Scan Secrets in Text — Pattern Detector
Scan pasted text for secret-like patterns (AWS keys, GitHub PATs, PEM keys, and more). Documented subset — not a gitleaks-class repo scanner.
Developer notes
v1 detectors: pem_private_key, aws_access_key_id, github_pat, slack_token, generic_assignment, jwt_compact (opt-in), high_entropy_string (opt-in). Redaction: first 4 + last 4 chars (full mask if length < 12) in match and excerpt; Copy uses redacted columns only. validate-env (DevOps) mainly warns on secret-looking .env key names — complementary. 512 KB limit.
Options
- Severity floor
- all = every hit; high = high-severity detectors only.
- Entropy hints
- Enables noisy entropy heuristics — off by default.
- Include JWT
- Detects compact JWT tokens (low severity). Prefer jwt-decode to read a JWT.
When teams pick this route
Quick check of a paste before posting to a ticket. Spot an obvious GitHub PAT or AWS access key. Reduce noise with high-only severity floor.
Worked examples
Staging .env snippet
Before
After (hits)
severityFloor=high
Before
After (hits)
Related tools
For .env key-name warnings use validate-env. For a compact JWT: jwt-decode. Hub: security tools.
Scan secrets FAQ
Documented subset
When should I use validate-env?
validate-env validates .env structure and flags suspicious key names. scan-secrets looks for secret-like value patterns in any pasted text. An empty validate-env result is not the same signal as soft-empty here.
When should I use jwt-decode?
To read a JWT header/payload, use jwt-decode. This scanner’s includeJwt option is off by default to avoid false positives.
Is this a full repository secrets scanner?
No. It is a documented pattern subset for pasted text — not a repository walk or enterprise rule pack.
Which detectors are included?
pem_private_key, aws_access_key_id, github_pat, slack_token, generic_assignment; jwt_compact and high_entropy_string are opt-in.
Security & tokens
JWKS, X.509 certificates, and secrets scan — browser-local.
Explore other tool categories
- Minify
Shrink code and assets for production — minify JavaScript, CSS, HTML, JSON and XML before gzip or CDN deploy.
- Unminify
Expand minified or compressed code — unminify JavaScript, CSS, TypeScript, SCSS, LESS, SQL, YAML and other formats when debugging or reviewing.
- Conversion
Transform data between JSON, YAML, XML and CSV locally — no server uploads.
- Encoding
Encode or decode Base64, URL components and HTML entities — client-side only.
- Serialization
Serialize and deserialize PHP data structures beside JSON workflows.
- JSON Tools
Validate, format, diff and explore JSON payloads — complementary to minifiers and converters.
- SVG Tools
Preview, optimize with SVGO, export Data URI, resize, beautify, convert to JSX and validate SVG — all in your browser.
- Beautify
Make code readable with consistent indentation — beautify JavaScript, CSS, TypeScript, SCSS, LESS, Markdown, GraphQL, SQL, YAML and more in your browser.
- CSS preprocessors
Compile SCSS or LESS to standard CSS in the browser — pair with beautify or minify for a full stylesheet workflow.
- Color & CSS Tools
Paste-local WCAG contrast checking with modern CSS color syntax — pair and matrix views, never uploaded.
- DevOps & Infra
Terraform HCL format/validate/minify, Dockerfile format & lint, Docker Compose and .env validation.
- CI/CD
GitHub Actions and GitLab CI — format YAML and check workflow/job structure in your browser.
- Logs & observability
Line-oriented JSON/NDJSON and Nginx/Apache access logs — format, filter, validate, and CSV/TSV.
- Kubernetes
Multi-doc manifests, structural validate, Ingress/Deployment starters, and Helm values formatting.
- Networking / IP
CIDR, subnets, and IPv4/IPv6 helpers — in your browser.
- API & schemas
OpenAPI tools to format, validate, and lint your specs.
- HTTP Tools
Paste-local cURL, HTTP messages, URLs, HAR files, and Cookie / Set-Cookie headers — format and inspect in your browser, never sent.
- SEO / Web Tools
Generate meta tags, Open Graph, and Twitter Card output locally — previews simulated from your inputs, never fetched from your live site.
- Developer utilities
Timestamps, UUID, ULID, Nanoid, cron, passwords, regex, slugify, number bases, case, text diff, and chmod — all client-side.
- Text & Markdown
Count words, build Markdown TOCs, and clean line lists — all in your browser.
- AI & LLM
Token counting, pricing estimates, and context-window fit — 100% browser-local.
- Test Data
Synthetic field values for fixtures and DB seed — reserved-range phone numbers first.
- Barcode labels
Draw Code 128, EAN-13, and UPC-A label images in the browser — PNG and SVG download, not a GS1 lookup.