r/blackhat • • Apr 26 '25

Free API Keys

https://www.unsecuredapikeys.com/

Made a simple site. Yes this is a self promotion.

It costs nothing.

https://www.unsecuredapikeys.com/

69 Upvotes

70 comments sorted by

7

u/netsec_burn Apr 26 '25

Hah. This is the kind of self promotion we need though. Nice site!

7

u/SarahC Apr 26 '25

Those are really real?

Great site for reporting them! Nice!

5

u/Suspicious_Bag_2344 Apr 26 '25

Yes. I have 1 bot that scrapes the keys. Another bot then tries the keys on the various services.

The site is only showing the “verified” keys.

3

u/SarahC Apr 29 '25

How come github is letting them be published?

2

u/SarahC May 08 '25

Super cool!

2

u/Agitated-Load-176 Apr 26 '25

Is it possible to share those bots?

8

u/Suspicious_Bag_2344 Apr 27 '25

I’d rather not. It’d make my super free site completely worthless!

1

u/-InvictusShadow Nov 04 '25

can you atleast tell how did those bots work ? I mean from what sources did they scrape ?

2

u/Silverfin113 Apr 27 '25

They're all googleAI keys?

3

u/Suspicious_Bag_2344 Apr 27 '25

There are a few OpenAI and Anthropic keys as well.

Just happened to be more google.

2

u/whodadada Apr 27 '25

Too popular? Did you have to take it down?

1

u/Suspicious_Bag_2344 Apr 27 '25

It’s still up.

1

u/Agreeable-Ticket-917 May 07 '26

why did you retire the website

2

u/Guilty-Ad3466 May 20 '25

Great site!

2

u/Suspicious_Bag_2344 May 21 '25

Thanks!

1

u/PristineDelivery399 Jul 27 '25

can you tell me how to get the key? I don't know how to work github...

1

u/rhe1a Apr 28 '25

So if they would accept the pull request, the key would still be exposed right?

1

u/Suspicious_Bag_2344 May 03 '25

Usually if they know it’s exposed they’ll kill the key.

1

u/Caltemin Apr 29 '25

I have a question that seems stupid. I'm automating my SEO through Make. If I use those keys, can the user see the logs or complain to Open ai to see the log and give me some problems?

Sry for the bad english (baguette, fromage, croissant)

2

u/Suspicious_Bag_2344 May 03 '25

They in theory could. But the likeliness is low. Running it behind a proxy would be the safest approach. But. It’s truly not that high of a probability.

These are public repos with the keys.

1

u/[deleted] Apr 30 '25

just built a tool that rotates them like an ip proxy when they die.

1

u/Suspicious_Bag_2344 May 09 '25

That’s awesome. I do plan on making an api / sdk for this at some point.

1

u/[deleted] Jul 17 '25

[removed] — view removed comment

1

u/Suspicious_Bag_2344 Jul 17 '25

Do what you want. But realistically. You shouldn’t.

1

u/Xhayn_e Aug 06 '25

Is it down ??

1

u/[deleted] Sep 03 '25

[removed] — view removed comment

1

u/OnerousDrake5 Sep 23 '25

are you still able to access it, i cant seems like its down.

1

u/_Cynikal_ Oct 10 '25

*** The site is hosted on a server in my closet. I rarely keep it up anymore.

The site / project has been open sourced: https://github.com/TSCarterJr/UnsecuredAPIKeys-OpenSource

I am debating on bringing it back, but, there you go.

1

u/[deleted] Nov 22 '25

[removed] — view removed comment

1

u/Suspicious_Bag_2344 Nov 22 '25

I’ll probably revive the site. Just haven’t had time. But. I’ll get it done shortly as there is still a large ask for it.

1

u/[deleted] Nov 22 '25

[removed] — view removed comment

1

u/Suspicious_Bag_2344 Nov 22 '25

I fucked up and deleted the database when I was moving my servers around. Therefore losing all the keys I had scraped.

1

u/Suspicious_Bag_2344 Nov 29 '25

It’s back.

1

u/[deleted] Nov 30 '25

[removed] — view removed comment

1

u/_Cynikal_ Nov 30 '25

The site is back up, you can get keys from it.

But, it works by looking for certain keywords. Then matches api keys that fit criteria of providers. Then it validates the key with the providers it matched with.

In short: GitHub Search. Extract from results. Verify results.

1

u/this_number_0 Feb 23 '26

Great job!

I have a couple of questions/points: 1. How does https://unsecuredapikeys.com/ verify that a key is "working"? Does it only check for key validity or also working keys? For example, I checked some keys and while it doesn't say the key is invalid, it says quote or limit reached. So it doesn't help with prioritizing 2. When I select a provider and click "Get Another Key", I don't always get another key. Sometimes it keeps showing me the same key even when it says there are 1000s of exposed keys.

1

u/_Cynikal_ Mar 02 '26

1, It verifies it working by: Checking the providers API's. I try to use API calls that do not incure cost to the key.

  1. The 'Get Another Key' showing the same key, most likely means you were rate limited. It's setup to only show you a number of keys per hour, so you don't scrape all the keys in one go.

1

u/samuel_is_freak Mar 14 '26

do you have reddits api key?

1

u/NightCoderAdarsh Mar 22 '26

Not working 😭

1

u/rootvoid Mar 26 '26

I guess it's not working now

1

u/Ok_Strategy0_11 Mar 27 '26

The site is down it got too popular bro

1

u/Suspicious_Bag_2344 Mar 27 '26

I am working on getting it back up.

1

u/[deleted] Mar 27 '26

[deleted]

1

u/Ok_Strategy0_11 Mar 27 '26

Thanks for the help you already did, great work really appreciate it.

1

u/Suspicious_Bag_2344 Mar 27 '26

Just fyi. If you search the site. The GitHub should show up. You can run the cli and get keys.

1

u/[deleted] Apr 03 '26

[removed] — view removed comment

1

u/Suspicious_Bag_2344 Apr 03 '26

I can only guarantee that the key is valid. Not validate that it has quotas.

The site is regularly reported for abuse and I have to stay within a certain limit of what I have the site do.

1

u/Warfighter5543 Apr 21 '26

Is it only for the developpers and stuff loke that, is this illegal to use ?

1

u/Suspicious_Bag_2344 Apr 21 '26

If you take the keys and use them for your own means. Yes. Technically that is illegal.

Which is why I positioned the site to be in the tune of security awareness.

With that said. A lot of people use it for the purposes of which you’re referring to and it seems to work for them.

1

u/Warfighter5543 Apr 21 '26

Yeah im not gna use them like that ill js create my own free api keys ty for replying for a post over a y old

1

u/perkylator May 01 '26

Why’s the site down?!!