Skip to content
(347) 262-9435

Free tool · No sign-up

Secret & .env Scanner

Paste a code snippet, a config file, or a whole .env and it flags anything that looks like a live credential: AWS keys, Stripe and OpenAI keys, Supabase service_role tokens, private key blocks, database URLs with passwords in them, and generic high-entropy strings. Runs entirely in the browser, so the secret you are checking never leaves the tab.

Paste anything you are about to commit or share. It is scanned in your browser and never uploaded.

Method & assumptions
  • Detection is by known key formats plus a high-entropy check on secret-named fields. It finds the common leaks, not every possible one.
  • Matched values are masked before display — the tool tells you a secret is present without reprinting it in full.
  • A test-mode or publishable key is flagged more gently than a live one, but still belongs in an environment variable.
  • Everything runs in your browser. Nothing you paste is uploaded, logged, or stored.

Software engineering

We write the software
behind tools like these

Anyone about to commit, paste into an issue, or share a config and wanting a last look first.

Or call and speak to someone who does the work(347) 262-9435inquiries@jcitsystems.com
  • Free diagnostics
  • Same-day across most of the metro
  • Named technicians
  • No fix, no labour charge