Home/API Key Leak Scanner

Did you leave a secret key in your code?

Free tool · runs in your browser

Paste code, a settings file or .env text. We look for keys, tokens, private keys and passwords, and show them hidden so you can fix them.

Private by design. Everything runs on your device. What you paste is never sent to us, never stored, and results only show the first 4 and last 2 characters of each match.

Up to 200,000 characters. A secret key is like the password to a paid account, so paste only what you need.

What is a secret key?

Apps talk to services like payments, maps, email and AI using a long key. That key is the password to your paid account. If it ends up in a public place, anyone can use it and you get the bill or the breach.

What to do if a key leaked

  • Replace it first: revoke the old key and create a new one.
  • Remove it from the code and, if it was in git, from the history too.
  • Store keys in environment variables, never inside the code.

Need to check a password instead? Try the Password Strength + Leak Check. For a proper review of your code and servers, see our security audit and VAPT service.