← All tools
Find secrets leaked in CI/CD configs
Pipeline configs are a magnet for hardcoded tokens and deploy keys. GhostCred scans your GitHub Actions, GitLab CI, CircleCI, and other pipeline files for exposed credentials.
Check a snippet now
This check runs in your browser, nothing is uploaded. Paste a config file or code snippet and matches appear below as you type.
Patterns checked on this page (20)
- Private key block
- AWS access key ID
- AWS secret access key
- Stripe secret or restricted key
- Stripe webhook signing secret
- Stripe publishable key
- Anthropic API key
- OpenAI API key
- GitHub token (ghp_, gho_, ghu_, ghs_, ghr_)
- GitHub fine-grained personal access token
- GitLab personal access token
- Google API key
- Google OAuth client secret
- Slack token
- Slack incoming webhook URL
- SendGrid API key
- npm access token
- JSON Web Token
- Connection string with an inline password
- Hardcoded secret assignment (password, token, api_key, secret...)
Scan my CI/CD configFree first repo scan, no signup.
What the full scan checks
- ✓Hardcoded tokens in workflow YAML
- ✓Deploy keys and cloud credentials in pipeline config
- ✓Secrets echoed into logs or build args
- ✓Registry and package-manager credentials
Why it matters
Your pipeline has the keys to ship to production. A leak here is a leak everywhere downstream.
Free first scan. No signup. Results in ~60 seconds.
Scan my CI/CD config