All skills
mapbox avatar

/mapbox-token-security

@f5ae7de official
by mapboxmapbox/mapbox-agent-skills80 stars
17

Security best practices for Mapbox access tokens, including scope management, URL restrictions, rotation strategies, and protecting sensitive data. Use when creating, managing, or advising on Mapbox token security.

Use this Skill: https://skilld.dev/gh/mapbox/mapbox-agent-skills/mapbox-token-security

This session only. Nothing lands on disk.

referencesincident-response.md

≈586 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Incident Response & Common Mistakes

Incident Response Plan

If a Token is Compromised

Immediate actions (first 15 minutes):

  1. Revoke the token via Mapbox dashboard or API
  2. Create replacement token with different scopes/restrictions if needed
  3. Update all services using the compromised token
  4. Notify team via incident channel

Investigation (within 24 hours): 5. Review access logs to understand exposure 6. Check for unauthorized usage in Mapbox dashboard 7. Identify root cause (how was it exposed?) 8. Document incident with timeline and impact

Prevention (within 1 week): 9. Update procedures to prevent recurrence 10. Implement additional safeguards (CI checks, secret scanning) 11. Train team on lessons learned 12. Update documentation with new security measures

Common Security Mistakes

1. Exposing Secret Tokens in Client Code

❌ CRITICAL ERROR:

// NEVER DO THIS - Secret token in client code
const map = new mapboxgl.Map({
  accessToken: 'sk.YOUR_SECRET_TOKEN_HERE' // SECRET TOKEN
});

✅ Correct:

// Public token only in client code
const map = new mapboxgl.Map({
  accessToken: 'pk.YOUR_PUBLIC_TOKEN_HERE' // PUBLIC TOKEN
});

2. Overly Permissive Scopes

❌ Too broad:

{
  "scopes": ["styles:*", "tokens:*"]
}

✅ Specific:

{
  "scopes": ["styles:read"]
}

3. Missing URL Restrictions

❌ No restrictions:

{
  "scopes": ["styles:read"],
  "allowedUrls": [] // Token works anywhere
}

✅ Domain restricted:

{
  "scopes": ["styles:read"],
  "allowedUrls": ["https://myapp.com/*"]
}

4. Long-Lived Tokens Without Rotation

❌ Never rotated:

Token created: Jan 2020
Last rotation: Never
Still in production: Yes

✅ Regular rotation:

Token created: Dec 2024
Last rotation: Dec 2024
Next rotation: Mar 2025

5. Tokens in Version Control

❌ Committed to Git:

// config.js (committed to repo)
export const MAPBOX_TOKEN = 'sk.YOUR_SECRET_TOKEN_HERE';

✅ Environment variables:

// config.js
export const MAPBOX_TOKEN = process.env.MAPBOX_SECRET_TOKEN;
# .env (in .gitignore)
MAPBOX_SECRET_TOKEN=sk.YOUR_SECRET_TOKEN_HERE

Source: SKILL.md on GitHub

No alerts17d5 checks · Risk SAFE
  • Gen Agent Trust Hub17d

    The skill provides security best practices and educational guidance for managing Mapbox access tokens. It covers token types, scope management, URL restrictions, and secure storage via environment variables. No malicious patterns, code execution, or data exfiltration attempts were detected.

  • Socket17d

    No alerts

  • Snyk17d

    Risk: LOW · No issues

  • Runlayer6mo

    1/2 files flagged

  • ZeroLeaks5mo

    Score: 93/100 · 2 sections analyzed

Signed by skilld at f5ae7de. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 5 hours ago.

Activeupdated 2 months ago
  • Security
  • mapbox
  • tokens
  • access-control
  • api-keys
  • scope-management
  • url-restrictions
  • environment-variables

README badge

README badge for mapbox/mapbox-agent-skills/mapbox-token-security

Advises on Mapbox token security, including scope management, public vs secret token distinction, URL restrictions, and rotation strategies. Use when creating tokens, deciding scope levels, implementing storage policies, or responding to token compromise incidents.

Generated from the current SKILL.md.

What's the difference between public (pk.*), secret (sk.*), and temporary (tk.*) tokens?
Public tokens can be safely exposed in client-side code and are limited to read-only scopes like styles:read and fonts:read. Secret tokens have full API access and must never be exposed; use them only server-side. Temporary tokens are short-lived (max 1 hour), created by secret tokens, and automatically expire after use.
Can I use a secret token in a client-side application?
No. Secret tokens must never be exposed in client-side code. Always use public tokens for client-facing applications and store secret tokens only in server-side environment variables or secret management services.
What URL restrictions should I set on public tokens?
Set URL restrictions to your specific domain(s), such as https://myapp.com/* or https://*.myapp.com/*. Avoid overly broad patterns like * or *.com/*. Create separate tokens for each environment (production, staging, development) with their own URL restrictions.
How often should I rotate Mapbox tokens?
The skill recommends rotating tokens every 90 days as a baseline, though your organization's policy may differ. The skill includes detailed rotation strategies and monitoring guidance in the references/rotation-monitoring.md file.
What scopes should I grant to a public token that only displays a map?
Use the minimum required: styles:read, fonts:read, and styles:tiles if your map uses raster tile sources. Never grant write or delete scopes to public tokens.

Generated from the current SKILL.md. These answers refresh after source changes.