Exposed API key checker
Check if Your
API Keys Are Exposed
A single API key left in your frontend bundle can be scraped by a bot within minutes of going live — running up huge bills or handing over your data. Paste your site's URL and we'll scan the live page source and JavaScript for leaked keys, then tell you exactly which to rotate.
Free instant scan · See your first issue free · No account needed
- OpenAI & other LLM keys in your bundle (sk-…)
- Stripe live secret keys (sk_live_…)
- AWS access keys (AKIA…)
- Google API keys and Supabase service_role keys
- Keys hidden in source maps shipped to production
