Articles ยท Privacy & Trust
Find leaked API keys and tokens before you paste
A support paste, a CI log, or a “can you look at this .env” message is how tokens leave the building. Searching by eye misses Bearer headers and AWS-style keys. Uploading the file to a random scanner copies every secret to someone else. A checker that runs in the tab, lists High and Medium hits with masked previews, and never prints the raw value in the report is the difference between sharing a stack and sharing production credentials.
Why this is worth doing in the browser
DevNestro’s Secret Leak Inspector reuses the same local detectors as the AI Prompt Privacy Checker: OpenAI-style keys, GitHub tokens, AWS access-key ids, Slack tokens, Google API keys, JWTs, Bearer headers, private-key armor, connection strings, password assignments, and URL userinfo. Emails and names are out of scope here so the report stays about secrets. Matches are replaced in a safe copy with [SECRET], [TOKEN], or [PASSWORD]. The scan is pattern matching. It is not a guarantee, not a pentest, and not a claim that the remaining text is safe to publish.
How to use the tool
Paste text or a config dump, scan, read the masked list, create a safe copy, copy it, or send the result to the Privacy Redactor when you also need emails and phones removed. Clear wipes the boxes. Analytics may record that the tool ran, not the payload.
- Treat High as “this pattern usually is a secret,” not as proof.
- Create a safe copy instead of redacting by hand in a screenshot.
- Still read the file. Custom headers and unusual encodings are missed.
- Do not paste the original into a ticket after you have a safe copy.
Privacy
Scanning runs in your browser. Text is not uploaded to DevNestro. Detected secret values are not sent to analytics.
Before you share a log or .env snippet, open Secret Leak Inspector, scan locally, and copy the labelled version.