← All tools

Scan Dockerfiles for hardcoded secrets

Secrets baked into image layers or compose files ship to every environment and stay in the image history. GhostCred detects hardcoded credentials in your Dockerfiles and docker-compose configs.

Check a snippet now

This check runs in your browser, nothing is uploaded. Paste a config file or code snippet and matches appear below as you type.

Patterns checked on this page (20)
  • Private key block
  • AWS access key ID
  • AWS secret access key
  • Stripe secret or restricted key
  • Stripe webhook signing secret
  • Stripe publishable key
  • Anthropic API key
  • OpenAI API key
  • GitHub token (ghp_, gho_, ghu_, ghs_, ghr_)
  • GitHub fine-grained personal access token
  • GitLab personal access token
  • Google API key
  • Google OAuth client secret
  • Slack token
  • Slack incoming webhook URL
  • SendGrid API key
  • npm access token
  • JSON Web Token
  • Connection string with an inline password
  • Hardcoded secret assignment (password, token, api_key, secret...)
Scan my DockerfileFree first repo scan, no signup.

What the full scan checks

Why it matters

Anyone who pulls the image can extract baked-in secrets. Catch them before they ship.

Free first scan. No signup. Results in ~60 seconds.

Scan my Dockerfile