← All tools
Scan for exposed GitHub tokens
A leaked GitHub PAT can give an attacker read/write access to your private repositories and CI. GhostCred detects exposed ghp_/gho_/ghs_ and fine-grained tokens and OAuth credentials in your code and config.
Check a snippet now
This check runs in your browser, nothing is uploaded. Paste a config file or code snippet and matches appear below as you type.
Patterns checked on this page (5)
- Private key block
- GitHub token (ghp_, gho_, ghu_, ghs_, ghr_)
- GitHub fine-grained personal access token
- GitLab personal access token
- Hardcoded secret assignment (password, token, api_key, secret...)
Scan for exposed GitHub tokensFree first repo scan, no signup.
What the full scan checks
- ✓Personal access tokens (ghp_…) and fine-grained tokens
- ✓OAuth and app installation tokens (gho_…, ghs_…)
- ✓Tokens in CI config, Dockerfiles, and .env files
- ✓Deploy keys and credentials committed to the repo
Why it matters
Repo access is lateral-movement gold: source code, more secrets, and your build pipeline. A 60-second check beats discovering it in an incident.
Free first scan. No signup. Results in ~60 seconds.
Scan for exposed GitHub tokens