Runtime leak detector for modern web apps — finds exposed API keys, validates BaaS misconfigurations (Supabase/Firebase RLS), and catches secrets in JS bundles. Chrome extension + CLI.
-
Updated
Jun 14, 2026 - Python
Runtime leak detector for modern web apps — finds exposed API keys, validates BaaS misconfigurations (Supabase/Firebase RLS), and catches secrets in JS bundles. Chrome extension + CLI.
CLI tool to scan local codebases and public GitHub repos for leaked API keys and secrets, including git history
Detect, inspect, and govern AI service usage across your infrastructure.
Security toolkit for Claude Code agents, MCP servers and skills — detect prompt injection, compromised API keys, integrity tampering
Advanced Secrets & API Key Scanner - Protect Your Code, Protect Your Business
Security guardrails for AI coding agents. Blocks prompt injection, prevents credential exfiltration, scans session logs.
A Go-based HTTP service that scrapes public GitHub repositories for exposed secrets and API keys using configurable regex patterns.
Scans GitHub for leaked OpenAI, Anthropic, Gemini API keys. Tests each one live. Saves the working ones to disk. No credits. No cloud service. No subscription. Just Go.
Add a description, image, and links to the api-key-scanner topic page so that developers can more easily learn about it.
To associate your repository with the api-key-scanner topic, visit your repo's landing page and select "manage topics."