tmate-io / tmate

Instant Terminal Sharing
https://tmate.io/
Other
5.55k stars 298 forks source link

What powers do tmate API keys have? #304

Open kobus-v-schoor opened 2 days ago

kobus-v-schoor commented 2 days ago

Hi there, I'm trying to determine what access an attacker to get if they were to come into possession of my tmate API key. Could they see active named sessions? Could they do something else? From what I can tell the API key can only be used to create more named sessions, is that correct?

PS thanks for this awesome project!