Skip to content
← LibraryTechnique entry
SAAS-API-TOKEN-LEAKCredential Access

SaaS API Token in Code / CI

Stripe / SendGrid / Datadog / PagerDuty tokens committed to repos or logged in CI — abuse for billing fraud, data exfil, account takeover.

§ Where this technique fits

SAAS-API-TOKEN-LEAK is catalogued under the Credential Access tactic of the offensive-security kill-chain. It appears in 0 approved dossiers in the registry, typically.