What this tool covers
Scan pasted code for patterns resembling exposed API keys, tokens, private keys and credentials. The result is based only on the source and settings supplied for the current run.
Scan pasted code for patterns resembling exposed API keys, tokens, private keys and credentials.
Privacy: Your input is processed in the browser where supported and is not intentionally stored by this tool.
Scan pasted code for patterns resembling exposed API keys, tokens, private keys and credentials. The result is based only on the source and settings supplied for the current run.
Start with a representative input, inspect the first output, and change one option at a time. Copy or download the result only after checking it against the source.
Pattern matching can miss secrets or flag examples; rotate any credential that was genuinely exposed.
Use Code Secret Scanner when you need a focused result without installing a separate desktop application. Scan pasted code for patterns resembling exposed API keys, tokens, private keys and credentials. The result changes when the source data or selected options change, so it is easy to run a second comparison.
A practical way to use it is to inspect a small representative sample before applying the same change in a production workflow. Start with a representative input, inspect the first result, then adjust one setting at a time if you need a different outcome.
Processing stays in the browser where the individual feature supports it. Live public checks use a protected, rate-limited site endpoint; avoid unnecessary sensitive data.
The code, structured data, expression, token, or sample value requested by the interface.
A transformed, generated, or diagnostic result for the submitted technical input.
Format, validate, minify, and copy JSON.
FormatEncode and decode Base64 text instantly.
EncodeDecode JWT header and payload safely.
DecodeEncode and decode URLs or query strings.
EncodeGenerate random UUID v4 values.
GenerateThe code, structured data, expression, token, or sample value requested by the interface.
Choose only the settings that apply to the result you need; leave optional controls unchanged when you are unsure.
Start the task and wait for the interface to return its result or a clear setup message.
Test the result in a non-production environment. Never paste passwords, private keys, live access tokens or confidential production data.
The code, structured data, expression, token, or sample value requested by the interface. Start with a representative input and use only the options needed for your intended result.
A transformed, generated, or diagnostic result for the submitted technical input. Check the result against the original input before using it in a live or important workflow.
Test the result in a non-production environment. Never paste passwords, private keys, live access tokens or confidential production data.
Processing stays in the browser where the individual feature supports it. Live public checks use a protected, rate-limited site endpoint; avoid unnecessary sensitive data.
The page can be used without creating a visitor account. Your browser or device may limit unusually large files or demanding media jobs.