You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何查找文件中的Google API密钥及确认公司站点所用密钥的简便方法

Hey there! Let's tackle your two questions about Google API keys—they're common pain points, so I've got some practical tips for you.

1. 如何在文件中查找Google API密钥?

Google API keys follow a consistent format (AIza[0-9A-Za-z-_]{35}) — a 39-character string starting with AIza. Here are efficient ways to hunt them down:

  • Use regex for precise matching
    Most text editors and terminal tools support regular expressions, which avoids false positives from random text.
    • In Notepad++: Open the Find dialog (Ctrl+F), switch to the "Regular expression" mode, and paste AIza[0-9A-Za-z-_]{35} to locate keys instantly.
    • In Linux/macOS terminal: Run grep -r "AIza[0-9A-Za-z-_]\{35\}" /path/to/target/folder to search recursively.
    • In Windows PowerShell: Use Select-String -Path "C:\path\to\folder\*" -Pattern "AIza[0-9A-Za-z-_]{35}" for the same recursive search.
  • Narrow down to relevant file types
    API keys rarely hide in random text files. Focus on config files and code files like .env, .json, .js, .php, .py. In Notepad++, specify these types in the "Find in files" dialog (e.g., *.env;*.js;*.json) to cut down on search time and system load.
2. 确认Google API密钥所属站点的简便方法

If you can't run a full disk search without crashing the system, try these targeted approaches:

  • Check Google Cloud Console (most reliable)
    If you or your team has access to the Google Cloud project tied to the key:
    1. Log into Google Cloud Console, navigate to APIs & Services > Credentials.
    2. Find the API key in question.
    3. Look at its Restrictions: If "HTTP referrer restrictions" are set, you'll see the exact domains/sites allowed to use the key.
    4. Even without restrictions, check the Usage statistics tab—it shows recent request sources, which can point you to the site using the key.
  • Target only critical directories
    Skip full disk searches and focus on your web server's core directories (e.g., /var/www/html on Linux, C:\inetpub\wwwroot on Windows) or application config folders. Use the regex commands from the first question, but limit them to these specific paths. For example:
    # Linux/macOS: Search only JS and env files in the web root
    grep -r "AIza[0-9A-Za-z-_]\{35\}" /var/www/html --include="*.js" --include="*.env"
    
    # Windows: Target specific file types in the web root
    Select-String -Path "C:\inetpub\wwwroot\*.js", "C:\inetpub\wwwroot\.env" -Pattern "AIza[0-9A-Za-z-_]{35}"
    
  • Inspect the site's frontend directly
    If you have a list of suspect company sites, open each site in a browser, hit F12 to open DevTools, and go to the Network tab. Filter requests for googleapis.com, then check the request URL's key parameter—compare it to the key you have. This lets you verify without touching server files at all.

内容的提问来源于stack exchange,提问作者John Beasley

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.19 08:43:51