← All tools

Scan your .env file for secrets

The humble .env is where secrets pile up, and where they leak when committed by accident. Paste it below for an instant in-browser check, or upload it for a full scan that surfaces each credential and scores the risk. The paid report maps findings to SOC 2 / HIPAA.

Check a snippet now

This check runs in your browser, nothing is uploaded. Paste a config file or code snippet and matches appear below as you type.

Patterns checked on this page (20)
  • Private key block
  • AWS access key ID
  • AWS secret access key
  • Stripe secret or restricted key
  • Stripe webhook signing secret
  • Stripe publishable key
  • Anthropic API key
  • OpenAI API key
  • GitHub token (ghp_, gho_, ghu_, ghs_, ghr_)
  • GitHub fine-grained personal access token
  • GitLab personal access token
  • Google API key
  • Google OAuth client secret
  • Slack token
  • Slack incoming webhook URL
  • SendGrid API key
  • npm access token
  • JSON Web Token
  • Connection string with an inline password
  • Hardcoded secret assignment (password, token, api_key, secret...)
Scan my .env fileFree first repo scan, no signup.

What the full scan checks

Why it matters

One stray `git add .env` and your whole stack is exposed. A quick scan tells you exactly what's at risk.

Free first scan. No signup. Results in ~60 seconds.

Scan my .env file