Pro tip: a guy at a Dallas API meetup showed me my auth tokens were sitting in the URL logs and I had no clue
He pulled up his laptop and pointed at a token pasted right into a GET request, and I realized mine were doing the same thing on 3 endpoints since January... swapped them to headers the next morning. Anyone else find out the hard way that stuff you log at a proxy can bite you?
That line about tokens sitting in the URL logs since January is what got me. That's months of them just sitting there, and you'd never know unless somebody showed you. I had the same thing happen with a webhook setup where I was logging full requests to debug something and forgot to turn it off. Took me weeks to notice, and by then those logs had been copied to a backup I wasn't even watching. Swapping to headers is the easy part, it's the stuff already logged that keeps you up at night.