R-GMA
gmapsapiscanner
Checks a discovered or leaked Google Maps API key against the many distinct Maps Platform APIs to see which are enabled and exploitable for billing abuse or data exposure.
OVERVIEW
gmapsapiscanner (github.com/ozguralp/gmapsapiscanner, by Ozgur Alp) tests a given Google Maps API key against the roughly 20 distinct APIs that sit under the Google Maps Platform umbrella — Directions, Places, Geocoding, Static Maps, Street View, Distance Matrix, and more — and reports which of them the key can actually call. This matters because a single leaked key rarely maps cleanly to "exposed" or "safe": each API has its own enablement flag, its own quota, and its own abuse potential.
A key shipped unrestricted in a mobile app or website's client-side JavaScript is a common finding, and the practical impact ranges from straightforward billing abuse — running up the key owner's Google Cloud bill by hammering a paid API — to data exposure, when an enabled API like Places Details or Geocoding leaks more information than the application intended to expose to end users.
USE CASES
Practical use cases
- 01
Confirming which Maps Platform APIs a key found in a mobile app's decompiled source or network traffic can call.
- 02
Checking a Maps API key discovered in a website's client-side JavaScript for missing HTTP-referrer or API restrictions.
- 03
Demonstrating billing-abuse potential of an unrestricted key as evidence for a bug bounty or assessment finding.
- 04
Assessing whether an enabled API (e.g. Places Details) leaks more data than the application's intended use case.
QUICK START
After finding a Google Maps API key embedded in a mobile app, website, or source repository, to check which of the many Maps Platform APIs it can actually call.
- Clone the repository and install the Python dependencies from requirements.txt / pyproject.toml.
- Confirm the discovered key was found in scope (client's own app/site/repo) and not obtained by unauthorized means.
- Run the scanner with `--api-key` pointing at the discovered key.
- Review which APIs responded successfully and cross-reference each with its potential for billing abuse or data exposure.
python3 maps_api_scanner.py --api-key AIzaSy...leaked-key --no-jsapiBEFORE YOU RUN IT
What to check before running it
A successful call against a paid API consumes the key owner's real Google Cloud quota and billing — keep test volume minimal and only probe each API once it needs confirming.
Treat a positive result as a starting point for exploitability, not proof of impact — pair it with a concrete abuse scenario (cost run-up, data leak) before reporting.
Only scan keys found within the engagement's authorized scope; scanning a key harvested from an unrelated third party is out of bounds.