[ Free tool ]
Leaked API key scanner
AI builders often put secret keys where every visitor can read them. Enter your site’s URL and we’ll check the JavaScript it ships for Stripe, OpenAI, Anthropic, Supabase service-role and other secret keys.
What it checks
- Critical: Stripe live secret and restricted keys, OpenAI, Anthropic, Groq and Replicate keys, Supabase
service_roleandsb_secret_keys, AWS access keys, GitHub and Slack tokens, SendGrid and Mailgun keys, private keys. - Info: keys that are meant to be public but only safe with the right rules: Supabase anon/publishable keys (needs row-level security), Firebase web keys (needs restricted keys and locked-down rules), Stripe publishable keys.
What it can’t check
A clean scan doesn’t mean a safe app. This only sees what your site sends to the browser. It can’t see whether your Supabase tables have row-level security, whether your API routes check who’s calling, whether your Stripe webhooks verify signatures, or what’s in your repo’s history. That’s what theSecurity Audit is for.
Found something?
- Rotate the key first in the provider’s dashboard. Removing it from the code doesn’t help. It has already been downloaded.
- Move the call to a server: a Supabase Edge Function, a Cloudflare Worker or your API. The browser calls your server; your server holds the key.
- Check usage and billing on the provider for anything you didn’t do.
Shipped through App Review
Our own apps go through the same review yours does.
We ship native iOS apps under our own names and for clients, which is why we know where AI-built apps get stuck.
Next step
Keys in your bundle are rarely the only problem.
The scan sees what your site ships. The audit reads the code, the database rules and the API behind it, and ranks what to fix first.

