Source Secret Auditor

Source Secret Auditor

Browser-local source review · candidate values are never shown or exported.

1. Select source files

Choose individual files or a folder. The last selection replaces the previous selection; selected source contents stay in this tab.

0 files selected · 200 files · 1 MiB per file · 12 MiB total · 2,000 findings maximum

Generated folders are always skipped. Paths matching these globs and fixture folders are skipped by default. Use secret-auditor: ignore on an intentional source line.

Select files to begin.

Comments & questions

Source Secret Auditor

Choose local source files or a folder to locate possible service tokens, private-key headers, credential assignments and bearer tokens. This is a bounded, rule-based review tool: it returns a path, line number and rule name without displaying the matched value or surrounding code. Exclude generated and fixture files, then investigate each candidate in your own editor. Zero findings never proves that a repository contains no secrets.

Key features

  • Detect selected common service-token shapes and private-key headers
  • Review likely literal assignments and bearer values without exposing them
  • Show path, line, rule and confidence only; no matched bytes or code excerpts
  • Exclude generated directories, fixture paths and user-specified glob patterns
  • Download a masked JSON report with explicit skipped-file and scan-limit counts

How to use

  1. Select source files or a folder in the browser.
  2. Adjust exclusion globs and decide whether to include credential assignments and fixtures.
  3. Run the local scan and review file, line, rule and confidence for each candidate.
  4. Inspect the cited lines privately in your own editor; rotate or remove confirmed exposed credentials.
  5. Download the masked JSON report if needed, and review paths before sharing it.

Use cases

  • Review a project before publishing source code
  • Find a pasted private-key header in a configuration file
  • Exclude test fixtures that intentionally contain example tokens
  • Produce a location-only review list for a teammate

Frequently asked questions

Does zero findings mean my code is free of secrets?

No. The scanner recognizes a limited set of patterns in selected, readable text files. Encoded, split, unusual or excluded secrets can be missed. Review your repository and use dedicated security processes as well.

Are secret values shown in the page or JSON report?

No. Findings contain a path, line number, rule and confidence only. The tool does not include matched values, partial bytes or source excerpts in either output.

How can I reduce false positives?

Use path globs to exclude generated or test files, leave fixture scanning off, disable broad assignment and bearer checks, or mark an intentional line with secret-auditor: ignore. The line marker suppresses all rules on that line.

What files and limits apply?

The browser reads up to 200 selected files, at most 1 MiB each and 12 MiB total. It scans at most 50,000 lines per file and returns at most 2,000 findings. Unsupported extensions, binary text, oversized files and generated paths are listed as skipped.

Does this tool test whether a credential works?

No. It never contacts a provider or validates a token. If you confirm a real credential was exposed, revoke or rotate it through the provider and check its usage separately.

Privacy

Selected file contents are read in this browser tab and are not sent to this site by this tool. The on-screen result and downloaded JSON contain no source snippets or matched values. Paths and line numbers remain in the report, so review those before sharing it. Clearing the page discards the in-memory results.

Related Tools

Password Strength CheckerSensitive Text RedactorData Anonymization WorkbenchWasm Module InspectorHreflang Matrix CheckerAST Query PlaygroundContainer Build GraphDependency Graph ExplorerSemver Range LabCron Schedule AuditorPatch Review WorkbenchSource Map ExplorerLocalization Catalog AuditorStructured Data ReviewerHTTP Archive AnalyzerWebhook Signature LabProtobuf Schema WorkbenchGraphQL Schema LabAvro Schema EvolutionLocal SQL WorkbenchSchema Form BuilderMesh Repair WorkbenchPipe Network LabRobot Arm Kinematics LabThermal Network LabBeam Response LabGear Train DesignerTolerance Stackup LabSensor Calibration FitPCB Stackup PlannerDigital Filter DesignerNetwork Reachability MapSun Shadow MapGPS Error SimulatorDigital Logic SimulatorAnalog Circuit LabMechanism Linkage LabAnalysis Mesh GeneratorOpenAPI Contract InspectorDatabase Migration PlannerDimensional Equation CheckerTruss Force LabBoolean Minimization LabControl Response LabQueueing Simulation LabGeofence Event SimulatorCoordinate Reference LabSurvey Traverse LabRaster Classification LabChoropleth Design LabMap Print ComposerRaster Reprojection LabElevation Contour MakerTerrain Viewshed LabWatershed DelineatorMap Tile PackagerText File Encoding WorkbenchFilesystem Portability AuditorSBOM License ExplorerFile Signature Auditornpm Lockfile Conflict ResolverOffline Web Package BuilderCertificate Chain InspectorTorrent Metainfo InspectorChunked File PackagerEncrypted File VaultDuplicate File FinderArchive WorkbenchDesign Token ManagerSpacing Token DesignerResponsive Type SystemPackaging Dieline DesignerSVG Icon Sprite PackerFlex Layout PlaygroundCSS Grid PlaygroundRegex Equivalence LabMarkdown Repository AuditorLog Template MinerResponsive Layout AuditorEmail Template PreviewInternal Link GraphState Machine TesterPetri Net SimulatorGit History VisualizerCurl Request WorkbenchBinary Protocol DesignerHex File EditorBinary Patch WorkbenchFile Signature WorkbenchAPI Mock SandboxSchema Column MapperEvent Log SessionizerER Diagram DesignerTime Series Gap AuditorStratified Data SplitterData Lineage DesignerDecision Tree LabData Expectation RunnerJSON Schema ValidatorBasket Pattern AnalyzerRobots Policy TesterSEO HTML AuditorAccessibility Structure AuditorSyndication Feed WorkbenchIndexNow Payload BuilderCrawl Log AnalyzerCSP Policy WorkbenchSearch Performance AnalyzerCSV Formula Risk AuditorCORS Response SimulatorCache Header LabCookie Policy InspectorWeb Vitals Trace LabSitemap Health AuditorBatch File RenamerFile Manifest VerifierFolder Space MapFolder Difference ReviewerRoute Order OptimizerGeoJSON Map EditorPolygon Overlay LabCartographic Label PlacerSpatial Table JoinGeoJSON Topology AuditorGPX Track AnalyzerTrack Privacy RedactorCSV Table JoinCSV Pivot WorkbenchScientific Data ProfilerTabular Cleaning WorkbenchRecord ReconciliationData Dictionary BuilderCanonical Graph AuditorRedirect Plan TesterHTTP response and ping reference testBrowser and System InformationJSON ↔ YAML ConverterXML ↔ JSON ConverterHTML FormatterJavaScript MinifierMock Data Generator.gitignore GeneratorLicense GeneratorUser-Agent ParserCode to ImageXML FormatterHTTP Status Code LookupMIME Type LookupJS & SQL String EscapeCSS Box Shadow GeneratorCSS Gradient GeneratorIndent ConverterNumber Base ConverterUnicode Escape ConverterUnicode InspectorJSON Structure DiffMarkdown Table GeneratorBase64 EncoderJSON FormatterURL EncoderSQL FormatterCron Expression GeneratorRegex TesterUUID GeneratorHash GeneratorTimestamp ConverterJWT DecoderHTML Entity ConverterMarkdown PreviewCSS MinifierMeta Tag GeneratorJSON ↔ CSVCase ConverterImage to Base64
Explore all Dev Tools tools →Image/Media →Text/Convert →Life/Fun →