Scans git history too
A key committed once and 'removed' still lives in history. We check past commits, not just the current tree.
Hardcoded API keys, database passwords and tokens are a top cause of breaches. Nurbak's secret scanner finds them in your repository — including secrets left behind in git history. Scan a public repo free.
A key committed once and 'removed' still lives in history. We check past commits, not just the current tree.
The model tells a live Stripe or AWS key from an example placeholder, so you chase real leaks, not false alarms.
Each finding says what the secret unlocks and how to rotate it — not just a regex match.
Runs on our own model on ephemeral infra; your code and any secrets found are never sent to a third-party AI and aren't stored.
Enter a public repository as owner/repo.
We scan the code and git history on ephemeral infra.
The model classifies each candidate secret by type and risk.
You get the exposed secrets with rotation guidance.
Connect GitHub read-only to scan private repos.
Paste your repository above and run the scan. Nurbak checks the code and git history for hardcoded API keys, tokens, passwords and other credentials, free for public repos.
Yes. Secrets that were committed and later deleted remain recoverable in history, so we scan past commits as well as the current code.
The model distinguishes real, live-looking credentials from obvious placeholders and test values, so you focus on genuine leaks.
No. Analysis runs on ephemeral infrastructure with our own model; your code and any secrets found are deleted after the scan and never reach a third-party AI.
See which keys and credentials are exposed in your repo in minutes.
Scan my repo