← All tools
Detect exposed private keys
A leaked private key undermines everything it protects: TLS, SSH, signing, and more. GhostCred finds exposed .pem/.key files, SSH keys, and certificates in your code.
Check a snippet now
This check runs in your browser, nothing is uploaded. Paste a config file or code snippet and matches appear below as you type.
Patterns checked on this page (1)
- Private key block
Scan for exposed private keysFree first repo scan, no signup.
What the full scan checks
- ✓RSA/EC private keys (-----BEGIN PRIVATE KEY-----)
- ✓SSH private keys and .pem / .pfx / .p12 files
- ✓TLS certificates with bundled private keys
- ✓Signing and encryption keys in the repo
Why it matters
Private keys can't just be rotated quietly. Exposure often means re-issuing certs and rebuilding trust. Find them first.
Free first scan. No signup. Results in ~60 seconds.
Scan for exposed private keys