# Secret scanner — find leaked credentials, no upload

> Scan code, config, or logs for exposed API keys, tokens, and credentials in your browser. Nothing is uploaded — the text stays in the tab.

Scan pasted code, config, or logs for exposed secrets — API keys, tokens, private keys, and credentials — using pattern detection. It runs in the browser, so the very secrets you're checking never leave the tab.

Leaked credentials are among the most common and damaging mistakes — a key in a commit, a token in a log. Scanning text before you share or commit it catches those exposures while the secret is still in your hands.

Crucially, the scan is local, so you're not transmitting the very secrets you're worried about. Diff env files with the .env manager and scrub HAR captures with the HAR viewer.

## How to

1. **Paste text.** Paste the code, config, or log to scan.
2. **Scan.** Known secret patterns are flagged with their type.
3. **Remediate.** Rotate and remove any exposed credentials found.

## FAQ

### What kinds of secrets can it find?

Common patterns like cloud API keys, tokens, private keys, and connection strings — the credentials that most often get committed or logged by accident.

### If it's clean, am I safe?

It catches known patterns, so a clean result is reassuring but not a guarantee. Still, it's a fast pre-commit or pre-share check.

### Is my text uploaded to scan it?

No. Scanning runs in the browser, which is essential — sending suspected secrets to a server would defeat the purpose.


## Related tools

- [.env manager & diff](https://www.safepaper.app/dev/env-manager)
- [HAR viewer + scrub](https://www.safepaper.app/dev/har-viewer)
- [K8s secret decode](https://www.safepaper.app/dev/k8s-secret)
- [AES file encrypt](https://www.safepaper.app/security/file-encrypt)

---

Canonical HTML: https://www.safepaper.app/dev/secret-scanner
Markdown: https://www.safepaper.app/dev/secret-scanner.md

There is no upload endpoint — your files are processed in this browser tab. Open your network tab and check.
