Skip to content
We use cookies to improve the site and measure traffic. See our Cookie Policy. You can accept or reject non-essential cookies.
  • Free
  • No signup
  • Fast
  • Privacy-friendly

Back to Category

Secret Leak Scanner

Heuristic scan of pasted env/config/log text for API keys, tokens, PEM keys, and JWTs.

Waiting for bot check… this usually takes a second.

What next?

Keep going with Secret Leak Scanner

Finish this check in the browser, then pick the path that matches how you work — another related tool, REST for apps, or MCP for agents.

  1. 1. Related check

    After this result, run JWT decoder for the next signal.

    JWT decoder
  2. 2. Automate with API

    Same job from your server with X-Api-Key. Free tier includes 500 credits/month.

    Create free account
  3. 3. Hand off to an agent

    Connect Cursor or Claude to ToolYour MCP — plan → run → verify.

    MCP setup

What is Secret Leak Scanner?

Pattern scan for leaked credentials in pasted env, config, or log text. Scrub PII first with AI PII Scrubber when needed. Follow up JWT hits with JWT Decoder. Agents use secrets-and-auth-hygiene playbooks, then verify until remaining leak findings clear — see <a href="/developers/security-audit">security audit</a>.

What are common questions about Secret Leak Scanner?

What does Secret Leak Scanner do?

Heuristic scan of pasted env/config/log text for API keys, tokens, PEM keys, and JWTs.

Is this available via API and MCP?

Yes. Same route under /api/v1/security-apis/{slug} with one ToolYour API key.

What are the key features of Secret Leak Scanner?

Common secret shapes

AWS, GitHub, Slack, Stripe, Google API keys, PEM, JWTs, and secret assignments.

Redacted previews

Results show truncated matches, not full secrets.

How do you use Secret Leak Scanner?

Paste text

Drop env, config, or log snippets into the scanner.

Rotate hits

Treat high-severity matches as compromised until proven otherwise.
Free · API · MCPToolYour platform

Use Secret Leak Scanner three ways

The free Secret Leak Scanner on this page works in your browser. The same workflow is available via REST API for apps and via the remote MCP server for Cursor, Claude, and other agents — one API key, one plan, one quota. This tool is part of the security-apis module under Security Tools.

  1. 1Create a free accountGet an API key for REST and MCP — 500 credits/month on the free tier.
  2. 2Connect or callPaste the MCP URL into Cursor/Claude, or call REST with X-Api-Key.
  3. 3Same key & creditsBrowser smoke-checks stay free; API-backed runs share one monthly credit quota.

Which secrets & auth tools sit in this cluster?

Where does this job fit on ToolYour?

Which SEO or privacy tools pair with this security check?

Where do you browse more security tools tools?

Which toolkits include Secret Leak Scanner?