Paste JavaScript, drop .js files, or fetch a URL. Find hidden API endpoints and exposed secrets. Free, no signup.
🔒 Paste and local-file parsing stay in your browser. Fetch URL contacts the specified server. The optional public relay sees the URL and fetched content - never route private or authenticated files through it.
Drop .js / .mjs / .map files here, or click to pick
Optional: import a HAR fileExport the Network tab from your browser DevTools after using the site. JSRecon adds the real request URLs it saw, which catches routes built at runtime. Runs locally; only URLs are read, with query values redacted.
Exposed secrets & keys
Endpoints
403-Bypass Variant Generator // new
Found an endpoint that answers 403? Generate the classic bypass variants (encoding, headers, path normalization, version fallback) as ready-to-run curl commands. This page only generates text - it sends nothing anywhere. Only test targets you are authorized to test.
Honest limits
Joined strings (a + b, template literals, simple constants) are now resolved in the same file. Values that come from other files, user input, the server or runtime logic stay unresolved and show as :name. A HAR import adds the requests your browser actually made, but only for pages and actions you exercised.
Regex + entropy heuristics. High-severity findings are worth a look, not proof - verify before you report anything. False positives happen; real secrets in minified bundles get missed too.
Findings are masked (prefix + length + suffix) so a screenshot of this page can't leak them further.
URL fetch depends on the target's CORS headers. Most sites block direct browser fetch - the relay option works around that, but only for public files.
This finds what is shipped to the browser. A key in front-end code is already public: rotate first, then remove.