An old dev named Ray showed me a curl command back in 2016 that still saves me
Back in 2016 I was doing IT grunt work at a shop in Sacramento, not security, just resetting passwords and running cable. An older dev named Ray watched me poke at an endpoint in a browser tab for like 20 minutes and finally walked over. He typed curl -v and showed me how the raw request and response showed everything the pretty UI hid, headers, status codes, the works. He said most people never look at what their app actually sends, and that is where the leaks live. I still run a plain curl against any new API I touch before I trust it with real data. These days everything is a fancy dashboard with hidden fields, and I wonder how many teams out there are shipping keys or tokens they never even see. What is your go to first move when you poke at a strange API?
My buddy Dan found a live Stripe key sitting in a JS file just by running curl against some startup's checkout page. Took him 30 seconds and he still tells that story at every meetup.