API Radar - See your leaked API keys before attackers do
API Radar turns leaked API keys into a searchable threat feed for your own org. This new version rebuilds the core engine so it continuously discovers exposed keys in public GitHub, then lets you slice them by provider, repo, file path, and time to see exactly what’s out and where. Instead of digging through noisy scanners or random alerts, you get a focused view of real leaked credentials you can revoke and rotate fast.



Replies
API Radar – Live Feed of Leaked API Keys
That def would be helpful. It would also help to see if keys have already been rotated, most of the times if keys are leaked they're rotated since it's already in git history
API Radar – Live Feed of Leaked API Keys
@bekjon_ibragimov 100% agree.
right now api radar shows leaks with the latest ones first, so if a owner pushed a key 10 hours ago, the chances are high that the key is still active
Dirac
What if an attacker uses Api radar before you do? :p
API Radar – Live Feed of Leaked API Keys
@peterz_shu Legit concern.
API Radar does scan public GitHub, so that risk is always on my mind.