Secret Scanner for AI Prompts

Pasting code or logs into an AI chat is an easy way to send a credential along with it. Once sent it cannot be recalled, and that key can no longer be trusted. Run it through here first and take the redacted copy instead.

Paste something and it scans as you type.

The scan runs in your browser too. Sending secrets to someone else's server to check whether secrets leak would rather defeat the point. And a key you already pasted somewhere is not un-leaked by masking it — revoke it and issue a new one.

What it looks for

Keys with a known prefix: OpenAI's sk-, Anthropic's sk-ant-, GitHub's ghp_, AWS's AKIA and ASIA, Google's AIza, Slack's xox. Beyond those, a PEM block opening with BEGIN PRIVATE KEY, a JWT split by two dots, a URL carrying user:pass@, and .env lines whose name contains SECRET, TOKEN or PASSWORD. Personal data is a separate switch — Korean resident registration numbers, card numbers, 010 mobile numbers, and email addresses.

How it masks

A match is not blanked out entirely: the first four and last four characters are kept. You need to know which key it was in order to revoke and replace it, and if everything is covered nothing can be told apart. Matches of eight characters or fewer are covered completely. The line number is recorded with each match, and scanning stops after 500 of them.

False alarms and misses

Because it matches by shape, a sixteen-digit order number looks like a card number and an example.com address in documentation looks like personal data. Conversely, a prefix not on the list — Stripe's sk_live_, say — or a random string such as a database password slips through. The phone rule only knows Korean mobile numbers beginning 01 (010, 011, 016, 017, 018, 019), so numbers from other countries are not caught. Rather than loosening the rules to silence warnings, only the certain matches are marked red and the rest are left amber.

The masked text is shorter than the original

At most twelve asterisks are used. A thirty-character key shrinks to twenty — four leading, twelve asterisks, four trailing — so line lengths change. A key that appears several times is counted and masked every time. The list shows sixty findings at most and forty characters of each, but masking covers everything found.

The shape of the personal-data rules

A Korean resident registration number is matched only as six digits, then seven whose first digit is 1 to 4 — foreigner registration numbers starting 5 to 8 pass through. A card number must be four groups of four, so a fifteen-digit Amex written 4-6-5 is missed. A phone number is ten or eleven digits starting with 01, hyphens optional. An email is anything with an @ and a dot, so noreply@example.com is flagged too.

Frequently asked questions

If this comes back clean, am I safe?

No. Detection is based on shape, so keys with a known prefix (sk-, ghp_, AKIA and similar) are caught reliably, while an internal token with no fixed format or a password that is just a random string will slip through. Read it over yourself as well.

What if I already pasted it?

Redacting afterwards changes nothing. Revoke that key and issue a new one. Deleting the conversation does not guarantee that what was already transmitted is gone.

Does this scan run on a server?

No. Sending your secrets to someone else's server to find out whether your secrets are leaking would defeat the point. It runs entirely in your browser and works with the network disconnected.

What do I do with the masked text?

Take the masked copy instead. Only the values are replaced with asterisks, so the context survives and a model can still see where a key belongs — just not what it is.

The list stops at 60 items.

Only the display is capped at sixty; everything found is counted and masked. Scanning does stop at 501 findings, so paste text with more than that in pieces. Counts that high usually mean a column of emails or phone numbers — turning off personal-data detection is one way through.