Show HN: KeyLeak Detector – Scan websites for exposed API keys and secrets

Share This Post

I built this after seeing multiple teams accidentally ship API keys in their frontend code.

The problem: Modern web development moves fast. You’re vibe-coding, shipping features, and suddenly your AWS keys are sitting in a tag visible to anyone who opens DevTools. I’ve personally witnessed this happen to at least 3-4 production apps in the past year alone.

KeyLeak Detector runs through your site (headless browser + network interception) and checks for 50+ types of leaked secrets: AWS/Google keys, Stripe tokens, database connection strings, LLM API keys (OpenAI, Claude, etc.), JWT tokens, and more.

It’s not perfect—there are false positives—but it’s caught real issues in my own projects. Think of it as a quick sanity check before you ship.

Use case: Run it on staging before deploying, or audit your existing sites. Takes ~30 seconds per page.

MIT licensed, for authorized testing only.

https://github.com/Amal-David/keyleak-detector


Comments URL: https://news.ycombinator.com/item?id=45786192

Points: 1

# Comments: 0

Source: github.com

Subscribe To Our Newsletter

Get updates and learn from the best

More To Explore

Windows Securitym Hackers Feeds

You'll never see attrition referenced in an RCA

Article URL: https://surfingcomplexity.blog/2025/11/02/youll-never-see-attrition-referenced-in-an-rca/ Comments URL: https://news.ycombinator.com/item?id=45795232 Points: 1 # Comments: 0 Source: surfingcomplexity.blog

Do You Want To Boost Your Business?

drop us a line and keep in touch

We are here to help

One of our technicians will be with you shortly.