← All tools
Did you leak a Stripe secret key?
A committed sk_live key gives anyone the ability to read customers, create charges, or issue refunds. GhostCred scans your repo or config for exposed Stripe secrets and webhook signing keys instantly.
Check a snippet now
This check runs in your browser, nothing is uploaded. Paste a config file or code snippet and matches appear below as you type.
Patterns checked on this page (4)
- Stripe secret or restricted key
- Stripe webhook signing secret
- Stripe publishable key
- Hardcoded secret assignment (password, token, api_key, secret...)
Check for leaked Stripe keysFree first repo scan, no signup.
What the full scan checks
- ✓Live and test Stripe secret keys (sk_live…, sk_test…)
- ✓Restricted keys (rk_…) and webhook signing secrets
- ✓Keys committed to git or embedded in front-end bundles
- ✓Publishable keys paired with leaked secrets
Why it matters
Payment credentials are among the highest-value secrets in your stack. Catching an exposure before it's abused protects both revenue and customer trust.
Free first scan. No signup. Results in ~60 seconds.
Check for leaked Stripe keys