Detect Exposed Credentials
Find API keys, tokens and private keys in code or logs, 100% in your browser.
or drop a text file (.env, .log, .txt, code)
Detection rules v2026.08.1 — inspired by gitleaks/trufflehog
How do you scan for exposed API keys and secrets before sharing a file?
Paste your code, a .env file, or a log into Docuboxer's secret scanner and within seconds you'll see every credential that matches a known format — an AWS key, a GitHub token, a database connection string with a password baked in, a PEM private key, and a dozen more — flagged with its exact line number and a partially masked value. It's easy to forget that a stack trace you're about to paste into a public issue, or a log you're sending to support, still carries a leftover token or database password buried in the text nobody reads line by line. This scanner runs detection rules inspired by gitleaks and trufflehog — the same class of engine security teams use to audit repositories — and labels every finding as either confirmed by format or possible, so a UUID or a git commit hash that merely looks random doesn't trigger a false alarm. The entire scan runs in your browser: nothing you paste is ever sent anywhere, so you can safely scan a .env with real production credentials without the risk of uploading them to someone else's server. Free, no signup, no usage limit.
How to use Detect Exposed Credentials
- Paste the code, .env file, or log you want to check into the text box, or drop it in as a file.
- The scanner walks through every line applying its detection rules and shows the findings grouped by severity, with the line number and a masked value.
- Review each finding along with its remediation note — where to revoke or rotate that specific type of credential.
- Copy the report if you need to document the review before cleaning up the file or rotating the exposed keys.
Common use cases
Check a log before pasting it into a public GitHub issue
Stack traces and error logs routinely drag along session tokens, connection strings, or auth headers. Scan the log before posting it to GitHub, a forum, or a support ticket so you don't leak credentials by accident.
Audit a .env file you inherited from someone else
When you're handed a project with a .env nobody remembers the origin of, check exactly what credentials it holds before reusing it, moving it into a secrets manager, or deleting it with confidence.
Review a repository before flipping it to public
Before switching a private repo to public, paste the contents of any config file you're unsure about to confirm no API key slipped into a loose file or an old commit.
Clean code before sharing it with support or a contractor
When you need to send a code snippet or config to someone outside your team, verify first that it doesn't include real secrets that person shouldn't see.
One more pass before a large commit
Paste the full diff of a commit that touches many files to catch any key that slipped in among the changes — a last filter before you push.
Frequently asked questions
Why is it safe to paste my real secrets into this tool?
Because the scan runs entirely in your browser using JavaScript — there's no network call involved at any point. You can verify this yourself by opening the Network panel in DevTools while you use the tool: you won't see a single outgoing request carrying the text you pasted.
What kinds of credentials does it detect?
AWS keys, GitHub and GitLab tokens, Slack tokens, Stripe live keys, Google, OpenAI, and Anthropic API keys, SendGrid and Twilio keys, npm tokens, JWTs, PEM private keys, database connection strings with embedded passwords, password environment variables, and a generic high-entropy heuristic for patterns not covered by a specific rule.
What does it mean for a finding to be "confirmed" versus "possible"?
"Confirmed" means the detected format is unambiguous for that provider — for example, AWS's AKIA prefix or GitHub's ghp_ prefix. "Possible" means it's based on a heuristic, such as a suspicious variable name combined with high entropy, that can occasionally produce a false positive. That's why the generic rule is always labeled "possible" — there's no way to confirm from format alone that a random-looking string is actually a secret.
Why is the detected value shown masked?
Even though everything happens in your browser, the tool never displays the full secret in the results — only the first and last few characters, with the rest hidden. That way you can identify which credential it is without it appearing in full on your screen or in a screenshot you might share.
If the scanner finds nothing, does that mean the file is clean?
Not necessarily. The rules cover widely used, publicly known credential formats, but they can't catch every possible secret — especially internal tokens or proprietary formats with no recognizable public pattern. Treat it as one useful layer of review, not an absolute guarantee.
Is there a size limit on the text I can scan?
The scanner processes roughly up to 1 MB of text per scan, enough for the vast majority of .env files, logs, and code snippets. If the file is larger, only the first portion is scanned and a notice appears on screen.