Secret Scanner
Find keys, tokens, and passwords in any text, and copy it with them redacted.
Your data stays in your browser
Advertisement
Text to scan
.log, .txt, .env, .json, .yaml, or any text file, up to 10.0 MB. Or drop a file on the text area. Files are read in your browser.
Paste text or open a file
Long values that look random, with no known format or telling name. Off by default: IDs and hashes look random too.
Secrets
No resultPaste logs, a config, or code in Text to scan, or open a file. Secret Scanner finds keys, tokens, and passwords, and redacts them.
Advertisement
Example
Default settings: 3 possible secrets, all redacted
Input
DB_PASSWORD=Winter2026! GET /api/orders Authorization: Bearer abcDEF123ghiJKL456mnoPQR789 DATABASE_URL=postgres://app:s3cr3t-pass@db.internal/app
Output
DB_PASSWORD=[REDACTED] GET /api/orders Authorization: Bearer [REDACTED] DATABASE_URL=postgres://app:[REDACTED]@db.internal/app
How it works
- Finds private keys, JWTs, Bearer and Basic credentials, passwords in URLs and connection strings, cookies, and known key formats, such as cloud access keys and source-hosting tokens.
- Finds values whose name says they are secret, such as
DB_PASSWORD=,"apiKey":, orX-Api-Key:, in .env files, YAML, JSON, headers, query strings, and code. Empty values, numbers, and placeholders such as${DB_PASSWORD}are skipped. - Values stay masked on screen until you reveal one. Mark a value Not a secret to keep it: it is kept everywhere it appears.
- Copy or download the text with every secret replaced by
[REDACTED]and everything else exactly as written. Paste text or open a file: nothing is uploaded.