Your country

Tools that support it use your country for local currency, number formats, units and paper size. Your choice is saved only in this browser.

Type a name or a two-letter code. Use the up and down arrow keys to move through the countries, Enter to choose one and Escape to close.

Secret & Credential Leak Scanner

Find leaked keys, tokens and passwords in code and logs before someone else does.

Security No upload Works offline Free, no sign-up

Scanned on your device as you type — nothing is uploaded.

Options

Detection rules: the default rule set of gitleaks 8.30.1 by Zachary Rice and contributors, ported to JavaScript and used under the MIT licence.

What was found

Paste text or open files. Findings appear here with their line, what kind of credential it is and how to rotate it.

Next steps

About the Secret & Credential Leak Scanner

Credentials end up where they should not: a .env file pasted into a chat, an access key printed in a CI log, a token hard-coded “just for testing”. This scanner reads code, config files and logs and points out exposed credentials — cloud access keys, GitHub, GitLab, Slack and Stripe tokens, private-key blocks, JSON Web Tokens, passwords inside database URLs and random-looking values assigned to fields named password, secret or token — with the line and column of each, a masked preview and what to do next.

Detection uses the rule set of gitleaks, the open-source secret scanner (MIT licence): all 222 rules of its 8.30.1 release, ported to run in your browser with their keywords, entropy thresholds and allowlists. Tests check that the port reports the same findings as the gitleaks 8.30.1 program on hundreds of sample files. Two extra checks come on top: passwords in connection URLs and, if you ask, random-looking quoted strings. Nothing you paste or open leaves your device.

How to use it

  1. Paste the text — source code, a .env or config file, a log — or press Open files to scan several files at once (you can also drop them on the page).
  2. Read the findings: each shows the kind of credential, its line and column, and the line it sits on with the secret masked. Tick Show secret values to see them in full.
  3. Open What to do on a finding for rotation steps and, for the big providers, a link to their own instructions.
  4. Copy or download the redacted copy before you share the text, and export the findings as CSV or JSON for a ticket.

Examples

An AWS key pair in a .env file
Input
AWS_ACCESS_KEY_ID=AKIA… (20 characters)
AWS_SECRET_ACCESS_KEY=… (40 random characters)
Result
Secret — AWS access key ID (line 1)
Likely secret — Secret assigned to a key, token or password field (line 2)

The access key ID has a fixed format; the secret access key is caught by gitleaks’ generic rule because it is a random value assigned to a field named “…KEY”.

Placeholders are left alone
Input
DB_PASSWORD=changeme
SMTP_PASSWORD=${SMTP_PASSWORD}
DOCS_KEY=AKIAIOSFODNN7EXAMPLE
Result
No secrets found

Template variables, short placeholder words and the example key from AWS’s documentation are on gitleaks’ allowlists.

A database URL
Input
DATABASE_URL=postgres://billing:Vq7rT2mK9xLw@db.example.com:5432/billing
Result
Secret — Database password in a connection URL (line 1, column 33)

Common uses

  • Checking a log, stack trace or config snippet before pasting it into a ticket, a forum or an AI chat.
  • Reviewing a pull request or a file someone sent you for hard-coded keys.
  • Cleaning a .env file or deployment notes before sharing them with a contractor.
  • Finding which line of a long CI log printed a token, and getting a redacted copy to attach instead.

What it finds

  • Cloud and platform keys: AWS access key IDs (AKIA…, ASIA…), Google API keys (AIza…), Microsoft Entra ID client secrets, Alibaba, DigitalOcean, Heroku, Fly.io and more.
  • Code hosting and CI tokens: GitHub tokens (ghp_, gho_, ghu_, ghs_, ghr_, github_pat_ — prefixes GitHub introduced to make leaks detectable), GitLab tokens (glpat- and others), npm and PyPI publish tokens.
  • Messaging, payments and AI services: Slack bot and user tokens and webhook URLs, Stripe secret and restricted keys, Twilio, SendGrid, OpenAI, Anthropic and Hugging Face keys, and about 150 other services.
  • Keys and tokens of any origin: private-key blocks (-----BEGIN … PRIVATE KEY-----), JSON Web Tokens (their header and claims are decoded, nothing is verified), passwords in curl -u commands and Authorization headers.
  • Configuration files, by file name: Kubernetes Secret YAML, Terraform passwords, NuGet config passwords, and .p12/.pfx key stores.
  • Generic secrets: random-looking values assigned to names containing key, token, secret, password, auth or credential.

How a match becomes a finding

Each rule has keywords, a pattern and often a minimum randomness (Shannon entropy, in bits per character). A rule runs only when the text contains one of its keywords; a match is dropped when its secret is not random enough, when the line contains gitleaks:allow, or when an allowlist covers it — template variables such as ${VAR} and {{ secrets.X }}, the example key from AWS’s documentation, words like true or null, and generated files such as package-lock.json. When a specific rule and the generic one find the same secret, the specific one wins. Rules tied to a file type run on opened files by their name, as in gitleaks.

The two extra checks, which gitleaks does not have, are marked as such: passwords in connection URLs (postgres://user:password@host, also MySQL, MongoDB, Redis and others; placeholders are skipped) and, when you tick it, random-looking quoted strings with the default thresholds of Yelp’s detect-secrets (more than 4.5 bits per character for Base64-like text, 3.0 for hex). The second check also flags hashes and IDs, so its results are labelled “possible secret”.

When a secret has leaked

Deleting the line does not undo a leak: anyone who saw the text, and every system that logged it, may still have the value. The OWASP Secrets Management Cheat Sheet recommends treating it as compromised:

  • Revoke or rotate it at the provider first, then deploy the replacement.
  • Limit the replacement to the permissions it needs, and load it from an environment variable or a secrets manager instead of code.
  • Check the provider’s logs for use you do not recognise since the leak.
  • Clean the history if it was committed: the old value stays in every clone. GitHub explains how to remove sensitive data from a repository — after rotating, not instead of it.
  • Tell your security team if it was a work credential, even if you have already rotated it.

Limitations

  • Pattern matching finds known formats and obvious assignments. A password written in a sentence (“the password is tiger7”), a secret split over several lines or an unusual in-house format can slip through: a clean result is not proof.
  • It does not know whether a key still works — it never contacts the provider — so expired and revoked keys are reported too.
  • Base64- or URL-encoded secrets are not decoded first (gitleaks can do this with its decode option).
  • Binary files are skipped (except .p12/.pfx key stores, which are flagged by name), each file can be up to 20 MB and all files together 60 MB. Extract archives before scanning them.

Privacy

Everything happens in your browser. What you enter or open here is not uploaded or stored by MySmartCoPilot.

Frequently asked questions

Is it safe to paste a real secret here?

The scan runs in your browser, in a background worker: the text and files are never uploaded or stored, and the page makes no network request with them. Still, a secret that was pasted into a chat, a ticket or a log should be rotated anyway — the scanner only tells you where it is.

How is this different from running gitleaks?

The rules are the same, ported from gitleaks 8.30.1. gitleaks itself scans Git history (every commit) and whole directories, and belongs in your CI pipeline or a pre-commit hook. This page is for the text in front of you: a paste, a log, a handful of files — without installing anything.

What do “Secret”, “Likely secret” and “Possible secret” mean?

Secret: a credential with a recognisable format, such as a GitHub token or a private key. Likely secret: a random value assigned to a key, token or password field (gitleaks’ generic rule), or an identifier such as a client ID that is usually stored next to a secret. Possible secret: a random-looking quoted string (the optional check) — often a real key, but sometimes a hash or an ID.

Why was a key in my file not found?

Either its format is not one the rules know, it is not random enough to pass the rule’s entropy threshold, or an allowlist matched it (for example a value that looks like ${VARIABLE}). Tick the random-looking strings check to cast a wider net, and if a common format is missing, the gitleaks project accepts new rules.

How do I stop a test value from being reported?

As in gitleaks, add the comment gitleaks:allow to the line. Better still, make test values obviously fake (all x’s or a template variable) so that no scanner mistakes them for real ones.

Does it decode JSON Web Tokens?

It shows a JWT’s algorithm and claims such as sub, iss and exp, and whether it has expired, without checking the signature. For a full view use the JWT Decoder.

Quick answers and tool search

Type to search tools or to get a quick answer, for example 18% of 2500. Use the up and down arrow keys to move through the results, Enter to choose, and Escape to close.