Secret Pattern Detector
Scan pasted text or code for the shape of a leaked API key, token or private key.
Paste text on the left.
How it works
Scans pasted text for the shape of common credential formats — AWS access keys, GitHub tokens, Stripe keys, Slack tokens, PEM private key headers, JWTs and a handful of other provider-specific patterns — before they ship in a commit, a log line, or a support ticket.
Pattern matching, not validation
This cannot tell a live key from a revoked, rotated, or entirely fabricated one — it flags text that looks like a real secret. Every match needs a human decision; the tool only narrows down where to look. A secret that does not match a known provider format will not be flagged.
Nothing here is transmitted
The scan runs entirely in this browser tab. Matches are shown redacted — only the first and last four characters — so a screenshot of the results does not itself become a way the secret leaks.
Example
If a scan finds a real match, treat the credential as compromised, not just exposed: rotate it at the provider immediately, and if it reached a git history, remove it from every ref with a history-rewriting tool — a leaked key sitting unrotated in history is still live regardless of whether the branch is public.
Frequently asked questions
Why is the match shown redacted instead of in full?
So a screenshot of the results, or a second person looking over your shoulder, does not itself become a way the secret leaks. Only the first and last four characters are shown — enough to identify which credential it is without exposing enough to use it.
It found a match — what should I actually do?
Treat any real match as compromised, not just exposed: rotate the credential at the provider immediately, and if it went into a git history, remove it from every ref (not just the latest commit) with a history-rewriting tool, since a leaked key sitting unrotated in history is still live regardless of whether the branch is public.
Does it check for exposed personal data, not just credentials?
No — this tool is scoped to credential and secret patterns specifically. Checking pasted content for personal data (names, emails, government IDs) is a different detection problem with different false-positive tradeoffs and is not what this tool does.
Related tools
IOC Extractor
Pull indicators of compromise out of any block of text, log or report.
LocalHash Identifier
Narrow an unlabelled hash down to the algorithms that could have produced it.
LocalSecurity Headers Analyzer
Review a set of pasted HTTP response headers against current guidance.
LocalPassword Entropy Checker
A charset-and-length entropy estimate, with the math and its limits shown, not a bare score.
LocalIOC Defanger
Neutralise indicators so they can be shared without becoming clickable.
LocalIOC Refanger
Restore defanged indicators to their original, machine-readable form.
Local