Security
Scan code, config or logs for leaked API keys, tokens, private keys and database passwords before you commit or share them.
Runs entirely in your browser, nothing is uploadedThe rules are regular expressions compiled in this tab. Nothing is uploaded, so there is no request to inspect and nothing to log.
Most rules key on a prefix the provider publishes — AKIA for AWS, ghp_ for GitHub, sk_live_ for Stripe. A prefix identifies both the vendor and the credential type, which is what makes a finding worth acting on.
Two rules have no prefix to rely on and match assignments to names like api_key or a Bearer header. Those are only reported if the value is also high-entropy, which is how a real key gets through and password = "changeme" does not.
Decode a JSON Web Token’s header and payload, and verify an HS256 signature with a secret.
Open toolGuess what algorithm produced a given hash, based on its length and format.
Open toolCheck how crackable a password really is, based on known patterns and dictionaries, not just character-type rules.
Open tool