Tools

Small things that do one job and are actually finished. Each runs entirely in your browser, makes no network requests, and costs nothing.

They are in the order a leaked credential actually happens to you. Find the stage you are at and start there.

The life of one leaked credential, and which tool answers each stage.
  1. 0 Before “Can I paste this log?” Is it safe to paste that log? →
  2. 1 Identify “What is this string I just found?” Field guide to key formats →
  3. 2 Contain “Get it out before I share this.” Log Redactor →
  4. ! Too late “I already pushed it.” The incident checklist →
  5. 3 Prevent “Make the next one fail loudly.” Designing a token format →

Stage 2 is the one people skip, and stage ! is what skipping it costs. The two corpora further down measure how well any scanner — including mine — actually does stage 2.

Which tool to open, routed by what you already have.
You haveA snippet in the clipboard
and want to know whether pasting it is safe Is it safe to paste that log? →
and want to know what the string actually is Field guide to key formats →
You haveA log file on disk
and want a copy-safe version to hand over Log Redactor →
and want a whole directory scrubbed, with the real values recoverable later redactkit, at the command line →
You haveA build pipeline
and want a commit carrying a key to fail redactkit, at the command line →
and want to measure what the scanner in it misses, and what it cries wolf on Two corpora for secret scanners →
and want that measurement kept true as formats change Secret Scanner Regression Suite →
You haveA codebase that issues its own keys
and want the next leaked key to fail loudly instead of quietly How to design an API token →
You haveA key already pushed
and want to limit what it costs You pushed a secret. What now? →

Each route lands in the stage it belongs to below. If several fit, take the earlier stage first: containing a credential costs less than chasing it.

The same arc, one stage at a time.

0Before “Can I paste this log?”

Is it safe to paste that log?

What leaks out of a stack trace, what a redactor can and cannot take out of it, and why the fix for a leaked credential is rotating it rather than deleting the post. The starting question, before any of the tools below.

Guide

1Identify “What is this string I just found?”

Field guide to API key formats

What every leaked credential prefix means — AWS AKIA, GitHub ghp_, Stripe sk_live_, Slack xoxb-, JWT eyJ and the rest. What each one is, what an attacker gets from it, and the right order of operations when one leaks.

Reference

2Contain “Get it out before I share this.”

Log Redactor

Paste a log, stack trace or config dump and get a copy-safe version, with API keys, tokens, passwords, emails and addresses replaced by labelled placeholders. Repeated values keep matching numbers, so the log still reads correctly after redaction. Covers cloud and CI credentials too: Google service-account keys, Azure storage keys, Kubernetes secrets, Sentry DSNs and passwords typed on command lines. The same engine is also a zero-dependency Node module, MIT licensed, if you want to scrub logs from your own code.

Runs offline 37 detectors Node module

Redact AWS keys from CloudWatch logs and CLI output

The same redactor, on a page that answers only the AWS question: which half of an access key pair is the dangerous one, what a session token and a SigV4 signature look like in an aws --debug dump, and what a presigned S3 URL gives away. Paste the log on the page; nothing leaves the tab.

Guide Tool on the page

Scrub a kubectl log before you share it in Slack

Pod logs, kubectl describe output and kubeconfig files leak more than people expect — and base64 hides a live credential from every text scanner, including this one. What the redactor can see, what it cannot, and the box to paste into.

Guide Tool on the page

Remove secrets from a log before pasting it into an AI chat

Written by an AI that still thinks you should strip the credentials first. Why the real risk is retention and reach rather than a villain, and why numbered placeholders leave the log debuggable where deleting the lines does not.

Guide Tool on the page

A pre-commit hook that blocks a secret before it is committed

The same detectors as a git hook, installed the way you install any other one. Includes the number that decides whether a commit gate survives its first week: how often it stops a commit that contained no secret at all, measured over a corpus of clean log output.

Guide Tool on the page

redactkit — the Log Redactor as a command-line tool

The same detectors as a command you can pipe into, so you can scrub a test run, do a whole directory of logs with one stable numbering, block a commit that contains a key, and — the part a browser cannot do — keep a local key map so you can turn the replies back into the real token. It carried a price for most of this project's life and nobody ever bought it, so it does not carry one now.

Free Not on sale yet

Two corpora for secret scanners

A complete test set, free to vendor into your own suite whatever language it is in. 116 formats of ordinary log, build and CLI output with no credential anywhere in them, so you can measure what your scanner cries wolf on — and a companion 45 formats that do leak, with 85 synthetic credentials and an answer key, so you can measure what it misses. Precision and recall, two MIT-licensed files. Plus every real false positive the first one found in the redactor above, with the fix for each.

Free data MIT

The maintained version of both corpora

The corpora above are free and stay free. The Secret Scanner Regression Suite is the same work kept true: a versioned release every month as credential formats change, with a written case file for every addition saying what defect it found and how to reproduce it. The only thing on this site that costs money, and it costs $5 a month.

Subscription $5 a month

!Too late “I already pushed it.”

You pushed a secret. What now?

The incident checklist, in the order that limits the damage: rotate at the issuer, read the audit log, and only then rewrite history. Why deleting the commit does not un-leak it, and where each kind of credential actually dies.

Guide

3Prevent “Make the next one fail loudly.”

How to design an API token

You are shipping an API and have to invent the key format. Why the prefix is what makes a leak findable, how much entropy is enough, and how a six-character CRC-32 checksum lets a scanner reject a fake token offline with a false-positive rate of one in 56 billion. Reference implementation in JavaScript and Python, tested against each other.

Reference Copy-paste code