Drop a folder here
or use the buttons below — a whole project directory works best
What it looks for
By filename or path — .env, *htpasswd*, *.pem, *.key, *.p12, *.pfx, *.crt, id_rsa*, id_ed25519*, *_rsa, *_ed25519, *credential*, *secret*, *token*, *oauth*, *client_secret*, *api_key*, *apikey*, *password*, *passwd*, *cookie*, access.log, *.sqlite, *.db, authorized_keys, known_hosts, KEYSDONOTDELETE*.
By folder name — anything inside secrets, .secrets, orders, customers, KEYSDONOTDELETE, or uploads under a private path.
By content (first 8 KB, files under 2 MB) — PEM private-key headers, AWS_SECRET_ACCESS_KEY, and assignments like api_key = … / client_secret: … / password=… where the value runs 16 characters or more.
Deliberately allowed — .env.example, .env.sample, .env.template, and UI routes such as ForgotPassword or reset-password. Placeholder values (changeme, your_…, example, <…>) and bare identifiers on the right-hand side are skipped, since stripe.api_key = stripe_key is code, not a leak. .git directories are ignored.
A hit means shaped like a secret, not proven to be one. It is a stop-and-look list, not a verdict.