FM Field Manual smhansen.dev

FM 4-09 Chapter 4 · Security and crypto

Secret scanner

Find API keys, tokens, private keys and passwords in text before sharing it, and redact them.

Local only Runs in your browser. Nothing you enter leaves this page.

Usable as a step in Chain

Scanned in this tab only. The text is not sent anywhere and not written to the address bar.

Known formats: AWS access key IDs (AKIA, ASIA) and a 40-character secret key next to one, GitHub (ghp_, gho_, ghu_, ghs_, ghr_, github_pat_), GitLab glpat-, Slack xox tokens and webhooks, Stripe sk_live_ and rk_live_, Google AIza keys, Azure AccountKey=, PEM private keys, JWTs, passwords in URLs and assignments such as password=, secret: or api_key =.

High entropy: a run of at least 20 base64-type characters with letters and digits whose Shannon entropy (bits per character, from its own character frequencies) reaches 0.85 of the most a string that long can have, capped at 4.5 bits, and that switches between upper case, lower case and digits at least 40% of the time. Random keys pass; words and camelCase names mostly do not. Hex strings (hashes, IDs) count only next to a word like key, secret or token. Expect some false positives.

  • No entry in this manual matches “”.

↑ ↓ move · Enter open · Esc close