How to Use .env Secret Scanner
Paste any code, .env file, config or log and this tool scans it for exposed secrets — AWS keys, Google & Stripe keys, GitHub tokens, JWTs, private keys and generic credential assignments — before you commit or share it. Everything is scanned locally in your browser and nothing is uploaded.
Open the .env Secret Scanner tool →What is .env Secret Scanner?
Scan code, .env files or logs for accidentally exposed API keys, tokens and credentials. It's completely free, needs no sign-up, and runs entirely in your browser — so it's fast and private.
How to use .env Secret Scanner
- Open the .env Secret Scanner tool.
- Paste or type your input.
- Set any options provided.
- Copy the result. Everything runs in your browser — nothing is uploaded.
Frequently asked questions
What secrets does it detect?
AWS keys, Google and Stripe keys, GitHub tokens, Slack/SendGrid/Twilio tokens, JWTs, private-key blocks, and generic api_key/secret/password/token assignments.
Is my code uploaded?
No — the scan runs entirely in your browser. If it finds a real secret, rotate it, since it may already be exposed elsewhere.
Does 'no secrets found' mean I'm safe?
Not guaranteed — it catches common patterns, but always review anything before making it public.
Ready to try it?
Open .env Secret Scanner →