← All tools

Scan for exposed GitHub tokens

A leaked GitHub PAT can give an attacker read/write access to your private repositories and CI. GhostCred detects exposed ghp_/gho_/ghs_ and fine-grained tokens and OAuth credentials in your code and config.

Check a snippet now

This check runs in your browser, nothing is uploaded. Paste a config file or code snippet and matches appear below as you type.

Patterns checked on this page (5)
  • Private key block
  • GitHub token (ghp_, gho_, ghu_, ghs_, ghr_)
  • GitHub fine-grained personal access token
  • GitLab personal access token
  • Hardcoded secret assignment (password, token, api_key, secret...)
Scan for exposed GitHub tokensFree first repo scan, no signup.

What the full scan checks

Why it matters

Repo access is lateral-movement gold: source code, more secrets, and your build pipeline. A 60-second check beats discovering it in an incident.

Free first scan. No signup. Results in ~60 seconds.

Scan for exposed GitHub tokens