API Key Detector

Scan code and config files for accidentally exposed API keys. Detects 15+ providers including OpenAI, AWS, GitHub, Stripe. 100% local — no data sent anywhere.

Code / Config Input

All scanning is performed locally in your browser. No data is sent to any server.

This tool uses pattern matching and may produce false positives. Always review results manually.

What the API key detector does

Paste code or a config file and this scanner flags anything that looks like a live secret — API keys, tokens, and credentials for 15+ providers including OpenAI, AWS, GitHub, and Stripe — using each provider's known key format. Crucially, it runs 100% in your browser: your code never leaves your machine, which is exactly what you want when the whole point is to find secrets.

How to scan for exposed keys

  1. Paste your code, .env, or config file.
  2. Review the flagged matches and which provider each belongs to.
  3. Remove the secret from the file and rotate it if it was ever committed.

Why exposed keys are so dangerous

A committed API key is one of the fastest ways to get breached — bots scan public GitHub within seconds of a push, and a leaked cloud key can run up a huge bill or exfiltrate data before you notice. Once a secret has been pushed anywhere, treat it as compromised: rotate it, don't just delete the line, because it lives forever in git history.

Frequently asked questions

Is my code sent anywhere?

No — the scan runs entirely in your browser. Nothing is uploaded.

What do I do if I find a live key?

Rotate it at the provider immediately, then remove it from the code and from git history (a deleted line is still in past commits).

Which providers does it detect?

15+, including OpenAI, AWS, GitHub, Stripe, Google, and other common formats.

SharePost

More tools like this