OWASP API2 2023 No Credentials in URL (Edit)
URL parameters MUST NOT contain credentials such as API key, password, or secret. This is a security risk as URLs are often logged and cached.
OWASPSecurityCredentialsOpenAPI
URL parameters MUST NOT contain credentials such as API key, password, or secret. This is a security risk as URLs are often logged and cached.