Skip to main content
QUIETLYTIC
Cybersecurity

Secret Pattern Detector

Scan pasted text or code for the shape of a leaked API key, token or private key.

Local · nothing leaves this browser Waiting for text to scan
Esc Clear
Findings

Paste text on the left.

How it works

Scans pasted text for the shape of common credential formats — AWS access keys, GitHub tokens, Stripe keys, Slack tokens, PEM private key headers, JWTs and a handful of other provider-specific patterns — before they ship in a commit, a log line, or a support ticket.

Pattern matching, not validation

This cannot tell a live key from a revoked, rotated, or entirely fabricated one — it flags text that looks like a real secret. Every match needs a human decision; the tool only narrows down where to look. A secret that does not match a known provider format will not be flagged.

Nothing here is transmitted

The scan runs entirely in this browser tab. Matches are shown redacted — only the first and last four characters — so a screenshot of the results does not itself become a way the secret leaks.

Example

If a scan finds a real match, treat the credential as compromised, not just exposed: rotate it at the provider immediately, and if it reached a git history, remove it from every ref with a history-rewriting tool — a leaked key sitting unrotated in history is still live regardless of whether the branch is public.

Frequently asked questions

Why is the match shown redacted instead of in full?

So a screenshot of the results, or a second person looking over your shoulder, does not itself become a way the secret leaks. Only the first and last four characters are shown — enough to identify which credential it is without exposing enough to use it.

It found a match — what should I actually do?

Treat any real match as compromised, not just exposed: rotate the credential at the provider immediately, and if it went into a git history, remove it from every ref (not just the latest commit) with a history-rewriting tool, since a leaked key sitting unrotated in history is still live regardless of whether the branch is public.

Does it check for exposed personal data, not just credentials?

No — this tool is scoped to credential and secret patterns specifically. Checking pasted content for personal data (names, emails, government IDs) is a different detection problem with different false-positive tradeoffs and is not what this tool does.

Related tools

From the intelligence desk