoded" -d 'client_id=<CLIENT_ID>&scope=https%3A%2F%2Fgraph.microsoft.com%2F.default&client_secret=<CLIENT_SECRET>&grant_type=client_credentials' 'https://login.microsoftonline.com/<TENANT_ID>/oauth2/v2.0/token'
```
## [Microsoft 공유 액세스 서명 (SAS)](https://github.com/MicrosoftDocs/azure-docs/blob/master/articles/storage/common/storage-dotnet-shared-access-signature-part-1.md)
다음 powershell을 사용하여 Shared Access Signature Token을 테스트할 수 있습니다:```powershell
static void UseAccountSAS(string sasToken)
{
// Create new storage credentials using the SAS token.
StorageCredentials accountSAS = new StorageCredentials(sasToken);
// Use these credentials and the account name to create a Blob service client.
CloudStorageAccount accountWithSAS = new CloudStorageAccount(accountSAS, "account-name", endpointSuffix: null, useHttps: true);
CloudBlobClient blobClientWithSAS = accountWithSAS.CreateCloudBlobClient();
// Now set the service properties for the Blob client created with the SAS.
blobClientWithSAS.SetServiceProperties(new ServiceProperties()
{
HourMetrics = new MetricsProperties()
{
MetricsLevel = MetricsLevel.ServiceAndApi,
RetentionDays = 7,
Version = "1.0"
},
MinuteMetrics = new MetricsProperties()
{
MetricsLevel = MetricsLevel.ServiceAndApi,
RetentionDays = 7,
Version = "1.0"
},
Logging = new LoggingProperties()
{
LoggingOperations = LoggingOperations.All,
RetentionDays = 14,
Version = "1.0"
}
});
// The permissions granted by the account SAS also permit you to retrieve service properties.
ServiceProperties serviceProperties = blobClientWithSAS.GetServiceProperties();
Console.WriteLine(serviceProperties.HourMetrics.MetricsLevel);
Console.WriteLine(serviceProperties.HourMetrics.RetentionDays);
Console.WriteLine(serviceProperties.HourMetrics.Version);
}
```
## [Microsoft Teams Webhook](https://learn.microsoft.com/en-us/microsoftteams/platform/webhooks-and-connectors/how-to/connectors-using)
아래 명령이 `Summary or Text is required.`를 반환하면 URL이 유효하다는 의미입니다. 만약 `Invalid webhook URL`이나 다른 응답을 반환한다면 URL이 유효하지 않다는 의미입니다.```
curl -H "Content-Type:application/json" -d "{'text':''}" "YOUR_WEBHOOK_URL"
```
## [New Relic 개인 API 키 (NerdGraph)](https://docs.newrelic.com/docs/apis/nerdgraph/get-started/introduction-new-relic-nerdgraph#endpoint)```
curl -X POST https://api.newrelic.com/graphql \
-H 'Content-Type: application/json' \
-H 'API-Key: YOUR_API_KEY' \
-d '{ "query": "{ requestContext { userId apiKey } }" } '
```
## [뉴 렐릭 REST API](https://docs.newrelic.com/docs/apis/rest-api-v2/application-examples-v2/list-your-app-id-metric-timeslice-data-v2)```
curl -X GET 'https://api.newrelic.com/v2/applications.json' \
-H "X-Api-Key:${APIKEY}" -i
```
유효하다면, [관리자 키](https://docs.newrelic.com/docs/apis/get-started/intro-apis/types-new-relic-api-keys#admin)인지 추가로 테스트하세요
## [Heroku API 키](https://devcenter.heroku.com/articles/platform-api-quickstart)```
curl -X POST https://api.heroku.com/apps -H "Accept: application/vnd.heroku+json; version=3" -H "Authorization: Bearer API_KEY_HERE"
```
## [Mapbox API key](https://docs.mapbox.com/api/)
Mapbox 비밀 키는 `sk`로 시작하며, 나머지는 `pk`(공개 토큰), `sk`(비밀 토큰) 또는 `tk`(임시 토큰)로 시작합니다.```
curl "https://api.mapbox.com/geocoding/v5/mapbox.places/Los%20Angeles.json?access_token=ACCESS_TOKEN"
#Check token validity
curl "https://api.mapbox.com/tokens/v2?access_token=YOUR_MAPBOX_ACCESS_TOKEN"
#Get list of all tokens associated with an account. (only works if the token is a Secret Token (sk), and has the appropiate scope)
curl "https://api.mapbox.com/tokens/v2/MAPBOX_USERNAME_HERE?access_token=YOUR_MAPBOX_ACCESS_TOKEN"
```
## [Salesforce API 키](https://developer.salesforce.com/docs/atlas.en-us.api_rest.meta/api_rest/quickstart_oauth.htm)```
curl https://instance_name.salesforce.com/services/data/v20.0/ -H 'Authorization: Bearer access_token_here'
```
## [Algolia API key](https://www.algolia.com/doc/rest-api/search/#overview)
키가 `listIndexes` 권한을 가지고 있다면, 다음과 같이 인덱스를 나열할 수 있습니다:```
curl --request GET \
--url https://<example-app-id>-1.algolianet.com/1/indexes/ \
--header 'content-type: application/json' \
--header 'x-algolia-api-key: <example-key>' \
--header 'x-algolia-application-id: <example-appid>'
```
그렇지 않으면 인덱스의 이름을 알아야 합니다 (앱 소스 코드나 요청을 확인하세요). 그런 다음 해당 콘텐츠를 열거하려면:```
curl --request GET \
--url https://<example-app-id>-1.algolianet.com/1/indexes/<example-index> \
--header 'content-type: application/json' \
--header 'x-algolia-api-key: <example-key>' \
--header 'x-algolia-application-id: <example-appid>'
```
이 명령을 실행할 때는 주의하십시오. 페이로드가 `highlightPreTag`를 편집 중인 인덱스에 따라 관리 환경 내에서 실행될 수 있습니다. 가능한 크로스 사이트 스크립팅 공격을 입증하기 위해 XSS Hunter와 같은 더 조용한 페이로드를 사용하는 것이 좋습니다.```
curl --request PUT \
--url https://<application-id>-1.algolianet.com/1/indexes/<example-index>/settings \
--header 'content-type: application/json' \
--header 'x-algolia-api-key: <example-key>' \
--header 'x-algolia-application-id: <example-application-id>' \
--data '{"highlightPreTag": "<script>alert(1);</script>"}'
```
## [Zapier Webhook Token](https://zapier.com/help/how-get-started-webhooks-zapier/)```
curl -H "Accept: application/json" -H "Content-Type: application/json" -X POST -d '{"name":"streaak"}' "webhook_url_here"
```
## [Pagerduty API 토큰](https://support.pagerduty.com/docs/using-the-api)```
curl -H "Accept: application/vnd.pagerduty+json;version=2" -H "Authorization: Token token=TOKEN_HERE" -X GET "https://api.pagerduty.com/schedules"
```
## [BrowserStack 액세스 키](https://www.browserstack.com/automate/rest-api)```
curl -u "USERNAME:ACCESS_KEY" https://api.browserstack.com/automate/plan.json
```
## [Google Maps API key](https://developers.google.com/maps/documentation/javascript/get-api-key)
**키 제한은 서비스별로 설정됩니다. 키를 테스트할 때, 한 서비스에서 키가 제한/비활성화되어 있으면 다른 서비스로 시도해 보세요.**
| 이름| Endpoint| 요금|
| ------------- |:-------------:| -----:|
| Static Maps | https://maps.googleapis.com/maps/api/staticmap?center=45%2C10&zoom=7&size=400x400&key=KEY_HERE| $2 |
| Streetview | https://maps.googleapis.com/maps/api/streetview?size=400x400&location=40.720032,-73.988354&fov=90&heading=235&pitch=10&key=KEY_HERE| $7 |
| Embed | https://www.google.com/maps/embed/v1/place?q=place_id:ChIJyX7muQw8tokR2Vf5WBBk1iQ&key=KEY_HERE| Varies |
| Directions | https://maps.googleapis.com/maps/api/directions/json?origin=Disneyland&destination=Universal+Studios+Hollywood4&key=KEY_HERE| $5 |
| Geocoding | https://maps.googleapis.com/maps/api/geocode/json?latlng=40,30&key=KEY_HERE| $5 |
| Distance Matrix| https://maps.googleapis.com/maps/api/distancematrix/json?units=imperial&origins=40.6655101,-73.89188969999998&destinations=40.6905615%2C-73.9976592%7C40.6905615%2C-73.9976592%7C40.6905615%2C-73.9976592%7C40.6905615%2C-73.9976592%7C40.6905615%2C-73.9976592%7C40.6905615%2C-73.9976592%7C40.659569%2C-73.933783%7C40.729029%2C-73.851524%7C40.6860072%2C-73.6334271%7C40.598566%2C-73.7527626%7C40.659569%2C-73.933783%7C40.729029%2C-73.851524%7C40.6860072%2C-73.6334271%7C40.598566%2C-73.7527626&key=KEY_HERE | $5 |
|Find Place from Text | https://maps.googleapis.com/maps/api/place/findplacefromtext/json?input=Museum%20of%20Contemporary%20Art%20Australia&inputtype=textquery&fields=photos,formatted_address,name,rating,opening_hours,geometry&key=KEY_HERE | Varies |
| Autocomplete | https://maps.googleapis.com/maps/api/place/autocomplete/json?input=Bingh&types=%28cities%29&key=KEY_HERE| Varies |
| Elevation | https://maps.googleapis.com/maps/api/elevation/json?locations=39.7391536,-104.9847034&key=KEY_HERE | $5 |
| Timezone | https://maps.googleapis.com/maps/api/timezone/json?location=39.6034810,-119.6822510×tamp=1331161200&key=KEY_HERE | $5 |
| Roads | https://roads.googleapis.com/v1/nearestRoads?points=60.170880,24.942795\|60.170879,24.942796\|60.170877,24.942796&key=KEY_HERE | $10|
| Geolocate | https://www.googleapis.com/geolocation/v1/geolocate?key=KEY_HERE| $5 |
*\*요금은 요청 1,000회당 USD 기준입니다 (최초 100,000회 요청 기준)*
추가 정보는 아래에서 확인할 수 있습니다.
https://medium.com/@ozguralp/unauthorized-google-maps-api-key-usage-cases-and-why-you-need-to-care-1ccb28bf21e
https://github.com/ozguralp/gmapsapiscanner/
https://developers.google.com/maps/api-key-best-practices
## [Google Recaptcha key](https://developers.google.com/recaptcha/docs/verify)
다음 URL로 POST 요청을 보내세요.```
https://www.google.com/recaptcha/api/siteverify
```
`secret`와 `response`는 필수 POST 매개변수로, `secret`은 키이고 `response`는 테스트할 응답입니다.
정규 표현식: `^6[0-9a-zA-Z_-]{39}$`. API 키는 항상 6으로 시작하며 길이는 40자입니다. 자세한 내용은 다음에서 확인하세요: https://developers.google.com/recaptcha/docs/verify.
## [Google Cloud 서비스 계정 자격 증명](https://cloud.google.com/docs/authentication/production)
서비스 계정 자격 증명은 다음과 같은 JSON 파일에서 찾을 수 있습니다:```
$ cat service_account.json
{
"type": "service_account",
"project_id": "...",
"private_key_id": "...",
"private_key": "-----BEGIN PRIVATE KEY-----...-----END PRIVATE KEY-----\n",
"client_email": "...",
"client_id": "...",
"auth_uri": "https://accounts.google.com/o/oauth2/auth",
"token_uri": "https://oauth2.googleapis.com/token",
"auth_provider_x509_cert_url": "https://www.googleapis.com/oauth2/v1/certs",
"client_x509_cert_url": "https://www.googleapis.com/robot/v1/metadata/x509/..."
}
```
이 경우 `gcloud` 도구를 사용하여 이러한 자격 증명을 확인할 수 있습니다([`gcloud` 설치 방법](https://cloud.google.com/sdk/docs/quickstart-debian-ubuntu)):```
$ gcloud auth activate-service-account --key-file=service_account.json
Activated service account credentials for: [...]
$ gcloud auth print-access-token
ya29.c...
```
성공 시 터미널에 액세스 토큰이 출력됩니다. 자격 증명이 실제로 유효한지 확인한 후에는 이 자격 증명의 권한을 열거하는 것이 좋습니다. 이는 또 다른 이야기입니다.
## [Branch.IO Key and Secret](https://docs.branch.io/pages/apps/deep-linking-api/#app-read)
유효성을 확인하려면 다음 URL을 방문하세요:```
https://api2.branch.io/v1/app/KEY_HERE?branch_secret=SECRET_HERE
```
## [Bing Maps API 키](https://docs.microsoft.com/en-us/bingmaps/rest-services/locations/find-a-location-by-address)
이 링크를 방문하여 키의 유효성을 확인하세요. 유효한 키의 응답은 `authenticationResultCode: "ValidCredentials"`로 시작해야 합니다.```
https://dev.virtualearth.net/REST/v1/Locations?CountryRegion=US&adminDistrict=WA&locality=Somewhere&postalCode=98001&addressLine=100%20Main%20St.&key=API_KEY
```
## [Bit.ly 액세스 토큰](https://dev.bitly.com/authentication.html)
다음 URL을 방문하여 유효성을 확인하세요:```
https://api-ssl.bitly.com/v3/shorten?access_token=ACCESS_TOKEN&longUrl=https://www.google.com
```
## [Buildkite 액세스 토큰](https://buildkite.com/docs/apis/rest-api)```
curl -H "Authorization: Bearer ACCESS_TOKEN" \
https://api.buildkite.com/v2/access-token
```
## [ButterCMS-API-Key](https://buttercms.com/docs/api/#authentication)```
curl -X GET 'https://api.buttercms.com/v2/posts/?auth_token=your_api_token'
```
## [Asana 액세스 토큰](https://asana.com/developers/documentation/getting-started/auth#personal-access-token)```
curl -H "Authorization: Bearer ACCESS_TOKEN" https://app.asana.com/api/1.0/users/me
```
## [Zendesk 액세스 토큰](https://support.zendesk.com/hc/en-us/articles/203663836-Using-OAuth-authentication-with-your-application)```
curl https://{subdomain}.zendesk.com/api/v2/tickets.json \
-H "Authorization: Bearer ACCESS_TOKEN"
```
## [Zendesk API 키](https://developer.zendesk.com/api-reference/ticketing/introduction/)
API 토큰은 OAuth 토큰과 다릅니다. API 토큰은 Support 관리자 인터페이스에서 자동 생성된 비밀번호입니다.```
curl https://{target}.zendesk.com/api/v2/users.json \ -u support@{target}.com/token:{here your token}
```
## [MailChimp API 키](https://developer.mailchimp.com/documentation/mailchimp/reference/overview/)```
curl --request GET --url 'https://<dc>.api.mailchimp.com/3.0/' --user 'anystring:<API_KEY>' --include
```
## [WPEngine API Key](https://wpengineapi.com/)
이 문제는 [@hateshape](https://github.com/hateshape/)의 gist https://gist.github.com/hateshape/2e671ea71d7c243fac7ebf51fb738f0a를 확인하여 추가로 악용될 수 있습니다.```
curl "https://api.wpengine.com/1.2/?method=site&account_name=ACCOUNT_NAME&wpe_apikey=WPENGINE_APIKEY"
```
## [DataDog API 키](https://docs.datadoghq.com/api/)```
curl "https://api.datadoghq.com/api/v1/dashboard?api_key=<api_key>&application_key=<application_key>"
```
## [Delighted API key](https://app.delighted.com/docs/api)
끝에 있는 `:`를 삭제하지 마세요.```
curl https://api.delighted.com/v1/metrics.json \
-H "Content-Type: application/json" \
-u YOUR_DELIGHTED_API_KEY:
```
## [Travis CI API 토큰](https://developer.travis-ci.com/gettingstarted)```
curl -H "Travis-API-Version: 3" -H "Authorization: token <TOKEN>" https://api.travis-ci.org/repos
```
## [텔레그램 봇 API 토큰](https://core.telegram.org/bots/api#making-requests)```
curl https://api.telegram.org/bot<TOKEN>/getMe
```
## [WakaTime API 키](https://wakatime.com/developers)```
curl "https://wakatime.com/api/v1/users/current?api_key=KEY_HERE"
```
## [Sonarcloud Token](https://sonarcloud.io/web_api)```
curl -u <token>: "https://sonarcloud.io/api/authentication/validate"
```
## [Spotify 액세스 토큰](https://developer.spotify.com/documentation/general/guides/authorization-guide/)```
curl -H "Authorization: Bearer <ACCESS_TOKEN>" https://api.spotify.com/v1/me
```
## [Instagram 기본 표시 API 액세스 토큰](https://developers.facebook.com/docs/instagram-basic-display-api/getting-started)
예: IGQVJ...```
curl -X GET 'https://graph.instagram.com/{user-id}?fields=id,username&access_token={access-token}'
```
## [Instagram Graph API 액세스 토큰](https://developers.facebook.com/docs/instagram-api/getting-started)
예: EAAJjmJ...```
curl -i -X GET 'https://graph.facebook.com/v8.0/me/accounts?access_token={access-token}'
```
## [Gitlab 개인 액세스 토큰](https://docs.gitlab.com/ee/api/README.html#personal-access-tokens)```
curl "https://gitlab.example.com/api/v4/projects?private_token=<your_access_token>"
```
## [GitLab 러너 등록 토큰](https://docs.gitlab.com/runner/register/)```
docker run --rm gitlab/gitlab-runner register \
--non-interactive \
--executor "docker" \
--docker-image alpine:latest \
--url "https://gitlab.com/" \
--registration-token "PROJECT_REGISTRATION_TOKEN" \
--description "keyhacks-test" \
--maintenance-note "Testing token with keyhacks" \
--tag-list "docker,aws" \
--run-untagged="true" \
--locked="false" \
--access-level="not_protected"
```
## [페이팔 클라이언트 ID 및 비밀 키](https://developer.paypal.com/docs/api/get-an-access-token-curl/)```
curl -v https://api.sandbox.paypal.com/v1/oauth2/token \
-H "Accept: application/json" \
-H "Accept-Language: en_US" \
-u "client_id:secret" \
-d "grant_type=client_credentials"
```
액세스 토큰은 PayPal API에서 데이터를 추출하는 데 추가로 사용될 수 있습니다. 더 많은 정보: https://developer.paypal.com/docs/api/overview/#make-rest-api-calls.
이는 다음을 사용하여 확인할 수 있습니다:```
curl -v -X GET "https://api.sandbox.paypal.com/v1/identity/oauth2/userinfo?schema=paypalv1.1" -H "Content-Type: application/json" -H "Authorization: Bearer [ACCESS_TOKEN]"
```
## [Stripe 라이브 토큰](https://stripe.com/docs/api/authentication)```
curl https://api.stripe.com/v1/charges -u token_here:
```
토큰 끝에 콜론을 유지하여 `cURL`이 비밀번호를 요청하지 않도록 하십시오.
토큰은 항상 `sk_live_24charshere` 형식입니다. 여기서 `24charshere` 부분은 `a-z A-Z 0-9`의 24개 문자로 구성됩니다. 또한 `sk_test`로 시작하는 테스트 키도 있지만, 이 키는 테스트 목적으로만 사용되며 민감한 정보를 포함하지 않을 가능성이 높으므로 가치가 없습니다. 반면 라이브 키는 요금 정보부터 전체 제품 목록에 이르기까지 많은 정보를 추출/검색하는 데 사용될 수 있습니다.
Stripe는 마지막 4자리만 제공하므로 전체 신용카드 정보를 얻을 수 없다는 점을 명심하십시오.
자세한 정보/전체 문서: https://stripe.com/docs/api/authentication.
## [Razorpay API 키 및 시크릿 키](https://razorpay.com/docs/api/)
다음을 사용하여 확인할 수 있습니다:```
curl -u <YOUR_KEY_ID>:<YOUR_KEY_SECRET> \
https://api.razorpay.com/v1/payments
```
## [CircleCI 액세스 토큰](https://circleci.com/docs/api/#api-overview)```
curl https://circleci.com/api/v1.1/me?circle-token=<TOKEN>
```
## [Cloudflare API 키](https://api.cloudflare.com/#user-api-tokens-verify-token)```
curl -X GET "https://api.cloudflare.com/client/v4/user/tokens/verify" \
-H "Authorization: Bearer <YOUR_API_TOKEN>"
```
## [Loqate API key](https://www.loqate.com/resources/support/apis)```
curl 'http://api.addressy.com/Capture/Interactive/Find/v1.00/json3.ws?Key=<KEY_HERE>&Countries=US,CA&Language=en&Limit=5&Text=BHAR'
```
## [Ipstack API 키](https://ipstack.com/documentation)```
curl 'https://api.ipstack.com/{ip_address}?access_key={keyhere}'
```
## [NPM 토큰](https://docs.npmjs.com/about-authentication-tokens)
다음과 같이 [npm을 사용하여](https://medium.com/bugbountywriteup/one-token-to-leak-them-all-the-story-of-a-8000-npm-token-79b13af182a3) NPM 토큰을 확인할 수 있습니다 (`00000000-0000-0000-0000-000000000000`를 NPM 토큰으로 대체):```
export NPM_TOKEN="00000000-0000-0000-0000-000000000000"
echo "//registry.npmjs.org/:_authToken=${NPM_TOKEN}" > .npmrc
npm whoami
```
토큰을 확인하는 또 다른 방법은 API를 직접 쿼리하는 것입니다:```
curl -H 'authorization: Bearer 00000000-0000-0000-0000-000000000000' 'https://registry.npmjs.org/-/whoami'
```
성공 시 응답으로 사용자 이름을 받게 되며, 토큰이 존재하지 않는 경우 `401 Unauthorized`, IP 주소가 허용 목록에 없는 경우 `403 Forbidden`을 받게 됩니다.
NPM 토큰은 [CIDR 허용 목록](https://docs.npmjs.com/creating-and-viewing-authentication-tokens#creating-tokens-with-the-cli)에 추가될 수 있습니다. 따라서 *허용 목록에 없는* CIDR에서 토큰을 사용하면 응답으로 `403 Forbidden`을 받게 됩니다. 그러니 다른 IP 범위에서 NPM 토큰을 확인해보세요!.
추신. 일부 회사에서는 [`registry.npmjs.org`](https://medium.com/bugbountywriteup/one-token-to-leak-them-all-the-story-of-a-8000-npm-token-79b13af182a3) 외의 레지스트리를 사용합니다. 해당하는 경우 모든 `registry.npmjs.org` 항목을 회사 NPM 레지스트리의 도메인 이름으로 바꾸세요.
## [OpsGenie API 키](https://docs.opsgenie.com/docs/api-overview)```
curl https://api.opsgenie.com/v2/alerts -H 'Authorization: GenieKey API_KEY'
```
## [Keen.io API Key](https://keen.io/docs/api/)
특정 프로젝트의 모든 컬렉션 가져오기:```
curl "https://api.keen.io/3.0/projects/PROJECT_ID/events?api_key=READ_KEY"
```
>참고: cURL이 비밀번호를 요청하지 않도록 토큰 끝에 콜론을 유지하세요.
정보: 토큰은 항상 다음과 같은 형식입니다: sk_live_34charshere, 여기서 34charshere 부분은 a-z A-Z 0-9의 34개 문자를 포함합니다.
테스트 키도 있으며 sk_test로 시작하지만, 이 키는 테스트 목적으로만 사용되며 민감한 정보를 포함하지 않을 가능성이 높으므로 가치가 없습니다.
반면에 라이브 키는 많은 정보를 추출/검색하는 데 사용될 수 있습니다. 청구 내역부터 전체 제품 목록까지.
명심하세요, Stripe는 마지막 4자리 정도만 제공하므로 전체 신용카드 정보를 얻을 수는 없습니다.
더 많은 정보 / 전체 문서: https://stripe.com/docs/api/authentication
=======
## [Calendly API 키](https://developer.calendly.com/docs/)
사용자 정보 가져오기:````
curl --header "X-TOKEN: <your_token>" https://calendly.com/api/v1/users/me
````
웹후크 구독 목록:````
curl --header "X-TOKEN: <your_token>" https://calendly.com/api/v1/hooks
````
## [Azure Application Insights APP ID and API Key](https://dev.applicationinsights.io/reference)
지난 24시간 동안 이루어진 총 요청 수 가져오기:```
curl -H "x-api-key: {API_Key}" "https://api.applicationinsights.io/v1/apps/{APP_ID}/metrics/requests/count"
```
## [Cypress 레코드 키](https://docs.cypress.io/guides/dashboard/projects.html#Record-key)
`recordKey` 유효성을 확인하려면 `cypress.json` 파일에서 일반적으로 찾을 수 있는 공개 값인 `projectId`가 필요합니다. JSON 본문에서 `{recordKey}` 및 `{projectId}`를 자신의 값으로 바꾸십시오.```
curl -i -s -k -X $'POST' \
-H $'x-route-version: 4' -H $'x-os-name: darwin' -H $'x-cypress-version: 5.5.0' -H $'host: api.cypress.io' -H $'accept: application/json' -H $'content-type: application/json' -H $'Content-Length: 1433' -H $'Connection: close' \
--data-binary $'{\"ci\":{\"params\":null,\"provider\":null},\"specs\":[\"cypress/integration/examples/actions.spec.js\",\"cypress/integration/examples/aliasing.spec.js\",\"cypress/integration/examples/assertions.spec.js\",\"cypress/integration/examples/connectors.spec.js\",\"cypress/integration/examples/cookies.spec.js\",\"cypress/integration/examples/cypress_api.spec.js\",\"cypress/integration/examples/files.spec.js\",\"cypress/integration/examples/local_storage.spec.js\",\"cypress/integration/examples/location.spec.js\",\"cypress/integration/examples/misc.spec.js\",\"cypress/integration/examples/navigation.spec.js\",\"cypress/integration/examples/network_requests.spec.js\",\"cypress/integration/examples/querying.spec.js\",\"cypress/integration/examples/spies_stubs_clocks.spec.js\",\"cypress/integration/examples/traversal.spec.js\",\"cypress/integration/examples/utilities.spec.js\",\"cypress/integration/examples/viewport.spec.js\",\"cypress/integration/examples/waiting.spec.js\",\"cypress/integration/examples/window.spec.js\"],\"commit\":{\"sha\":null,\"branch\":null,\"authorName\":null,\"authorEmail\":null,\"message\":null,\"remoteOrigin\":null,\"defaultBranch\":null},\"group\":null,\"platform\":{\"osCpus\":[],\"osName\":\"darwin\",\"osMemory\":{\"free\":1153744896,\"total\":17179869184},\"osVersion\":\"19.6.0\",\"browserName\":\"Electron\",\"browserVersion\":\"85.0.4183.121\"},\"parallel\":null,\"ciBuildId\":null,\"projectId\":\"{projectId}\",\"recordKey\":\"{recordKey}\",\"specPattern\":null,\"tags\":[\"\"]}' \
$'https://api.cypress.io/runs'
```
네, 이 요청은 그렇게 클 필요가 있습니다. `projectId`와 `recordKey`가 모두 유효한 경우 실행에 대한 일부 정보와 함께 `200 OK`를 반환하고, `projectId`가 유효하지 않은 경우 `404 Not Found`와 `{"message":"Project not found. Invalid projectId."}`를 반환하거나, `recordKey`가 유효하지 않은 경우 `401 Unauthorized`와 `{"message":"Invalid Record Key."}`를 반환합니다.
`projectId`의 예는 `1yxykz`이고, `recordKey`의 예는 `a216e7b4-4819-4713-b9c2-c5da60a1c48c`입니다.
## [YouTube API Key](https://developers.google.com/youtube/v3/docs/)
YouTube 채널의 콘텐츠 세부 정보를 가져옵니다 (이 경우 channelId는 PewDiePie의 채널을 가리킵니다).```
curl -iLk 'https://www.googleapis.com/youtube/v3/activities?part=contentDetails&maxResults=25&channelId=UC-lHJZR3Gqxm24_Vd_AJ5Yw&key={KEY_HERE}'
```
## [ABTasty API 키](https://developers.abtasty.com/server-side.html#authentication)```
curl "api_endpoint_here" -H "x-api-key: your_api_key"
```
## [Iterable API Key](https://api.iterable.com/api/docs)
캠페인 분석 데이터를 JSON 형식으로 내보내며, 한 줄에 하나의 항목이 기록됩니다. 'range' 또는 'startDateTime'과 'endDateTime' 중 하나를 사용해야 합니다.```
curl -H "Api_Key: {API_KEY}" https://api.iterable.com/api/export/data.json?dataTypeName=emailSend&range=Today&onlyFields=List.empty
```
## [Amplitude API 키](https://help.amplitude.com/hc/en-us/articles/205406637-Export-API-Export-Your-Project-s-Event-Data)
응답은 JSON 파일의 압축 아카이브이며, 시간당 여러 개의 파일이 있을 수 있습니다. 2014-11-12 이전의 이벤트는 시간별이 아닌 일별로 그룹화됩니다. 프로젝트에 대해 데이터가 수집되지 않은 시간 범위의 데이터를 요청하면 서버로부터 404 응답을 받게 됩니다.```
curl -u API_Key:Secret_Key 'https://amplitude.com/api/2/export?start=20200201T5&end=20210203T20' >> yourfilename.zip
```
## [Visual Studio App Center API Token](https://docs.microsoft.com/en-us/appcenter/api-docs/)
1. API Token에 대한 모든 앱 프로젝트를 나열합니다. ```
curl -sX GET "https://api.appcenter.ms/v0.1/apps" \
-H "Content-Type: application/json" \
-H "X-Api-Token: {your_api_token}"
```
2. 특정 프로젝트의 최신 앱 빌드 정보를 가져옵니다:
> Step [1](#438)에서 응답으로 얻은 `name`과 `owner.name`을 사용하세요. ```
curl -sX GET "https://api.appcenter.ms/v0.1/apps/{owner.name}/{name}/releases/latest" \
-H "Content-Type: application/json" \
-H "X-Api-Token: {your_api_token}"
```
## [WeGlot API 키](https://weglot.com/)```
curl -X POST \
'https://api.weglot.com/translate?api_key=my_api_key' \
-H 'Content-Type: application/json' \
-d '{
"l_from":"en",
"l_to":"fr",
"request_url":"https://www.website.com/",
"words":[
{"w":"This is a blue car", "t": 1},
{"w":"This is a black car", "t": 1}
]
}'
```
## [PivotalTracker API 토큰](https://www.pivotaltracker.com/help/api/#top)
1. API 토큰으로 사용자 정보 나열: ```
curl -X GET -H "X-TrackerToken: $TOKEN" "https://www.pivotaltracker.com/services/v5/me?fields=%3Adefault"
```
1. 유효한 사용자 자격 증명으로 API 토큰 획득: ```
curl -s -X GET --user 'USER:PASSWORD' "https://www.pivotaltracker.com/services/v5/me -o pivotaltracker.json"
jq --raw-output .api_token pivotaltracker.json
```
## [LinkedIn OAUTH](https://docs.microsoft.com/en-us/linkedin/shared/authentication/client-credentials-flow?context=linkedin/context)
성공적인 액세스 토큰 요청은 access_token, expires_in을 포함하는 JSON 객체를 반환합니다.```
curl -XPOST -H "Content-type: application/x-www-form-urlencoded" -d 'grant_type=client_credentials&client_id=<client-ID>&client_secret=<client-secret>' 'https://www.linkedin.com/oauth/v2/accessToken'
```
## [Help Scout OAUTH](https://developer.helpscout.com/mailbox-api/overview/authentication/)
성공적인 액세스 토큰 요청은 token_type, access_token, expires_in을 포함하는 JSON 객체를 반환합니다.```
curl -X POST https://api.helpscout.net/v2/oauth2/token \
--data "grant_type=client_credentials" \
--data "client_id={application_id}" \
--data "client_secret={application_secret}"
```
## [Shodan API 키](https://developer.shodan.io/api/requirements)```
curl "https://api.shodan.io/shodan/host/8.8.8.8?key=TOKEN_HERE"
```
## [Bazaarvoice Passkey](https://developer.bazaarvoice.com/conversations-api/home)
성공적인 Passkey 요청은 회사 이름을 포함하는 JSON 객체를 반환합니다.```
curl 'https://which-cpv-api.bazaarvoice.com/clientInfo?conversationspasskey=<Passkey>' --insecure
```
## [Grafana Access Token](https://grafana.com/docs/grafana/latest/developers/http_api/user/)
Grafana API는 Bearer 및 Basic 인증 방식을 지원합니다. Bearer:```
curl -s -H "Authorization: Bearer your-api-key" http://your-grafana-server-url.com/api/user
```
기본:```
curl -u username:password http://your-grafana-server-url.com/api/user
```
# Contributing
저는 대중의 기여를 환영합니다.
### Using the issue tracker 💡
이슈 트래커는 버그 신고 및 기능 요청에 선호되는 채널입니다.
### Issues and labels 🏷
버그 트래커는 이슈를 조직화하고 식별하기 위해 여러 레이블을 사용합니다.
### Guidelines for bug reports 🐛
GitHub 이슈 검색을 사용하세요 — 이미 신고된 이슈인지 확인하세요.
# ⚠ Legal Disclaimer
이 프로젝트는 교육적이고 윤리적인 테스트 목적으로만 제작되었습니다. 사전 상호 동의 없이 대상을 공격하기 위해 이 도구를 사용하는 것은 불법입니다. 개발자는 어떠한 책임도 지지 않으며, 이 도구로 인한 오용이나 손해에 대해 책임을 지지 않습니다.