API key and secret exposure checker

Scan code, logs, configuration, or .env text for common secrets before you publish or share it. The scan runs locally in this browser tab. Your text is not uploaded.

Local-only scan. This page has no analytics and sends no text to ClipGuard. For a credential you already exposed, revoke or rotate it immediately.
0 characters Nothing is stored after you close or refresh this page.

Common secrets this checker can flag

OpenAI and Anthropic keys
GitHub access tokens
AWS access key IDs
Google API keys
Stripe secret keys
Slack and Discord webhooks
JWT tokens
Private key headers
Database connection strings
Credential assignments

No pattern-based scanner can prove text is safe. Review unusual credentials manually and rotate anything that may have been exposed.

Catch secrets before every paste

A one-time scan helps with one document. ClipGuard watches paste events on GitHub, Slack, Discord, forums, and other risky pages.