Ever Pasted a Screenshot and Realized Your API Key Was In It?
Yeah. Everyone’s done this at least once. One key sitting in a screenshot or a copy-pasted config, and it’s out there — even if you delete the post two seconds later, someone already grabbed it.
So I made a tiny tool for that exact moment.
paste your text
↓
it scans it
↓
finds the key/password
↓
blacks it out
↓
you copy the CLEAN version
↓
post that instead
It knows what OpenAI, GitHub, AWS, Google, Nvidia, and Hugging Face keys look like, plus general stuff like password= or token= — not just one company’s format.
Runs right in your browser, nothing gets uploaded anywhere. Sending your secret somewhere else just to check if it’s a secret would kind of defeat the point.
It’s not psychic — it can miss stuff, so still give the cleaned text a once-over yourself before you post.
And if a real key already got posted somewhere: don’t just delete the post, that doesn’t undo it. Go make a new key instead — the old one’s already burned.
!