Live Site Scanner

You built it fast.
Someone found what you missed.

Scan your live site for exposed API keys — and get exact, copy-paste fix instructions. Not just warnings.

Scan your live site
Free. No signup. Scans HTML, JS bundles, source maps, and public config files.
Fetching site resources...
Crawling JS bundles & source maps...
Running key pattern detection...
Building your report...
How it works

Scans like an attacker. Fixes like a teammate.

Most tools tell you there's a problem. We tell you exactly how to fix it — on your specific platform.

Step 01

Paste your URL

Drop in your live site URL. No signup needed for a one-time scan.

Step 02

We crawl everything

HTML, JS bundles, source maps, .env files left public, config objects — same paths an attacker would check.

Step 03

Keys detected instantly

50+ service patterns matched — Anthropic, OpenAI, Stripe, AWS, Firebase, Supabase, and more.

Step 04

Exact fix, your platform

Get copy-paste instructions for Cloudflare Pages, Vercel, Netlify, Replit, and more. Not generic advice.

Why this exists

The $187 lesson

$187

An API key got hardcoded into client-side JavaScript. Someone found it, scraped it from DevTools, and ran it. The bill showed up overnight.

The worst part? Every existing scanner catches exposed keys in GitHub repos. Nobody scans your live, deployed site — the version actually running in front of users. That's the gap.

Coverage

50+ services detected

Pattern-matched across every major API key format.

Anthropic Claude OpenAI Stripe AWS Firebase Supabase GitHub Twilio SendGrid Mailgun Slack Notion Airtable Pinecone Replicate HuggingFace Shopify Cloudflare Vercel Mapbox Algolia + more
Pricing

Start free. Stay protected.

One scan to find the problem. Monitoring to make sure it never comes back.

Free
$0
One-time scan, no account needed
  • Full site crawl
  • 50+ key patterns
  • Fix instructions included
  • 1 domain, 1 scan
Scan Now