What the attacker wants
API attackers call protected workloads with stolen keys, replayed tokens, mutated bodies, or revoked identities. The deployment question is whether possession of a long-lived credential still equals lasting caller rights after vault dump, CI leak, or agent clone - until rotation catches up.
