← All tools

Find secrets leaked in CI/CD configs

Pipeline configs are a magnet for hardcoded tokens and deploy keys. GhostCred scans your GitHub Actions, GitLab CI, CircleCI, and other pipeline files for exposed credentials.

Check a snippet now

This check runs in your browser, nothing is uploaded. Paste a config file or code snippet and matches appear below as you type.

Patterns checked on this page (20)
  • Private key block
  • AWS access key ID
  • AWS secret access key
  • Stripe secret or restricted key
  • Stripe webhook signing secret
  • Stripe publishable key
  • Anthropic API key
  • OpenAI API key
  • GitHub token (ghp_, gho_, ghu_, ghs_, ghr_)
  • GitHub fine-grained personal access token
  • GitLab personal access token
  • Google API key
  • Google OAuth client secret
  • Slack token
  • Slack incoming webhook URL
  • SendGrid API key
  • npm access token
  • JSON Web Token
  • Connection string with an inline password
  • Hardcoded secret assignment (password, token, api_key, secret...)
Scan my CI/CD configFree first repo scan, no signup.

What the full scan checks

Why it matters

Your pipeline has the keys to ship to production. A leak here is a leak everywhere downstream.

Free first scan. No signup. Results in ~60 seconds.

Scan my CI/CD config