Paste code below to scan for leaked secrets. Nothing is sent to any server — all scanning happens in your browser.
What to paste here
.js, .ts, .py, .go, etc. — that may contain hardcoded credentials.env, config.json, settings.py, application.yml.github/workflows/*.yml, Dockerfile, docker-compose.ymlterraform.tfvars, *.tf, Helm values filesDetects AWS keys, GitHub tokens, Stripe keys, Supabase JWTs, database URLs, private key blocks, and 150+ other patterns. All scanning runs locally in your browser.