Nicheloom

Market intelligence for builders — see what's gaining traction before it's crowded.

KeyLeak Detector

Scan websites for exposed API keys and secrets

Details

External ID
45786192
Source
HN
Company
—
Product
KeyLeak Detector
Website domain
github.com
Launched
Nov. 1, 2025
Cohort
—
Upvotes
30
Upvotes percentile
0.7521834061135371
Tags
—
Fetched at
Sept. 7, 2026, 9:25 p.m.
Updated at
Sept. 7, 2026, 9:25 p.m.

Description

I built this after seeing multiple teams accidentally ship API keys in their frontend code.The problem: Modern web development moves fast. You're vibe-coding, shipping features, and suddenly your AWS keys are sitting in a <script> tag visible to anyone who opens DevTools. I've personally witnessed this happen to at least 3-4 production apps in the past year alone.KeyLeak Detector runs through your site (headless browser + network interception) and checks for 50+ types of leaked secrets: AWS/Google keys, Stripe tokens, database connection strings, LLM API keys (OpenAI, Claude, etc.), JWT tokens, and more.It's not perfect, there are false positives but it's caught real issues in my own projects. Think of it as a quick sanity check before you ship.Use case: Run it on staging before deploying, or audit your existing sites. Takes ~30 seconds per page.MIT licensed, for authorized testing only.https://github.com/Amal-David/keyleak-detector

Enrichment

Theme
developer infrastructure and monitoring utilities
Vertical
Security
Function
Compliance & governance
Audience
B2B
AI stance
Not AI
Project type
Commercial product
Normalized one-liner
detect exposed api keys and secrets on websites
Manually corrected
False

Could you build this?

Yes A web scraper or crawler that inspects client-side HTML, JavaScript bundles, and source maps with regex patterns for common API keys (Stripe, AWS, OpenAI) is a standard utility readily vibe-coded.

Discussion

7 comments analyzed.

Competitors mentioned: Gitleaks, GitHub secret detection

Concerns raised: Gitleaks is more comprehensive for comparison, Runtime detection is limited compared to broader secret scanning, Underlying organizational/process problems are the real issue, Offensive security tools alone don't solve fundamental secret management flaws

Feature requests: Chrome plugin for runtime detection, CI/CD pipeline integration, Adversarial agent for vibe-coded apps

Competitors

Other products that read as similar to this one — 115 launches clear the similarity bar, closest 8 shown.

Attention rank: #29 of 116 (itself plus its competitors, highest first — normalized so YC and Product Hunt are compared fairly).

Looks like the first mover among its competitors.

Other launches for this product

Same idea, different domain

Nobody's really built a compliance & governance tool for Media & entertainment yet.