SaaSFraud

Bug-Bounty Triage

Validate reported key leaks fast and confirm whether the credential is still live.

Exposed API keys · 1 credit per finding per lookup · no monthly fee

Report #56Confirmed live
gh_pat_…

How it works

1

Scope your assets

Tell Encrata which domains, orgs and key patterns you own so results are matched to assets that are actually yours.

2

We sweep public sources

Encrata checks public code, gists and paste sites for credentials tied to your assets and confirms whether each is still live.

3

Rotate and prove it

Get each exposed key with its source and status, rotate it, and keep the record for auditors. One credit per exposed credential found.

One call, structured answer

Bug-Bounty Triage runs on the exposed api keys lookup at 1 credit per finding per lookup. Same API key, same JSON shape as every other Encrata lookup.

  • Matches leaked keys to assets you own, not generic noise
  • Confirms whether each exposed credential is still live
  • Clean sweeps cost nothing, you only pay per finding
  • Gives auditors concrete evidence of active credential monitoring
Terminal
curl -X POST "https://developer.encrata.com/api/breaches/exposed-keys" \
-H "Authorization: Bearer YOUR_API_KEY" \
-H "Content-Type: application/json" \
-d '{"query": "acme.com"}'
response.json
{
"query": "acme.com",
"findings": [
{ "type": "stripe_secret_key", "source": "gist.github.com/xxxx", "status": "live" }
],
"credits": 1
}

More exposed api keys use cases

View all
Start with 500 free credits
$curl https://developer.encrata.com/api/lookup -H "Authorization: Bearer YOUR_API_KEY" -d '{"e": "satya@microsoft.com"}'