← All tools
Is your OpenAI API key exposed?
Leaked LLM API keys are a known target for automated scraping, and a drained key runs up the bill fast. GhostCred scans for exposed OpenAI, Anthropic, and other AI provider keys in your code and environment files.
Check a snippet now
This check runs in your browser, nothing is uploaded. Paste a config file or code snippet and matches appear below as you type.
Patterns checked on this page (4)
- Anthropic API key
- OpenAI API key
- Google API key
- Hardcoded secret assignment (password, token, api_key, secret...)
Check for exposed AI keysFree first repo scan, no signup.
What the full scan checks
- ✓OpenAI keys (sk-…) and project keys
- ✓Anthropic, Cohere, and other LLM provider keys
- ✓Keys hardcoded in notebooks, scripts, and front-end code
- ✓AI agent and service-account credentials
Why it matters
Bots scan public code for AI keys, so an exposed key can be abused long before a monthly bill makes it obvious.
Free first scan. No signup. Results in ~60 seconds.
Check for exposed AI keys