如何查找文件中的Google API密钥及确认公司站点所用密钥的简便方法
Hey there! Let's tackle your two questions about Google API keys—they're common pain points, so I've got some practical tips for you.
1. 如何在文件中查找Google API密钥?
Google API keys follow a consistent format (AIza[0-9A-Za-z-_]{35}) — a 39-character string starting with AIza. Here are efficient ways to hunt them down:
- Use regex for precise matching
Most text editors and terminal tools support regular expressions, which avoids false positives from random text.- In Notepad++: Open the Find dialog (Ctrl+F), switch to the "Regular expression" mode, and paste
AIza[0-9A-Za-z-_]{35}to locate keys instantly. - In Linux/macOS terminal: Run
grep -r "AIza[0-9A-Za-z-_]\{35\}" /path/to/target/folderto search recursively. - In Windows PowerShell: Use
Select-String -Path "C:\path\to\folder\*" -Pattern "AIza[0-9A-Za-z-_]{35}"for the same recursive search.
- In Notepad++: Open the Find dialog (Ctrl+F), switch to the "Regular expression" mode, and paste
- Narrow down to relevant file types
API keys rarely hide in random text files. Focus on config files and code files like.env,.json,.js,.php,.py. In Notepad++, specify these types in the "Find in files" dialog (e.g.,*.env;*.js;*.json) to cut down on search time and system load.
2. 确认Google API密钥所属站点的简便方法
If you can't run a full disk search without crashing the system, try these targeted approaches:
- Check Google Cloud Console (most reliable)
If you or your team has access to the Google Cloud project tied to the key:- Log into Google Cloud Console, navigate to APIs & Services > Credentials.
- Find the API key in question.
- Look at its Restrictions: If "HTTP referrer restrictions" are set, you'll see the exact domains/sites allowed to use the key.
- Even without restrictions, check the Usage statistics tab—it shows recent request sources, which can point you to the site using the key.
- Target only critical directories
Skip full disk searches and focus on your web server's core directories (e.g.,/var/www/htmlon Linux,C:\inetpub\wwwrooton Windows) or application config folders. Use the regex commands from the first question, but limit them to these specific paths. For example:# Linux/macOS: Search only JS and env files in the web root grep -r "AIza[0-9A-Za-z-_]\{35\}" /var/www/html --include="*.js" --include="*.env"# Windows: Target specific file types in the web root Select-String -Path "C:\inetpub\wwwroot\*.js", "C:\inetpub\wwwroot\.env" -Pattern "AIza[0-9A-Za-z-_]{35}" - Inspect the site's frontend directly
If you have a list of suspect company sites, open each site in a browser, hit F12 to open DevTools, and go to the Network tab. Filter requests forgoogleapis.com, then check the request URL'skeyparameter—compare it to the key you have. This lets you verify without touching server files at all.
内容的提问来源于stack exchange,提问作者John Beasley
相关产品推荐
相关产品推荐

