fapi is a simple tool to find exposed API keys from subdomains using Wayback Machine, gau, and hakrawler.
- Finds subdomains using
subfinder
- Extracts JavaScript files using
waybackurls
,gau
, andhakrawler
- Extracts API keys from
.js
files only (to reduce false positives) - Saves results to a file if specified
Install dependencies first:
sudo apt install subfinder
go install github.com/tomnomnom/waybackurls@latest
go install github.com/lc/gau@latest
go install github.com/hakluke/hakrawler@latest
go install github.com/tomnomnom/anew@latest
git clone https://github.com/jr-boney/fapi
cd fapi
sudo mv fapi /usr/local/bin/fapi
sudo chmod +x /usr/local/bin/fapi
fapi -d example.com
To save results to a file:
fapi -d example.com -o results.txt