Vercel API Token
Bridgecrew Policy ID: BC_GIT_74
Chekov Check ID: CKV_SECRET_74
Severity: LOW
Vercel API Token
Description
Vercel Access Tokens are required to authenticate and use the Vercel API. Tokens can be created and managed inside your account settings, and can be scoped to only allow access for specific Teams.
Fix - Buildtime
Vercel
Step 1: Revoke the key
- On Vercel, click on the avatar, then Account
- Click on the API Tokens
- Find the API Token you want to revoke and click on the trash icon
Step 2: Monitor for abuse
Updated 8 months ago