Scan Secrets in Text — Pattern Detector

Scan pasted text for secret-like patterns (AWS keys, GitHub PATs, PEM keys, and more). Documented subset — not a gitleaks-class repo scanner.

Loading…
Secrets scan (paste)
Find secret-like patterns in pasted text. Fixed documented detector list — not a gitleaks equivalent.

Developer notes

• v1 detectors: pem_private_key, aws_access_key_id, github_pat, slack_token, generic_assignment, jwt_compact (opt-in), high_entropy_string (opt-in). • Redaction: first 4 + last 4 chars (full mask if length < 12) in match and excerpt; Copy uses redacted columns only. • validate-env (DevOps) mainly warns on secret-looking .env key names — complementary. • 512 KB limit.

Options

Severity floor
all = every hit; high = high-severity detectors only.
Entropy hints
Enables noisy entropy heuristics — off by default.
Include JWT
Detects compact JWT tokens (low severity). Prefer jwt-decode to read a JWT.

When teams pick this route

• Quick check of a paste before posting to a ticket. • Spot an obvious GitHub PAT or AWS access key. • Reduce noise with high-only severity floor.

Worked examples

Staging .env snippet

Before

# Staging deploy — fake secrets for demo only APP_NAME=payments-api NODE_ENV=staging LOG_LEVEL=info # AWS (fake AKIA from AWS documentation) AWS_ACCESS_KEY_ID=AKIAIOSFODNN7EXAMPLE AWS_REGION=eu-central-1 # GitHub Actions deploy GITHUB_TOKEN=ghp_TESTONLYabcdefghijklmnopqrstuv # Slack alert bot SLACK_BOT_TOKEN=xoxb-0000000000-0000000000000-abcdefghijklmnopqrstuvwx # Database DATABASE_HOST=db.internal.example DATABASE_PORT=5432 password=notarealsecret123 # Auth callback (JWT — toggle Include JWT) AUTH_JWT=eyJhbGciOiJub25lIiwidHlwIjoiSldUIn0.eyJzdWIiOiJkZW1vIn0.sig # High-entropy blob (Entropy — toggle Entropy) Aa1!xY9zxY9zxY9zxY9zxY9zxY9zxY9zxY9z # Health — no secrets HEALTHCHECK_PATH=/health

After (hits)

4 hits by default: aws_access_key_id (L7) · github_pat (L11) · slack_token (L14) · generic_assignment (L19, medium). Enable Include JWT (+ jwt_compact L22) and Entropy (+ high_entropy_string L25) for 6 hits total.

severityFloor=high

Before

password=notarealsecret123 AKIAIOSFODNN7EXAMPLE

After (hits)

Only aws_access_key_id (high); generic_assignment omitted

Related tools

For .env key-name warnings use validate-env. For a compact JWT: jwt-decode. Hub: security tools.

Scan secrets FAQ

Documented subset

When should I use validate-env?

validate-env validates .env structure and flags suspicious key names. scan-secrets looks for secret-like value patterns in any pasted text. An empty validate-env result is not the same signal as soft-empty here.

When should I use jwt-decode?

To read a JWT header/payload, use jwt-decode. This scanner’s includeJwt option is off by default to avoid false positives.

Is this a full repository secrets scanner?

No. It is a documented pattern subset for pasted text — not a repository walk or enterprise rule pack.

Which detectors are included?

pem_private_key, aws_access_key_id, github_pat, slack_token, generic_assignment; jwt_compact and high_entropy_string are opt-in.

Security & tokens

JWKS, X.509 certificates, and secrets scan — browser-local.

Explore other tool categories

Minify

Shrink code and assets for production — minify JavaScript, CSS, HTML, JSON and XML before gzip or CDN deploy.

Beautify

Make code readable with consistent indentation — beautify JavaScript, CSS, TypeScript, SCSS, LESS, Markdown, GraphQL, SQL, YAML and more in your browser.

Unminify

Expand minified or compressed code — unminify JavaScript, CSS, TypeScript, SCSS, LESS, SQL, YAML and other formats when debugging or reviewing.

Conversion

Transform data between JSON, YAML, XML and CSV locally — no server uploads.

CSS preprocessors

Compile SCSS or LESS to standard CSS in the browser — pair with beautify or minify for a full stylesheet workflow.

JSON Tools

Validate, format, diff and explore JSON payloads — complementary to minifiers and converters.

SVG Tools

Preview, optimize with SVGO, export Data URI, resize, beautify, convert to JSX and validate SVG — all in your browser.

DevOps & Infra

Terraform HCL format/validate/minify, Dockerfile format & lint, Docker Compose and .env validation.

CI/CD

GitHub Actions and GitLab CI — format YAML and check workflow/job structure in your browser.

Logs & observability

Line-oriented JSON/NDJSON and Nginx/Apache access logs — format, filter, validate, and CSV/TSV.

Kubernetes

Multi-doc manifests, structural validate, Ingress/Deployment starters, and Helm values formatting.

Networking / IP

CIDR, subnets, and IPv4/IPv6 helpers — in your browser.

API & schemas

OpenAPI tools to format, validate, and lint your specs.

Encoding

Encode or decode Base64, URL components and HTML entities — client-side only.

Developer utilities

Timestamps, UUID, ULID, Nanoid, cron, passwords, regex, slugify, number bases, case, text diff, and chmod — all client-side.

Text & Markdown

Count words, build Markdown TOCs, and clean line lists — all in your browser.

AI & LLM

Token counting, pricing estimates, and context-window fit — 100% browser-local.

Serialization

Serialize and deserialize PHP data structures beside JSON workflows.