Exposed Secrets Scanner
Detect API keys, tokens in code
⚠ This runs locally. Secrets never leave your browser.
📚 Learn more — how it works, FAQ & guide Click to expand
Learn more — how it works, FAQ & guide
Click to expand
Exposed secrets scanner
How to use this tool
- 1
Paste code or HTML
- 2
See detected secrets
Frequently Asked Questions
What counts as a secret?
API keys (AWS, OpenAI, Stripe, GitHub), bearer tokens, private keys, DB credentials, webhooks. Never deploy with these in client code.
You might also like
🔒
100% Privacy. This tool runs entirely in your browser. Your data is never uploaded to any server.