Free tool
Are there API keys in your JavaScript?
Everything a browser downloads is readable by whoever downloads it. A key that ends up in a bundle is published, not hidden, and the AI builders are unusually good at putting one there. We fetch your homepage and the scripts it links, and match them against the credential formats of the major providers.
What it actually does
Three steps, and none of them touch anything on the address you give it. Worth reading before you point a scanner at your own production site.
-
Step 1
Fetch the page
One GET to the address you give us, exactly as a browser would make it. Nothing is signed in to and no form is submitted.
-
Step 2
Read the scripts it links
Every JavaScript bundle the page references is downloaded and read, because that is what a visitor downloads too.
-
Step 3
Match known key formats
The contents are matched against the credential formats the major providers issue, so a match is a real key rather than a string that looks like one.
Read-only. Nothing is signed in to, submitted or changed on the address you enter. See the methodology for how each result is graded.
The rest of it
This is one check of 48.
Leaked keys are one finding. The full scan also checks exposed .env and .git paths, debug pages left on, open admin surfaces and source maps.
Run the full free auditRun your first audit today
Start on the free plan, with enough searches to cover a city and enough audits to judge a shortlist. No card, and it does not expire.