Free tool · No sign-up
Secret & .env Scanner
Paste a code snippet, a config file, or a whole .env and it flags anything that looks like a live credential: AWS keys, Stripe and OpenAI keys, Supabase service_role tokens, private key blocks, database URLs with passwords in them, and generic high-entropy strings. Runs entirely in the browser, so the secret you are checking never leaves the tab.
Paste anything you are about to commit or share. It is scanned in your browser and never uploaded.
Method & assumptions
- Detection is by known key formats plus a high-entropy check on secret-named fields. It finds the common leaks, not every possible one.
- Matched values are masked before display — the tool tells you a secret is present without reprinting it in full.
- A test-mode or publishable key is flagged more gently than a live one, but still belongs in an environment variable.
- Everything runs in your browser. Nothing you paste is uploaded, logged, or stored.
Other tools
More on the bench
- 01
Supabase Security Auditor
Point it at your project, find the holes. - 02
JWT Decoder
Paste a token, read what is inside. - 03
Security Headers Scanner
Enter a URL, grade its headers. - 04
CORS Tester
See exactly what a URL allows cross-origin. - 05
Base64 Encode / Decode
Text or files, both directions. - 06
URL Encode / Decode
Percent-encoding, both directions. - 07
JSON Formatter
Validate, pretty-print, or minify. - 08
UUID Generator
v4 and v7, one or a thousand.
Software engineering
We write the software
behind tools like these
Anyone about to commit, paste into an issue, or share a config and wanting a last look first.
- Free diagnostics
- Same-day across most of the metro
- Named technicians
- No fix, no labour charge