Free tools

Secret checker.

Paste code or a config file to find strings that look like API keys and credentials. Everything runs in your browser.

Scanned in your browser as you type. Nothing you paste leaves this page, and matches are shown redacted.

What it checks

Checks

  • Key formats from Stripe, AWS, OpenAI, Anthropic, GitHub, GitLab, Slack, Google, SendGrid, Twilio, npm and Resend.

  • Supabase service_role keys, told apart from the public anon key.

  • Private keys, database URLs with a password, and JSON Web Tokens.

Doesn’t check

  • Whether a key is live. A match only looks like a key.

  • Secrets with no recognizable shape, such as passwords.

  • Your repository's history, where a removed key still lives.

Questions

Is my text uploaded?

No. The check runs in this page's JavaScript; nothing you paste leaves your browser. Matches are shown redacted.

I found a key. What now?

Rotate it with the provider first, since anyone who saw it may have copied it. Then move it to an environment variable or a secrets manager, and remove it from your Git history.

Why was a key I know about not flagged?

It may have no prefix or fixed shape to recognize. The checker reports only formats it can match with confidence.

Check a whole repository,
free.