Security Lunch ☀️ Ed. — Wednesday, July 22nd, 2026, 12:00 pm @ CoDa E160
Exposed API Credentials on the Web
Nurullah Demir
Can't make it in person? Join us on
zoom.
See our past & upcoming events on our
website!
Abstract:
Application programming interfaces (APIs) are a central part of modern IT environments, and developers authenticate to them with sensitive credentials such as API keys and tokens. Prior work has studied credential exposure in source code repositories and cloud
storage; however, the web remains unexplored. We conduct a large-scale analysis of API credential exposure on the web, analyzing 10 million webpages. We identify exposed credentials on 10,000 webpages from 14 critical service providers (e.g., cloud and payment
services), affecting high-stakes services. This includes access to the infrastructure of a global bank, the distribution software of a firmware developer used globally in RC devices such as drones, and many other critical infrastructure providers. In this
talk, I will share the root causes of these exposures, show that exposed credentials persist for a year on average and in some cases up to five years, and explain how our responsible disclosure reduced this risk by half within two weeks.
Bio:
Nurullah Demir is a Visiting Postdoc at Stanford (ESRG) and holds a Ph.D. from the Karlsruhe Institute of Technology. His research focuses on building automated, agentic systems to identify and mitigate structural security and privacy risks at internet scale.
He is a core maintainer of the open-source project HTTP Archive and Editor-in-Chief of the Web Almanac, an annual technical report on the state of the web.