The goodsAPI key

Leaked API key

A cloud, payment or messaging credential lifted out of a config file, a repository or a stealer log and traded on its own. No password reset touches it, and most carry no expiry.

Why it matters to you

Key material rarely shows up in login telemetry, because it does not log in. Inventory what each key can reach and rotate on a schedule rather than on suspicion.

Where we meet it

A log carries far more than browser passwords, and the config and token files inside it are the part a victim never thinks to check. That is where a key that appeared in no breach notice turns up.

Where this term stops being vocabulary

Sherlog is where you watch it happen to you

Knowing the word is the cheap half. The platform is the half where the term arrives attached to your domain, with a timestamp and the source it came from.