keyleak-detector

runtime leak scanner

$ ./keyleak scan --target

Use throwaway bearer tokens or session cookies only. Authenticated scans help catch runtime leaks that appear after login.

Everything runs locally. Basic scan stays unauthenticated.

Enumerates subdomains (crt.sh + DNS) and crawls every page of the domain, then scans each one. This is an active scan — only run it against systems you own or are authorized to test.

›

WHAT IT CATCHES

Runtime secrets in JavaScript, API responses, headers, DOM config, authenticated pages, exposed files, and generated app bundles.

›

HOW IT WORKS

Uses Playwright and mitmproxy to inspect the running app locally, then returns a ship verdict with redacted proof, fix guidance, and a re-test command.

›

DETECTION COVERAGE

Detects AI provider keys, cloud credentials, SaaS tokens, database URLs, private keys, JWT/session leaks, direct object access hints, exposed files, security headers, admin endpoints, and attack-surface signals.