Skip to main content

Python Package Index Key

Description​

General​

  • Documentation: https://warehouse.readthedocs.io/api-reference/index.html
  • Summary: The python package index also called PyPI is the official software repository for Python. It is often used as a default source for packages by package managers. PyPI exposes an API to interact with the repository. This detectors catches the PyPI API keys used to perform authentication when uploading packages.

Revoke the secret​

API keys can be revoked from the account settings page.

Details for Python Package Index Key​

  • Family: token

  • Category: package_registry

  • Company: Python Package Index

  • High recall: True

  • Validity check available: True

  • Analyzer available: True

  • Revoker available: False

  • On-premise instances exist: False

  • Only valid secrets raise an alert: False

  • Occurrences found for one million commits: 4.47

  • Prefixed: True

Secret Analyzer​

Analysis Method​

  • Provider allows scopes enumeration: True
  • Total network call count: 2
  • Total call count may vary: True

HTTP Calls​

Requests are designed to capture metadata and not to function effectively.

  • POST: https://test.pypi.org/legacy/
  • POST: https://upload.pypi.org/legacy/

Other Calls​

Non-HTTP queries or HTTP calls made through a third-party app (e.g., Python package). No other calls for this analyzer.