All skills
mapbox avatar

/mapbox-token-security

@f5ae7de official
by mapboxmapbox/mapbox-agent-skills80 stars
17

Security best practices for Mapbox access tokens, including scope management, URL restrictions, rotation strategies, and protecting sensitive data. Use when creating, managing, or advising on Mapbox token security.

Use this Skill: https://skilld.dev/gh/mapbox/mapbox-agent-skills/mapbox-token-security

This session only. Nothing lands on disk.

AGENTS.md

≈1.5k tokens on demand. Your agent reads this file only when SKILL.md points to it.

Mapbox Token Security Guide

Quick reference for securing Mapbox access tokens. Critical security rules for token management.

Token Types - Quick Reference

Type Format Use Can Expose?
Public pk.* Client-side, mobile apps ✅ Yes (with URL restrictions)
Secret sk.* Server-side only ❌ NEVER expose
Temporary tk.* One-time operations ✅ Yes (expires in 1hr)

Critical Security Rules

❌ Never Do This

// ❌ NEVER commit tokens
const MAPBOX_TOKEN = 'pk.eyJ1...'; // Don't hardcode!

// ❌ NEVER use secret tokens client-side
<script>mapboxgl.accessToken = 'sk.eyJ1...'; // Exposed to users!</script>;

// ❌ NEVER log tokens
console.log('Token:', token); // Shows in browser console

// ❌ NEVER share tokens in public repos
// .env file committed to GitHub

✅ Always Do This

// ✅ Use environment variables
const MAPBOX_TOKEN = process.env.NEXT_PUBLIC_MAPBOX_TOKEN;

// ✅ Add URL restrictions to public tokens
// In Mapbox dashboard: Restrict to your domain(s)

// ✅ Use secret tokens only server-side
// server.js or API routes only

// ✅ Add .env to .gitignore
// .gitignore
.env
.env.local

Token Selection Decision Tree

Question 1: Where will this token be used?

  • Client-side (browser/mobile) → Use public token (pk.*)
  • Server-side (API/backend) → Use secret token (sk.*)
  • One-time operation → Use temporary token (tk.*)

Question 2: What operations are needed?

  • Display maps only → Public token with styles:tiles, styles:read
  • Upload/modify data → Secret token with write scopes
  • Administrative tasks → Secret token with admin scopes

Scope Management

Public Token Scopes (Most Common)

✅ styles:tiles    - Display raster style tiles
✅ styles:read     - Read style specifications
✅ fonts:read      - Access Mapbox fonts
✅ datasets:read   - Read dataset data

Secret Token Scopes (Server-Side Only)

⚠️  styles:write   - Create/modify styles
⚠️  styles:list    - List all styles
⚠️  tokens:write   - Create/modify tokens
⚠️  uploads:write  - Upload data

Principle: Grant minimum scopes needed. Don't use styles:write if only reading.

URL Restrictions

For all public tokens, always add URL restrictions:

  1. Go to Mapbox Dashboard → Access Tokens
  2. Select token → URL Restrictions
  3. Add allowed URLs:
    http://localhost:*          # Development
    https://yourdomain.com/*    # Production
    https://*.yourdomain.com/*  # Subdomains

Impact: Prevents token abuse if exposed. Must do for production.

Environment Variable Setup

Web Applications

# .env.local (Next.js, Vite)
NEXT_PUBLIC_MAPBOX_TOKEN=pk.your_token_here
VITE_MAPBOX_TOKEN=pk.your_token_here

# .env (Create React App)
REACT_APP_MAPBOX_TOKEN=pk.your_token_here

Mobile Applications

// iOS (Config.xcconfig)
MAPBOX_TOKEN = pk.your_token_here;

// Android (gradle.properties)
MAPBOX_TOKEN = pk.your_token_here;

Always add to .gitignore:

.env
.env.local
.env.*.local

Token Rotation

When to rotate:

  • 🔴 Immediately if token exposed publicly (GitHub, logs, etc.)
  • 🟡 Every 90 days for secret tokens (best practice)
  • 🟡 When team member leaves with access
  • 🟡 After security incident

How to rotate safely:

  1. Create new token with same scopes
  2. Update environment variables
  3. Deploy new code
  4. Verify new token works
  5. Delete old token (grace period: 24-48hrs)

Common Vulnerabilities

1. Token in Public Repository

Risk: Anyone can use your token, rack up charges Fix: Immediately rotate token, add to .gitignore, use git history rewrite if needed

2. No URL Restrictions

Risk: Token can be used on any domain Fix: Add URL restrictions in dashboard immediately

3. Secret Token in Frontend

Risk: Full API access exposed to all users Fix: Move to server-side, rotate token immediately

4. Overly Permissive Scopes

Risk: Token can do more than needed Fix: Create new token with minimum required scopes

Token Exposure Response

If token is exposed publicly:

  1. Immediately create new token in dashboard
  2. Update environment variables with new token
  3. Deploy updated code
  4. Delete exposed token in dashboard
  5. Check Mapbox dashboard for unexpected usage
  6. Add URL restrictions to new token
  7. Review security practices

Don't wait - exposed tokens can be used within minutes.

Quick Security Checklist

✅ Using public tokens (pk.) for client-side? ✅ URL restrictions added to all public tokens? ✅ No tokens hardcoded in source code? ✅ .env files in .gitignore? ✅ Secret tokens (sk.) only used server-side? ✅ Minimum scopes granted per token? ✅ Tokens rotated regularly (90 days)? ✅ No tokens in logs or console output? ✅ Different tokens for dev/staging/production? ✅ Team members have individual tokens (not shared)?

Framework-Specific Patterns

Next.js

// Public token (client-side)
const token = process.env.NEXT_PUBLIC_MAPBOX_TOKEN;

// Secret token (server-side API routes only)
const secretToken = process.env.MAPBOX_SECRET_TOKEN;

React

// Must use REACT_APP_ prefix
const token = process.env.REACT_APP_MAPBOX_TOKEN;

Vue/Vite

// Must use VITE_ prefix
const token = import.meta.env.VITE_MAPBOX_TOKEN;

Rate Limiting

Free tier limits:

  • 50,000 map loads/month
  • 100,000 API requests/month

Best practices:

  • Cache tiles in CDN
  • Implement client-side caching
  • Monitor usage in dashboard
  • Set up usage alerts

If approaching limits: Upgrade plan or optimize caching.

Source: SKILL.md on GitHub

No alerts17d5 checks · Risk SAFE
  • Gen Agent Trust Hub17d

    The skill provides security best practices and educational guidance for managing Mapbox access tokens. It covers token types, scope management, URL restrictions, and secure storage via environment variables. No malicious patterns, code execution, or data exfiltration attempts were detected.

  • Socket17d

    No alerts

  • Snyk17d

    Risk: LOW · No issues

  • Runlayer6mo

    1/2 files flagged

  • ZeroLeaks5mo

    Score: 93/100 · 2 sections analyzed

Signed by skilld at f5ae7de. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 6 hours ago.

Activeupdated 2 months ago
  • Security
  • mapbox
  • tokens
  • access-control
  • api-keys
  • scope-management
  • url-restrictions
  • environment-variables

README badge

README badge for mapbox/mapbox-agent-skills/mapbox-token-security

Advises on Mapbox token security, including scope management, public vs secret token distinction, URL restrictions, and rotation strategies. Use when creating tokens, deciding scope levels, implementing storage policies, or responding to token compromise incidents.

Generated from the current SKILL.md.

What's the difference between public (pk.*), secret (sk.*), and temporary (tk.*) tokens?
Public tokens can be safely exposed in client-side code and are limited to read-only scopes like styles:read and fonts:read. Secret tokens have full API access and must never be exposed; use them only server-side. Temporary tokens are short-lived (max 1 hour), created by secret tokens, and automatically expire after use.
Can I use a secret token in a client-side application?
No. Secret tokens must never be exposed in client-side code. Always use public tokens for client-facing applications and store secret tokens only in server-side environment variables or secret management services.
What URL restrictions should I set on public tokens?
Set URL restrictions to your specific domain(s), such as https://myapp.com/* or https://*.myapp.com/*. Avoid overly broad patterns like * or *.com/*. Create separate tokens for each environment (production, staging, development) with their own URL restrictions.
How often should I rotate Mapbox tokens?
The skill recommends rotating tokens every 90 days as a baseline, though your organization's policy may differ. The skill includes detailed rotation strategies and monitoring guidance in the references/rotation-monitoring.md file.
What scopes should I grant to a public token that only displays a map?
Use the minimum required: styles:read, fonts:read, and styles:tiles if your map uses raster tile sources. Never grant write or delete scopes to public tokens.

Generated from the current SKILL.md. These answers refresh after source changes.