Free Tool
Secrets scanner for AI agent configs
Paste an MCP config, env file, agent prompt, or any config file. We'll check it for exposed API keys and credentials — in your browser, in seconds.
Nothing leaves your browser. No account required.
.json, .env, .yaml, .toml, .md, .ts, .js, .py, .txt — max 250KB
What we detect
OpenAI API keys
Anthropic API keys
GitHub tokens
Stripe secret keys
AWS access keys
Linear API keys
Resend API keys
MCP env block credentials
Bearer tokens in headers
.env credential values
Named credential fields
Generic API key fields
UUIDs, bcrypt hashes, PEM keys, and placeholder values are automatically suppressed.