Skip to content
Tresna

Secret Scanner

Scan code for API keys, tokens, and passwords — without sending it anywhere.

secret-scanner

Results

Waiting for input

Waiting for input10 chars
Example

How to use this tool

Paste your code and find potential secrets before they leak. Everything runs in your browser — your code is never uploaded.

  1. 1Paste your code or configuration in the text area
  2. 2See every potential secret with its type and line number
  3. 3Fix or remove the secrets before sharing the code

What it detects

TypePattern
AWS Access KeyAKIA followed by 16 uppercase alphanumeric characters
GitHub Tokenghp_ followed by 36+ alphanumeric characters
JWTeyJ header with two base64url segments
Private Key-----BEGIN ... PRIVATE KEY-----
Passwordpassword, passwd, or pwd followed by a value
API Keyapi_key or api_secret followed by a value
Slack Tokenxoxb-, xoxp-, xoxa-, or xoxr- prefix
Stripe Keysk_live_ followed by 24+ characters

Why it matters

Accidentally committing secrets to a repository is one of the most common security mistakes. Once a secret is in git history, it is there forever — even if you delete it in a later commit. Scanning code before pushing catches these mistakes before they become incidents.

Online scanners require you to upload your code to a third-party server. If that code contains real secrets, you have just leaked them to someone else. A scanner that runs entirely in your browser eliminates that risk.

Limitations

This tool uses pattern matching, not semantic analysis. It will find strings that look like known secret formats, but it cannot detect a secret that does not match any pattern. It will also flag false positives — a string that looks like a secret but is not. Always review the results manually.

Frequently asked questions

Is my code uploaded anywhere?
No. Everything runs in your browser. Your code is never sent to any server.
Can I scan an entire repository?
No. This tool scans text you paste. For repository scanning, use a dedicated tool like git-secrets or truffleHog.
What if it finds a secret I did not know was there?
Rotate the secret immediately. If it was committed to a repository, consider it compromised and generate a new one.