Skip to content
OPS // KITitspentest.sh

R-GMA

gmapsapiscanner

Checks a discovered or leaked Google Maps API key against the many distinct Maps Platform APIs to see which are enabled and exploitable for billing abuse or data exposure.

Official siteBack to catalog

OVERVIEW

gmapsapiscanner (github.com/ozguralp/gmapsapiscanner, by Ozgur Alp) tests a given Google Maps API key against the roughly 20 distinct APIs that sit under the Google Maps Platform umbrella — Directions, Places, Geocoding, Static Maps, Street View, Distance Matrix, and more — and reports which of them the key can actually call. This matters because a single leaked key rarely maps cleanly to "exposed" or "safe": each API has its own enablement flag, its own quota, and its own abuse potential.

A key shipped unrestricted in a mobile app or website's client-side JavaScript is a common finding, and the practical impact ranges from straightforward billing abuse — running up the key owner's Google Cloud bill by hammering a paid API — to data exposure, when an enabled API like Places Details or Geocoding leaks more information than the application intended to expose to end users.

USE CASES

Practical use cases

  • 01

    Confirming which Maps Platform APIs a key found in a mobile app's decompiled source or network traffic can call.

  • 02

    Checking a Maps API key discovered in a website's client-side JavaScript for missing HTTP-referrer or API restrictions.

  • 03

    Demonstrating billing-abuse potential of an unrestricted key as evidence for a bug bounty or assessment finding.

  • 04

    Assessing whether an enabled API (e.g. Places Details) leaks more data than the application's intended use case.

QUICK START

After finding a Google Maps API key embedded in a mobile app, website, or source repository, to check which of the many Maps Platform APIs it can actually call.

  1. Clone the repository and install the Python dependencies from requirements.txt / pyproject.toml.
  2. Confirm the discovered key was found in scope (client's own app/site/repo) and not obtained by unauthorized means.
  3. Run the scanner with `--api-key` pointing at the discovered key.
  4. Review which APIs responded successfully and cross-reference each with its potential for billing abuse or data exposure.
python3 — bash
python3 maps_api_scanner.py --api-key AIzaSy...leaked-key --no-jsapi

BEFORE YOU RUN IT

What to check before running it

A successful call against a paid API consumes the key owner's real Google Cloud quota and billing — keep test volume minimal and only probe each API once it needs confirming.

Treat a positive result as a starting point for exploitability, not proof of impact — pair it with a concrete abuse scenario (cost run-up, data leak) before reporting.

Only scan keys found within the engagement's authorized scope; scanning a key harvested from an unrelated third party is out of bounds.

KEEP EXPLORING

View the whole phase →