Source Secret Auditor
Choose local source files or a folder to locate possible service tokens, private-key headers, credential assignments and bearer tokens. This is a bounded, rule-based review tool: it returns a path, line number and rule name without displaying the matched value or surrounding code. Exclude generated and fixture files, then investigate each candidate in your own editor. Zero findings never proves that a repository contains no secrets.
Key features
- Detect selected common service-token shapes and private-key headers
- Review likely literal assignments and bearer values without exposing them
- Show path, line, rule and confidence only; no matched bytes or code excerpts
- Exclude generated directories, fixture paths and user-specified glob patterns
- Download a masked JSON report with explicit skipped-file and scan-limit counts
How to use
- Select source files or a folder in the browser.
- Adjust exclusion globs and decide whether to include credential assignments and fixtures.
- Run the local scan and review file, line, rule and confidence for each candidate.
- Inspect the cited lines privately in your own editor; rotate or remove confirmed exposed credentials.
- Download the masked JSON report if needed, and review paths before sharing it.
Use cases
- Review a project before publishing source code
- Find a pasted private-key header in a configuration file
- Exclude test fixtures that intentionally contain example tokens
- Produce a location-only review list for a teammate
Frequently asked questions
Does zero findings mean my code is free of secrets?
No. The scanner recognizes a limited set of patterns in selected, readable text files. Encoded, split, unusual or excluded secrets can be missed. Review your repository and use dedicated security processes as well.
Are secret values shown in the page or JSON report?
No. Findings contain a path, line number, rule and confidence only. The tool does not include matched values, partial bytes or source excerpts in either output.
How can I reduce false positives?
Use path globs to exclude generated or test files, leave fixture scanning off, disable broad assignment and bearer checks, or mark an intentional line with secret-auditor: ignore. The line marker suppresses all rules on that line.
What files and limits apply?
The browser reads up to 200 selected files, at most 1 MiB each and 12 MiB total. It scans at most 50,000 lines per file and returns at most 2,000 findings. Unsupported extensions, binary text, oversized files and generated paths are listed as skipped.
Does this tool test whether a credential works?
No. It never contacts a provider or validates a token. If you confirm a real credential was exposed, revoke or rotate it through the provider and check its usage separately.
Privacy
Selected file contents are read in this browser tab and are not sent to this site by this tool. The on-screen result and downloaded JSON contain no source snippets or matched values. Paths and line numbers remain in the report, so review those before sharing it. Clearing the page discards the in-memory results.
Comments & questions