secret-scanner
Detects leaked Cloudflare API tokens in code or diffs to prevent accidental exposure.
Detects leaked DigitalOcean API tokens in code or diffs to prevent accidental exposure.
Detects leaked Discord bot tokens in code or diffs to prevent accidental exposure.
Detects leaked GitHub tokens (e.g., ghp_, fine-grained) in code or diffs to prevent accidental exposure.
Detects leaked Google API keys (e.g., AIza..., GOCSPX-...) in code or diffs to prevent accidental exposure.
Detects leaked Mailgun API keys in code or diffs to prevent accidental exposure.
Detects leaked MongoDB connection strings (e.g., mongodb+srv:// with embedded passwords) in code or diffs to prevent accidental exposure.
Detects leaked MySQL connection strings (e.g., mysql:// with embedded passwords) in code or diffs to prevent accidental exposure.
Detects leaked npm tokens (e.g., npm_...) in code or diffs to prevent accidental exposure.
Detects leaked OpenAI API keys (e.g., sk-...) in code or diffs to prevent accidental exposure.
Detects leaked PyPI tokens in code or diffs to prevent accidental exposure.
Detects leaked Redis connection strings (e.g., redis:// with embedded passwords) in code or diffs to prevent accidental exposure.
Detects leaked SendGrid API keys in code or diffs to prevent accidental exposure.
Detects leaked Shopify API keys in code or diffs to prevent accidental exposure.
Detects leaked Slack tokens (e.g., xox...) in code or diffs to prevent accidental exposure.
Detects leaked Square API keys in code or diffs to prevent accidental exposure.
Detects leaked Stripe API keys (e.g., sk_live_...) in code or diffs to prevent accidental exposure.
Detects leaked Telegram bot tokens in code or diffs to prevent accidental exposure.
Detects leaked Twilio API keys in code or diffs to prevent accidental exposure.
Detects leaked HashiCorp Vault tokens in code or diffs to prevent accidental exposure.
Click on "Install Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@secret-scannerscan this code change for secrets"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
secret-scanner 🔐
Catch leaked secrets in a diff/file before you commit, push or open a PR.
secret-scanner scans a blob of code, text or a unified git diff for leaked secrets and returns a CLEAN / REVIEW / LEAK verdict. Every finding includes the secret type, provider, severity and line:column, a masked excerpt (the full secret is never echoed), and a remediation note.
Detection is 100% local — the content you scan is never sent anywhere.
MCP server for Claude / Cursor / any agent:
npx -y secret-scanner-mcpPay-per-call x402 API:
POST /pro/scan($0.02 USDC on Base, no sign-up)Free HTTP API:
POST /scan(rate-limited)
What it catches
Category | Examples |
🔑 Provider keys | AWS ( |
📜 Private keys | RSA / EC / DSA / OpenSSH / PGP / encrypted private-key blocks, GCP service-account JSON |
🗄️ Connection strings |
|
🎫 Tokens | JWTs, generic |
🎲 Unknown secrets | high Shannon-entropy base64/hex blobs that look like credentials even without a known prefix |
Related MCP server: credential-free
MCP server (free)
{
"mcpServers": {
"secret-scanner": { "command": "npx", "args": ["-y", "secret-scanner-mcp"] }
}
}Tool: scan_for_secrets — params content (string, required), deep (boolean, optional; adds offline format-validity hints).
Or connect over HTTP at POST /mcp (free).
HTTP API
# Free (rate-limited 30/h/IP)
curl -X POST https://secret-scanner.vercel.app/scan \
-H 'content-type: application/json' \
-d '{"content":"AWS_KEY=AKIAIOSFODNN7EXAMPLE"}'
# Paid, deep, unlimited (x402 — agent pays $0.02 USDC automatically)
curl -X POST https://secret-scanner.vercel.app/pro/scan \
-H 'content-type: application/json' \
-d '{"content":"<your diff>"}'Example response:
{
"verdict": "LEAK",
"score": 80,
"summary": "1 potential secret(s) across 1 line(s): AWS×1. Verdict LEAK.",
"lines": 1,
"findings": [
{
"rule": "aws-access-key-id",
"title": "AWS Access Key ID",
"provider": "AWS",
"severity": "high",
"line": 1,
"column": 9,
"match": "AKIA…MPLE (20 chars)",
"remediation": "Rotate the IAM key immediately in the AWS console and remove it from history."
}
],
"meta": { "deep": false, "bytes": 28, "truncated": false, "rulesEvaluated": 35, "entropyFindings": 0 }
}Why pay-per-call?
The free tier is rate-limited. The /pro/scan route is gated by x402: your agent pays $0.02 USDC per call on Base automatically — no account, no API key. It settles on-chain to the operator's receiving wallet. Deep mode adds offline structural-validity hints for formats whose shape can be verified without any network call.
Privacy
The scan runs in-process. The content you submit is not stored and not forwarded to any third party. Secrets in findings are always masked (AKIA…MPLE (20 chars)), never returned in full.
License
MIT
Available Tools
1 toolscan_for_secretsA
Scan a blob of code, text, or a unified diff for LEAKED SECRETS before you commit, push, open a PR, or paste it somewhere. Detects provider API keys (AWS, GitHub, OpenAI, Anthropic, Stripe, Google, Slack, Twilio, SendGrid, npm, Telegram, Discord, Shopify, Cloudflare and more), generic tokens, private keys (RSA/EC/DSA/OpenSSH/PGP), JWTs, database connection strings with passwords, basic-auth URLs, and high-entropy strings that look like credentials. Returns a CLEAN / REVIEW / LEAK verdict with each finding's secret type, provider, severity, line:column, a MASKED excerpt (never the full secret), and a remediation note. Use this on every diff/file you are about to share. The scan is fully local — the secret is never sent anywhere.
| Name | Required | Description | Default |
|---|---|---|---|
| content | Yes | The code/text/diff to scan for secrets. | |
| deep | No | When true, adds an offline structural validity hint (valid_format / invalid_format) for formats whose shape can be checked without any network call. No secret is ever transmitted. |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
No annotations are provided, so the description carries the full burden. It fully discloses the scan is local and secret never transmitted. It details output components: verdict, secret type, provider, severity, line:column, masked excerpt, remediation note. This is comprehensive and honest.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is a single paragraph of 5 sentences, efficiently front-loaded with the main action and use cases. Each sentence adds value: examples, output description, usage instruction, privacy note. Slightly lengthy but not wasteful.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Given the tool's complexity, no output schema, and no annotations, the description covers purpose, detected secrets, output details, privacy, and usage. It lacks explanation of the 'deep' parameter's behavior, which is only in schema. Otherwise, it is sufficiently complete.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema has 100% description coverage, so baseline is 3. The tool description does not add extra meaning to parameters beyond the schema; it focuses on overall behavior. Thus, no additional value for parameter semantics.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly states the tool scans code/text/diff for leaked secrets and lists many detectable types. It specifies use cases before commits, pushes, PRs, or pasting. This is specific, verb+resource-driven, and distinguishes it from any general text scanner.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
Explicitly tells when to use: before commit, push, PR, or pasting. The instruction 'Use this on every diff/file you are about to share' is clear. No explicit when-not-to-use or alternatives are mentioned, but the given context is sufficient.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
Tool Schema Changelog
Recent tool additions, removals, and schema changes observed during successful MCP inspections. Dates show when Glama detected each change.
1 tool update
v0.1.1- First observed
scan_for_secrets
TDQS
Only one tool exists, so there is no risk of confusion or overlap between tools.
With a single tool, naming is trivially consistent; the name 'scan_for_secrets' clearly describes its action.
A single tool for a focused purpose like secret scanning is reasonable, though additional tools for repository scanning or configuration could be expected for broader coverage.
The tool comprehensively scans various secret types and provides detailed findings, but lacks capabilities like scanning entire repositories or managing ignore lists, which are minor gaps.
Maintenance
Related MCP Connectors
Scan configs, files, or text for leaked secrets and obvious misconfigurations. Nothing stored.
Deep security scans of repos you own from your editor: dependency CVEs, SAST, git-history secrets.
Risk-scan a diff, flag AI-generated-code tells, find secrets. 5 of 7 tools need no account.
Generate SBOMs, scan vulnerabilities, and analyze dependencies from local projects or Git repos.
Related MCP Servers
- AlicenseNot gradedqualityNot gradedmaintenanceEnables security scanning of code projects to identify common vulnerabilities like XSS, injections, SSRF, and path traversal issues. Provides local, offline scanning with severity-grouped results and actionable fix suggestions for improving code security.38-
- AlicenseNot gradedqualityCmaintenanceScans code for exposed secrets, API keys, tokens, and credentials across 69 patterns covering cloud services, AI platforms, payment providers, authentication services, and databases.MIT
- AlicenseAqualityFmaintenanceEnables scanning projects for leaked secrets and security issues directly from Claude Code, detecting secret categories, dangerous code patterns, and git hygiene issues.21MIT
- FlicenseNot gradedqualityCmaintenanceScans repositories for owner identifiers and secrets, blocking pushes or CI merges if any are found.-
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/Baneado98/secret-scanner'
If you have feedback or need assistance with the MCP directory API, please join our Discord server