GuardCue

Is a secret key sitting in my website?

Keys for payments, email, text messages and databases are meant to live on the server, where visitors cannot see them. When one ends up in the code the browser downloads, or committed alongside the app’s code, anyone who looks can copy it and use it as you. This check reads what your site ships to a browser and flags a real key, telling apart a genuine secret from a harmless public one.

Free. No sign-up. We only look at what any visitor can already see.

What this check can and cannot see

This sees what your public site exposes. To also read the app’s source history we would need you to connect the code, which unlocks a deeper version of this check. A clean result here means nothing dangerous is in what a visitor can see.

What we will never doChange anything in your app, or keep your customers’ data. A finding holds a count, the column names, and one sample blanked past its first two characters.