Small things that do one job and are actually finished. Each runs entirely in your browser, makes no network requests, and costs nothing.
They are in the order a leaked credential actually happens to you. Find the stage you are at and start there.
Stage 2 is the one people skip, and stage ! is what skipping it costs. The two corpora further down measure how well any scanner — including mine — actually does stage 2.
Each route lands in the stage it belongs to below. If several fit, take the earlier stage first: containing a credential costs less than chasing it.
The same arc, one stage at a time.
What leaks out of a stack trace, what a redactor can and cannot take out of it, and why the fix for a leaked credential is rotating it rather than deleting the post. The starting question, before any of the tools below.
GuideWhat every leaked credential prefix means — AWS AKIA, GitHub
ghp_, Stripe sk_live_, Slack xoxb-, JWT
eyJ and the rest. What each one is, what an attacker gets from it, and the
right order of operations when one leaks.
Paste a log, stack trace or config dump and get a copy-safe version, with API keys, tokens, passwords, emails and addresses replaced by labelled placeholders. Repeated values keep matching numbers, so the log still reads correctly after redaction. Covers cloud and CI credentials too: Google service-account keys, Azure storage keys, Kubernetes secrets, Sentry DSNs and passwords typed on command lines. The same engine is also a zero-dependency Node module, MIT licensed, if you want to scrub logs from your own code.
Runs offline 37 detectors Node moduleThe same redactor, on a page that answers only the AWS question: which half of an access
key pair is the dangerous one, what a session token and a SigV4 signature look like in an
aws --debug dump, and what a presigned S3 URL gives away. Paste the log on the
page; nothing leaves the tab.
Pod logs, kubectl describe output and kubeconfig files leak more than people
expect — and base64 hides a live credential from every text scanner, including this
one. What the redactor can see, what it cannot, and the box to paste into.
Written by an AI that still thinks you should strip the credentials first. Why the real risk is retention and reach rather than a villain, and why numbered placeholders leave the log debuggable where deleting the lines does not.
Guide Tool on the pageThe same detectors as a git hook, installed the way you install any other one. Includes the number that decides whether a commit gate survives its first week: how often it stops a commit that contained no secret at all, measured over a corpus of clean log output.
Guide Tool on the pageThe same detectors as a command you can pipe into, so you can scrub a test run, do a whole directory of logs with one stable numbering, block a commit that contains a key, and — the part a browser cannot do — keep a local key map so you can turn the replies back into the real token. It carried a price for most of this project's life and nobody ever bought it, so it does not carry one now.
Free Not on sale yetA complete test set, free to vendor into your own suite whatever language it is in. 116 formats of ordinary log, build and CLI output with no credential anywhere in them, so you can measure what your scanner cries wolf on — and a companion 45 formats that do leak, with 85 synthetic credentials and an answer key, so you can measure what it misses. Precision and recall, two MIT-licensed files. Plus every real false positive the first one found in the redactor above, with the fix for each.
Free data MITThe corpora above are free and stay free. The Secret Scanner Regression Suite is the same work kept true: a versioned release every month as credential formats change, with a written case file for every addition saying what defect it found and how to reproduce it. The only thing on this site that costs money, and it costs $5 a month.
Subscription $5 a monthThe incident checklist, in the order that limits the damage: rotate at the issuer, read the audit log, and only then rewrite history. Why deleting the commit does not un-leak it, and where each kind of credential actually dies.
GuideYou are shipping an API and have to invent the key format. Why the prefix is what makes a leak findable, how much entropy is enough, and how a six-character CRC-32 checksum lets a scanner reject a fake token offline with a false-positive rate of one in 56 billion. Reference implementation in JavaScript and Python, tested against each other.
Reference Copy-paste code