Paste JavaScript, drop .js files, or fetch a URL. Find hidden API endpoints and exposed secrets. Free, no signup.
🔒 100% client-side. Your code never leaves this browser tab - no upload, no logging, no analytics on your input.
Drop .js / .mjs / .map files here, or click to pick
Exposed secrets & keys
Endpoints
403-Bypass Variant Generator // new
Found an endpoint that answers 403? Generate the classic bypass variants (encoding, headers, path normalization, version fallback) as ready-to-run curl commands. This page only generates text - it sends nothing anywhere. Only test targets you are authorized to test.
Honest limits
Regex + entropy heuristics. High-severity findings are worth a look, not proof - verify before you report anything. False positives happen; real secrets in minified bundles get missed too.
Findings are masked (prefix + length + suffix) so a screenshot of this page can't leak them further.
URL fetch depends on the target's CORS headers. Most sites block direct browser fetch - the relay option works around that, but only for public files.
This finds what is shipped to the browser. A key in front-end code is already public: rotate first, then remove.