> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-385.md).

# Zoho OAuth token detected in code

## Rule Details

|                       |                     |
| --------------------- | ------------------- |
| Cortex AppSec Rule ID | APPSEC\_SECRET\_385 |
| Category              | API Keys            |
| Severity              | HIGH                |
| Framework             | Git                 |

## Impact

A Zoho OAuth token (authorization code, access token, or refresh token) grants API access to the user's Zoho account on behalf of an integrated application, scoped by the granted OAuth scopes. All three artifact types share the same wire format `1000.<32hex>.<32hex>`. Exposure allows an attacker to read or modify the user's Zoho data (Mail, CRM, Books, WorkDrive, etc.) within the granted scopes until the token is revoked or expires. Rotate immediately by revoking the token from the Zoho API Console and re-issuing via the OAuth flow.

## How to Fix

Revoke the exposed Zoho OAuth token via the Zoho API Console (<https://api-console.zoho.com>) or by calling the Zoho OAuth revoke endpoint. Re-run the OAuth authorization flow to issue a fresh token, distribute it via a secrets manager, and purge the leaked value from git history.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/appsec-rules/secrets-security/appsec-secret-385.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
