Skip to content

Free tool

Are there API keys in your JavaScript?

Everything a browser downloads is readable by whoever downloads it. A key that ends up in a bundle is published, not hidden, and the AI builders are unusually good at putting one there. We fetch your homepage and the scripts it links, and match them against the credential formats of the major providers.

Free, no account, and read-only

What it actually does

Three steps, and none of them touch anything on the address you give it. Worth reading before you point a scanner at your own production site.

  1. Step 1

    Fetch the page

    One GET to the address you give us, exactly as a browser would make it. Nothing is signed in to and no form is submitted.

  2. Step 2

    Read the scripts it links

    Every JavaScript bundle the page references is downloaded and read, because that is what a visitor downloads too.

  3. Step 3

    Match known key formats

    The contents are matched against the credential formats the major providers issue, so a match is a real key rather than a string that looks like one.

Read-only. Nothing is signed in to, submitted or changed on the address you enter. See the methodology for how each result is graded.

The rest of it

This is one check of 48.

Leaked keys are one finding. The full scan also checks exposed .env and .git paths, debug pages left on, open admin surfaces and source maps.

Run the full free audit

Run your first audit today

Start on the free plan, with enough searches to cover a city and enough audits to judge a shortlist. No card, and it does not expire.