QuickMeld

Secret Scanner

Find keys, tokens, and passwords in any text, and copy it with them redacted.

Your data stays in your browser

Advertisement

Text to scan

.log, .txt, .env, .json, .yaml, or any text file, up to 10.0 MB. Or drop a file on the text area. Files are read in your browser.

Paste text or open a file

Long values that look random, with no known format or telling name. Off by default: IDs and hashes look random too.

Secrets

No result

Paste logs, a config, or code in Text to scan, or open a file. Secret Scanner finds keys, tokens, and passwords, and redacts them.

Advertisement

Example

Default settings: 3 possible secrets, all redacted

Input

DB_PASSWORD=Winter2026!
GET /api/orders Authorization: Bearer abcDEF123ghiJKL456mnoPQR789
DATABASE_URL=postgres://app:s3cr3t-pass@db.internal/app

Output

DB_PASSWORD=[REDACTED]
GET /api/orders Authorization: Bearer [REDACTED]
DATABASE_URL=postgres://app:[REDACTED]@db.internal/app

How it works

  • Finds private keys, JWTs, Bearer and Basic credentials, passwords in URLs and connection strings, cookies, and known key formats, such as cloud access keys and source-hosting tokens.
  • Finds values whose name says they are secret, such as DB_PASSWORD=, "apiKey":, or X-Api-Key:, in .env files, YAML, JSON, headers, query strings, and code. Empty values, numbers, and placeholders such as ${DB_PASSWORD} are skipped.
  • Values stay masked on screen until you reveal one. Mark a value Not a secret to keep it: it is kept everywhere it appears.
  • Copy or download the text with every secret replaced by [REDACTED] and everything else exactly as written. Paste text or open a file: nothing is uploaded.