What is an API key — CCA-F Exam Prep

PencilPrepPencilPrep
L1.04|What is an API key
1/12
Real story
A developer's laptop screen showing a GitHub commit. Line 847 is highlighted in red with a string that looks like 'AKIA3E...' (an AWS key). In the background, a phone buzzing with AWS billing alerts. Dark room, blue screen glow.

Line 847. $14,000. 12 minutes.

A developer pushed code to GitHub. A public repository. 847 lines of Python. Somewhere in the middle, hardcoded: his AWS API key.

Bots that crawl GitHub for exposed keys found it in 12 minutes. They spun up cryptocurrency mining servers on his AWS account. By the time he woke up: $14,000 in charges.

The key was his identity. Anyone with it was him. AWS couldn't tell the difference.