KeyLeak Detector
Scan websites for exposed API keys and secrets
Details
- External ID
- 45786192
- Source
- HN
- Company
- —
- Product
- KeyLeak Detector
- Website domain
- github.com
- Launched
- Nov. 1, 2025
- Cohort
- —
- Upvotes
- 30
- Upvotes percentile
- 0.7521834061135371
- Tags
- —
- Fetched at
- Sept. 7, 2026, 9:25 p.m.
- Updated at
- Sept. 7, 2026, 9:25 p.m.
Description
I built this after seeing multiple teams accidentally ship API keys in their frontend code.The problem: Modern web development moves fast. You're vibe-coding, shipping features, and suddenly your AWS keys are sitting in a <script> tag visible to anyone who opens DevTools. I've personally witnessed this happen to at least 3-4 production apps in the past year alone.KeyLeak Detector runs through your site (headless browser + network interception) and checks for 50+ types of leaked secrets: AWS/Google keys, Stripe tokens, database connection strings, LLM API keys (OpenAI, Claude, etc.), JWT tokens, and more.It's not perfect, there are false positives but it's caught real issues in my own projects. Think of it as a quick sanity check before you ship.Use case: Run it on staging before deploying, or audit your existing sites. Takes ~30 seconds per page.MIT licensed, for authorized testing only.https://github.com/Amal-David/keyleak-detector
Enrichment
- Theme
- developer infrastructure and monitoring utilities
- Vertical
- Security
- Function
- Compliance & governance
- Audience
- B2B
- AI stance
- Not AI
- Project type
- Commercial product
- Normalized one-liner
- detect exposed api keys and secrets on websites
- Manually corrected
- False
Could you build this?
Yes A web scraper or crawler that inspects client-side HTML, JavaScript bundles, and source maps with regex patterns for common API keys (Stripe, AWS, OpenAI) is a standard utility readily vibe-coded.
Discussion
7 comments analyzed.
Competitors mentioned: Gitleaks, GitHub secret detection
Concerns raised: Gitleaks is more comprehensive for comparison, Runtime detection is limited compared to broader secret scanning, Underlying organizational/process problems are the real issue, Offensive security tools alone don't solve fundamental secret management flaws
Feature requests: Chrome plugin for runtime detection, CI/CD pipeline integration, Adversarial agent for vibe-coded apps
Competitors
Other products that read as similar to this one — 115 launches clear the similarity bar, closest 8 shown.
Attention rank: #29 of 116 (itself plus its competitors, highest first — normalized so YC and Product Hunt are compared fairly).
Looks like the first mover among its competitors.
- APIRadar – Open-Source API Key Scanner · ph · 2026-09-15 · 3 upvotes · similarity 0.49
- SecretEnv · hn · 2026-05-05 · 5 upvotes · similarity 0.46
- SendKey · ph · 2026-09-08 · 2 upvotes · similarity 0.46
- Open Passkey · hn · 2026-04-19 · 10 upvotes · similarity 0.45
- Shipcheck · ph · 2026-09-26 · 2 upvotes · similarity 0.42
- My agents are building a secure fork of OpenClaw · hn · 2026-02-13 · 9 upvotes · similarity 0.41
- BlindDrop · ph · 2026-09-18 · 2 upvotes · similarity 0.40
- KeyEnv · hn · 2026-01-18 · 5 upvotes · similarity 0.40
Other launches for this product
- No other launches for this product.
Same idea, different domain
Nobody's really built a compliance & governance tool for Media & entertainment yet.