Secret Scanner
Scan code for API keys, tokens, and passwords — without sending it anywhere.
secret-scanner
Waiting for input
How to use this tool
Paste your code and find potential secrets before they leak. Everything runs in your browser — your code is never uploaded.
- 1Paste your code or configuration in the text area
- 2See every potential secret with its type and line number
- 3Fix or remove the secrets before sharing the code
What it detects
| Type | Pattern |
|---|---|
| AWS Access Key | AKIA followed by 16 uppercase alphanumeric characters |
| GitHub Token | ghp_ followed by 36+ alphanumeric characters |
| JWT | eyJ header with two base64url segments |
| Private Key | -----BEGIN ... PRIVATE KEY----- |
| Password | password, passwd, or pwd followed by a value |
| API Key | api_key or api_secret followed by a value |
| Slack Token | xoxb-, xoxp-, xoxa-, or xoxr- prefix |
| Stripe Key | sk_live_ followed by 24+ characters |
Why it matters
Accidentally committing secrets to a repository is one of the most common security mistakes. Once a secret is in git history, it is there forever — even if you delete it in a later commit. Scanning code before pushing catches these mistakes before they become incidents.
Online scanners require you to upload your code to a third-party server. If that code contains real secrets, you have just leaked them to someone else. A scanner that runs entirely in your browser eliminates that risk.
Limitations
This tool uses pattern matching, not semantic analysis. It will find strings that look like known secret formats, but it cannot detect a secret that does not match any pattern. It will also flag false positives — a string that looks like a secret but is not. Always review the results manually.
Frequently asked questions
- Is my code uploaded anywhere?
- No. Everything runs in your browser. Your code is never sent to any server.
- Can I scan an entire repository?
- No. This tool scans text you paste. For repository scanning, use a dedicated tool like git-secrets or truffleHog.
- What if it finds a secret I did not know was there?
- Rotate the secret immediately. If it was committed to a repository, consider it compromised and generate a new one.