Show HN: KeyLeak Detector – Scan websites for exposed API keys and secrets

Share This Post

I built this after seeing multiple teams accidentally ship API keys in their frontend code.

The problem: Modern web development moves fast. You’re vibe-coding, shipping features, and suddenly your AWS keys are sitting in a tag visible to anyone who opens DevTools. I’ve personally witnessed this happen to at least 3-4 production apps in the past year alone.

KeyLeak Detector runs through your site (headless browser + network interception) and checks for 50+ types of leaked secrets: AWS/Google keys, Stripe tokens, database connection strings, LLM API keys (OpenAI, Claude, etc.), JWT tokens, and more.

It’s not perfect—there are false positives—but it’s caught real issues in my own projects. Think of it as a quick sanity check before you ship.

Use case: Run it on staging before deploying, or audit your existing sites. Takes ~30 seconds per page.

MIT licensed, for authorized testing only.

https://github.com/Amal-David/keyleak-detector


Comments URL: https://news.ycombinator.com/item?id=45786192

Points: 1

# Comments: 0

Source: github.com

Subscribe To Our Newsletter

Get updates and learn from the best

More To Explore

Windows Securitym Hackers Feeds

Don't Let "Nonsense" Erase ADHD Realities

Article URL: https://adhdreading.org/en Comments URL: https://news.ycombinator.com/item?id=45797210 Points: 1 # Comments: 0 Source: adhdreading.org

Windows Securitym Hackers Feeds

The Chessman (2008)

Article URL: https://time.com/archive/6683570/the-chessman/ Comments URL: https://news.ycombinator.com/item?id=45797199 Points: 1 # Comments: 0 Source: time.com

Do You Want To Boost Your Business?

drop us a line and keep in touch

We are here to help

One of our technicians will be with you shortly.