Self-Discovering API Key Permissions and Resources - Joseph Leon, Dylan Ayrey @OWASPGLOBAL
Self-Discovering API Key Permissions and Resources - Joseph Leon, Dylan Ayrey  @OWASPGLOBAL
Uploaded March 2025 | Updated September 2026, 2 weeks ago
You're a security analyst triaging a list of exposed credentials - how do you prioritize which key to rotate first? How do you even know what resources the key can access? Most SaaS providers make it difficult to enumerate the access granted to a particular credential without logging into their UI.


In this talk, we're releasing a new method (self-discovery) for enumerating the permissions and resources associated with API keys and other secrets, without requiring access to the provider's UI. We'll walk through the meticulous steps required to accurately assess different SaaS providers' permission and scopes, as well as share the logic behind how to validate key permissions, including string analysis, HTTP request brute forcing and more.


Finally, we'll demo a new open-source tool that automates the enumeration of API key permissions and accessible resources, without requiring access to the provider's UI.

-

Managed by the OWASP® Foundation
owasp.org
Self-Discovering API Key Permissions and Resources - Joseph Leon, Dylan AyreyOWASP IoT Security Testing Guide (ISTG) - Aaron GuzmanFixing My Fixing Talk: What We Got Wrong (and Right) About AI Auto-RemediationOWASP Global AppSec EU 2025 BarcelonaGlobal AppSec Dublin: Passwordless Future: Using WebAuthn And Passkeys In Practice - Clemens HübnerInfoSecMap x OWASP CollaborationThe Most Common AppSec Failures in Fortune 500 Companies and BeyondAutomatic application hardening by leveraging container runtime behavior analysis - Amit SchendelNo Admittance Except on Party Business - A Hobbits Memoir about an InfoSec JourneyOWASP Low-Code/No-Code Top 10 (LCNC) - Michael BarguryMCP Deception Incubator — Honeytraps as a Framework for Zero Trust AI Environments track 2From Maturity to Mastery: Accelerating Software Security with OWASP SAMM
OWASP Foundation |

Self-Discovering API Key Permissions and Resources - Joseph Leon, Dylan Ayrey

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER