Secret & Credential Leak Scanner
Find leaked keys, tokens and passwords in code and logs before someone else does.
Scanned on your device as you type — nothing is uploaded.
Detection rules: the default rule set of gitleaks 8.30.1 by Zachary Rice and contributors, ported to JavaScript and used under the MIT licence.
What was found
Paste text or open files. Findings appear here with their line, what kind of credential it is and how to rotate it.
Redacted copy of the pasted text
Redacting a copy does not make a leaked secret safe again: rotate it as well.
About the Secret & Credential Leak Scanner
Credentials end up where they should not: a .env file pasted into a chat, an access key printed in a CI log, a token hard-coded “just for testing”. This scanner reads code, config files and logs and points out exposed credentials — cloud access keys, GitHub, GitLab, Slack and Stripe tokens, private-key blocks, JSON Web Tokens, passwords inside database URLs and random-looking values assigned to fields named password, secret or token — with the line and column of each, a masked preview and what to do next.
Detection uses the rule set of gitleaks, the open-source secret scanner (MIT licence): all 222 rules of its 8.30.1 release, ported to run in your browser with their keywords, entropy thresholds and allowlists. Tests check that the port reports the same findings as the gitleaks 8.30.1 program on hundreds of sample files. Two extra checks come on top: passwords in connection URLs and, if you ask, random-looking quoted strings. Nothing you paste or open leaves your device.
How to use it
- Paste the text — source code, a
.envor config file, a log — or press Open files to scan several files at once (you can also drop them on the page). - Read the findings: each shows the kind of credential, its line and column, and the line it sits on with the secret masked. Tick Show secret values to see them in full.
- Open What to do on a finding for rotation steps and, for the big providers, a link to their own instructions.
- Copy or download the redacted copy before you share the text, and export the findings as CSV or JSON for a ticket.
Examples
AWS_ACCESS_KEY_ID=AKIA… (20 characters) AWS_SECRET_ACCESS_KEY=… (40 random characters)
Secret — AWS access key ID (line 1) Likely secret — Secret assigned to a key, token or password field (line 2)
The access key ID has a fixed format; the secret access key is caught by gitleaks’ generic rule because it is a random value assigned to a field named “…KEY”.
DB_PASSWORD=changeme
SMTP_PASSWORD=${SMTP_PASSWORD}
DOCS_KEY=AKIAIOSFODNN7EXAMPLENo secrets found
Template variables, short placeholder words and the example key from AWS’s documentation are on gitleaks’ allowlists.
DATABASE_URL=postgres://billing:Vq7rT2mK9xLw@db.example.com:5432/billing
Secret — Database password in a connection URL (line 1, column 33)
Common uses
- Checking a log, stack trace or config snippet before pasting it into a ticket, a forum or an AI chat.
- Reviewing a pull request or a file someone sent you for hard-coded keys.
- Cleaning a
.envfile or deployment notes before sharing them with a contractor. - Finding which line of a long CI log printed a token, and getting a redacted copy to attach instead.
What it finds
- Cloud and platform keys: AWS access key IDs (
AKIA…,ASIA…), Google API keys (AIza…), Microsoft Entra ID client secrets, Alibaba, DigitalOcean, Heroku, Fly.io and more. - Code hosting and CI tokens: GitHub tokens (
ghp_,gho_,ghu_,ghs_,ghr_,github_pat_— prefixes GitHub introduced to make leaks detectable), GitLab tokens (glpat-and others), npm and PyPI publish tokens. - Messaging, payments and AI services: Slack bot and user tokens and webhook URLs, Stripe secret and restricted keys, Twilio, SendGrid, OpenAI, Anthropic and Hugging Face keys, and about 150 other services.
- Keys and tokens of any origin: private-key blocks (
-----BEGIN … PRIVATE KEY-----), JSON Web Tokens (their header and claims are decoded, nothing is verified), passwords incurl -ucommands and Authorization headers. - Configuration files, by file name: Kubernetes Secret YAML, Terraform passwords, NuGet config passwords, and
.p12/.pfxkey stores. - Generic secrets: random-looking values assigned to names containing key, token, secret, password, auth or credential.
How a match becomes a finding
Each rule has keywords, a pattern and often a minimum randomness (Shannon entropy, in bits per character). A rule runs only when the text contains one of its keywords; a match is dropped when its secret is not random enough, when the line contains gitleaks:allow, or when an allowlist covers it — template variables such as ${VAR} and {{ secrets.X }}, the example key from AWS’s documentation, words like true or null, and generated files such as package-lock.json. When a specific rule and the generic one find the same secret, the specific one wins. Rules tied to a file type run on opened files by their name, as in gitleaks.
The two extra checks, which gitleaks does not have, are marked as such: passwords in connection URLs (postgres://user:password@host, also MySQL, MongoDB, Redis and others; placeholders are skipped) and, when you tick it, random-looking quoted strings with the default thresholds of Yelp’s detect-secrets (more than 4.5 bits per character for Base64-like text, 3.0 for hex). The second check also flags hashes and IDs, so its results are labelled “possible secret”.
When a secret has leaked
Deleting the line does not undo a leak: anyone who saw the text, and every system that logged it, may still have the value. The OWASP Secrets Management Cheat Sheet recommends treating it as compromised:
- Revoke or rotate it at the provider first, then deploy the replacement.
- Limit the replacement to the permissions it needs, and load it from an environment variable or a secrets manager instead of code.
- Check the provider’s logs for use you do not recognise since the leak.
- Clean the history if it was committed: the old value stays in every clone. GitHub explains how to remove sensitive data from a repository — after rotating, not instead of it.
- Tell your security team if it was a work credential, even if you have already rotated it.
Limitations
- Pattern matching finds known formats and obvious assignments. A password written in a sentence (“the password is tiger7”), a secret split over several lines or an unusual in-house format can slip through: a clean result is not proof.
- It does not know whether a key still works — it never contacts the provider — so expired and revoked keys are reported too.
- Base64- or URL-encoded secrets are not decoded first (gitleaks can do this with its decode option).
- Binary files are skipped (except .p12/.pfx key stores, which are flagged by name), each file can be up to 20 MB and all files together 60 MB. Extract archives before scanning them.
Privacy
Everything happens in your browser. What you enter or open here is not uploaded or stored by MySmartCoPilot.
Frequently asked questions
Is it safe to paste a real secret here?
The scan runs in your browser, in a background worker: the text and files are never uploaded or stored, and the page makes no network request with them. Still, a secret that was pasted into a chat, a ticket or a log should be rotated anyway — the scanner only tells you where it is.
How is this different from running gitleaks?
The rules are the same, ported from gitleaks 8.30.1. gitleaks itself scans Git history (every commit) and whole directories, and belongs in your CI pipeline or a pre-commit hook. This page is for the text in front of you: a paste, a log, a handful of files — without installing anything.
What do “Secret”, “Likely secret” and “Possible secret” mean?
Secret: a credential with a recognisable format, such as a GitHub token or a private key. Likely secret: a random value assigned to a key, token or password field (gitleaks’ generic rule), or an identifier such as a client ID that is usually stored next to a secret. Possible secret: a random-looking quoted string (the optional check) — often a real key, but sometimes a hash or an ID.
Why was a key in my file not found?
Either its format is not one the rules know, it is not random enough to pass the rule’s entropy threshold, or an allowlist matched it (for example a value that looks like ${VARIABLE}). Tick the random-looking strings check to cast a wider net, and if a common format is missing, the gitleaks project accepts new rules.
How do I stop a test value from being reported?
As in gitleaks, add the comment gitleaks:allow to the line. Better still, make test values obviously fake (all x’s or a template variable) so that no scanner mistakes them for real ones.
Does it decode JSON Web Tokens?
It shows a JWT’s algorithm and claims such as sub, iss and exp, and whether it has expired, without checking the signature. For a full view use the JWT Decoder.