All skills
mapbox avatar

/mapbox-token-security

@f5ae7de official
by mapboxmapbox/mapbox-agent-skills80 stars
17

Security best practices for Mapbox access tokens, including scope management, URL restrictions, rotation strategies, and protecting sensitive data. Use when creating, managing, or advising on Mapbox token security.

Use this Skill: https://skilld.dev/gh/mapbox/mapbox-agent-skills/mapbox-token-security

This session only. Nothing lands on disk.

referencesrotation-monitoring.md

≈510 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Token Rotation & Monitoring

Token Rotation Strategy

When to Rotate Tokens

Mandatory rotation:

  • Token exposed in public repository
  • Team member leaves with token access
  • Suspected compromise or breach
  • Service decommissioning
  • Compliance requirements

Scheduled rotation:

  • Every 90 days (recommended for production)
  • Every 30 days (high-security environments)
  • After major deployments
  • During security audits

Rotation Process

Zero-downtime rotation:

  1. Create new token with same scopes
  2. Deploy new token to canary/staging environment
  3. Verify functionality with new token
  4. Gradually roll out to production
  5. Monitor for issues for 24-48 hours
  6. Revoke old token after confirmation
  7. Update documentation with rotation date

Emergency rotation:

  1. Immediately revoke compromised token
  2. Create replacement token
  3. Deploy emergency update to all services
  4. Notify team of incident
  5. Investigate how compromise occurred
  6. Update procedures to prevent recurrence

Monitoring and Auditing

Track Token Usage

Metrics to monitor:

  • API request volume per token
  • Geographic distribution of requests
  • Error rates by token
  • Unexpected spike patterns
  • Requests from unauthorized domains

Alert on:

  • Usage from unexpected IPs/regions
  • Sudden traffic spikes (>200% normal)
  • High error rates (>10%)
  • Requests outside allowed URLs
  • Off-hours access patterns

Regular Security Audits

Monthly checklist:

  • Review all active tokens
  • Verify token scopes are still appropriate
  • Check for unused tokens (revoke if inactive >30 days)
  • Confirm URL restrictions are current
  • Review team member access
  • Check for tokens in public repositories (GitHub scan)
  • Verify documentation is up-to-date

Quarterly checklist:

  • Rotate production tokens
  • Full token inventory
  • Access control review
  • Update incident response procedures
  • Security training for team

Source: SKILL.md on GitHub

No alerts17d5 checks · Risk SAFE
  • Gen Agent Trust Hub17d

    The skill provides security best practices and educational guidance for managing Mapbox access tokens. It covers token types, scope management, URL restrictions, and secure storage via environment variables. No malicious patterns, code execution, or data exfiltration attempts were detected.

  • Socket17d

    No alerts

  • Snyk17d

    Risk: LOW · No issues

  • Runlayer6mo

    1/2 files flagged

  • ZeroLeaks5mo

    Score: 93/100 · 2 sections analyzed

Signed by skilld at f5ae7de. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 6 hours ago.

Activeupdated 2 months ago
  • Security
  • mapbox
  • tokens
  • access-control
  • api-keys
  • scope-management
  • url-restrictions
  • environment-variables

README badge

README badge for mapbox/mapbox-agent-skills/mapbox-token-security

Advises on Mapbox token security, including scope management, public vs secret token distinction, URL restrictions, and rotation strategies. Use when creating tokens, deciding scope levels, implementing storage policies, or responding to token compromise incidents.

Generated from the current SKILL.md.

What's the difference between public (pk.*), secret (sk.*), and temporary (tk.*) tokens?
Public tokens can be safely exposed in client-side code and are limited to read-only scopes like styles:read and fonts:read. Secret tokens have full API access and must never be exposed; use them only server-side. Temporary tokens are short-lived (max 1 hour), created by secret tokens, and automatically expire after use.
Can I use a secret token in a client-side application?
No. Secret tokens must never be exposed in client-side code. Always use public tokens for client-facing applications and store secret tokens only in server-side environment variables or secret management services.
What URL restrictions should I set on public tokens?
Set URL restrictions to your specific domain(s), such as https://myapp.com/* or https://*.myapp.com/*. Avoid overly broad patterns like * or *.com/*. Create separate tokens for each environment (production, staging, development) with their own URL restrictions.
How often should I rotate Mapbox tokens?
The skill recommends rotating tokens every 90 days as a baseline, though your organization's policy may differ. The skill includes detailed rotation strategies and monitoring guidance in the references/rotation-monitoring.md file.
What scopes should I grant to a public token that only displays a map?
Use the minimum required: styles:read, fonts:read, and styles:tiles if your map uses raster tile sources. Never grant write or delete scopes to public tokens.

Generated from the current SKILL.md. These answers refresh after source changes.