Secret Scanner
Scan pasted code or text for likely leaked secrets.
About the Secret Scanner
Scan pasted code, .env contents, or logs for patterns matching AWS keys, private keys, GitHub/Slack/Stripe tokens, JWTs, and generic high-entropy strings. Findings show the line number and a masked preview so nothing sensitive is fully exposed on screen.
Examples
Leaked AWS key
AKIAIOSFODNN7EXAMPLEOutput
AWS Access Key ID found on line 1Keyboard shortcuts
- Copy the main outputCtrl / ⌘ + Shift + C
- Download the resultCtrl / ⌘ + S
- Share this toolCtrl / ⌘ + Shift + S
- Reset the inputsAlt + R
- Open the tool search paletteCtrl / ⌘ + K
Related tools
SSH Key Fingerprint Formatter
Security
Parse an OpenSSH public key and show its SHA256/MD5 fingerprints.
SSL Certificate Checker
Security
Inspect the live certificate a domain serves, with expiry and chain details.
SSL CSR/Certificate Decoder
Security
Decode a PEM CSR or certificate into its ASN.1 structure.
Password Strength Checker
Security
Estimate password entropy, crack time, and get actionable advice.
CORS Config Generator
Security
Generate CORS headers/config for Nginx, Apache, Express, or Workers.
CSP Builder
Security
Build a Content-Security-Policy header from per-directive sources.
Frequently asked questions
Read more
- How to explore, edit and map a source project in your browser
A practical guide to opening a source archive, tracing dependencies, inspecting syntax trees and exporting edited files without uploading a repository.
- How TOTP two-factor codes actually work (and why 30 seconds matters)
A six-digit code every half minute, no network required. Here is what HMAC-SHA1, a shared secret and the Unix timestamp are actually doing.
Version 1.0.0 · Updated 2026-08-06 · Runs entirely in your browser