Coder answered 15 fingerprints: development environments that hold repository and cloud credentials
Coder provisions development environments from templates and gives the people who own them a shell inside that environment. It is a platform for creating workspaces, and it necessarily holds the keys that those workspaces need in order to be useful.
Query and scope
The query app="Coder" returned 15 matches on 2026-10-06 with the scope set to all asset types. The result is an application fingerprint, so it describes services whose banner names the product.
What a workspace platform must hold
Provisioning a workspace means reaching a compute provider, cloning repositories and, in most setups, authenticating the developer who asked for it. The platform therefore stores provider credentials, template definitions and, through single sign-on, the identity of each user. It also brokers the tokens that a workspace uses to reach the internal systems it was created for.
That combination places a workspace platform in the same category as a build system. Both create environments that need access, and both become the place where the access is defined. The platform itself is reachable through a web interface and an API, and the API is what the command line client talks to.
Where the control sits
The product implements user roles, workspace ownership and template permissions, and it supports external identity providers. Authentication is enforced for the interface by default. The open questions in a given deployment are which provider is configured, whether registration is open, and how broad the template permissions are. A template that provisions a privileged container with a mounted provider credential decides the blast radius of every workspace built from it.
Reading 15 honestly
Fifteen fingerprints is a small population, and it matches the profile of a platform that organisations run internally. Nothing in the count says that any of those instances is misconfigured. What it says is that a workspace platform, which by design holds credentials with which to reach other systems, is occasionally reachable, and that the design intent of such a platform is worth understanding before it is exposed.
Practical steps
Confirm that authentication is enabled and that self-registration is closed. Review the templates for privileged containers, mounted host paths and long-lived credentials, because the template is the access policy. Confirm that the API is behind the same controls as the interface, and check the platform's own release notes, since a product that stores provider credentials is a high-value target when a flaw becomes known.
References
[1] Coder documentation, coder.com
[2] CWE-862, Missing Authorization, cwe.mitre.org
Top comments (0)