Scan Secrets in Text — Pattern Detector

Scan pasted text for secret-like patterns (AWS keys, GitHub PATs, PEM keys, and more). Documented subset — not a gitleaks-class repo scanner.

…
Secrets scan (paste)
Find secret-like patterns in pasted text. Fixed documented detector list — not a gitleaks equivalent.

Developer notes

v1 detectors: pem_private_key, aws_access_key_id, github_pat, slack_token, generic_assignment, jwt_compact (opt-in), high_entropy_string (opt-in). Redaction: first 4 + last 4 chars (full mask if length < 12) in match and excerpt; Copy uses redacted columns only. validate-env (DevOps) mainly warns on secret-looking .env key names — complementary. 512 KB limit.

Options

Severity floor
all = every hit; high = high-severity detectors only.
Entropy hints
Enables noisy entropy heuristics — off by default.
Include JWT
Detects compact JWT tokens (low severity). Prefer jwt-decode to read a JWT.

When teams pick this route

Quick check of a paste before posting to a ticket. Spot an obvious GitHub PAT or AWS access key. Reduce noise with high-only severity floor.

Worked examples

Staging .env snippet

Before

# Staging deploy — fake secrets for demo only APP_NAME=payments-api NODE_ENV=staging LOG_LEVEL=info # AWS (fake AKIA from AWS documentation) AWS_ACCESS_KEY_ID=AKIAIOSFODNN7EXAMPLE AWS_REGION=eu-central-1 # GitHub Actions deploy GITHUB_TOKEN=ghp_TESTONLYabcdefghijklmnopqrstuv # Slack alert bot SLACK_BOT_TOKEN=xoxb-0000000000-0000000000000-abcdefghijklmnopqrstuvwx # Database DATABASE_HOST=db.internal.example DATABASE_PORT=5432 password=notarealsecret123 # Auth callback (JWT — toggle Include JWT) AUTH_JWT=eyJhbGciOiJub25lIiwidHlwIjoiSldUIn0.eyJzdWIiOiJkZW1vIn0.sig # High-entropy blob (Entropy — toggle Entropy) Aa1!xY9zxY9zxY9zxY9zxY9zxY9zxY9zxY9z # Health — no secrets HEALTHCHECK_PATH=/health

After (hits)

4 hits by default: aws_access_key_id (L7) · github_pat (L11) · slack_token (L14) · generic_assignment (L19, medium). Enable Include JWT (+ jwt_compact L22) and Entropy (+ high_entropy_string L25) for 6 hits total.

severityFloor=high

Before

password=notarealsecret123 AKIAIOSFODNN7EXAMPLE

After (hits)

Only aws_access_key_id (high); generic_assignment omitted

Related tools

For .env key-name warnings use validate-env. For a compact JWT: jwt-decode. Hub: security tools.

Scan secrets FAQ

Documented subset

When should I use validate-env?

validate-env validates .env structure and flags suspicious key names. scan-secrets looks for secret-like value patterns in any pasted text. An empty validate-env result is not the same signal as soft-empty here.

When should I use jwt-decode?

To read a JWT header/payload, use jwt-decode. This scanner’s includeJwt option is off by default to avoid false positives.

Is this a full repository secrets scanner?

No. It is a documented pattern subset for pasted text — not a repository walk or enterprise rule pack.

Which detectors are included?

pem_private_key, aws_access_key_id, github_pat, slack_token, generic_assignment; jwt_compact and high_entropy_string are opt-in.

JWKS, X.509 certificates, and secrets scan — browser-local.