Secret & Credential Scanner
Upload files or a .zip of a project and find hard-coded credentials: cloud and API tokens, private keys, passwords inside connection strings, and password = "..."-style values in code and config. Placeholders such as ${DB_PASSWORD} or os.environ[...] are ignored. Found values are masked in the report, so you can share it safely. Binary files, .git and node_modules are skipped.