Item logo image for KeySpotter – Exposed API Key Finder

KeySpotter – Exposed API Key Finder

ExtensionDeveloper Tools2 users
Item media 4 (screenshot) for KeySpotter – Exposed API Key Finder
Item media 1 (screenshot) for KeySpotter – Exposed API Key Finder
Item media 2 (screenshot) for KeySpotter – Exposed API Key Finder
Item media 3 (screenshot) for KeySpotter – Exposed API Key Finder
Item media 4 (screenshot) for KeySpotter – Exposed API Key Finder
Item media 1 (screenshot) for KeySpotter – Exposed API Key Finder
Item media 1 (screenshot) for KeySpotter – Exposed API Key Finder
Item media 2 (screenshot) for KeySpotter – Exposed API Key Finder
Item media 3 (screenshot) for KeySpotter – Exposed API Key Finder
Item media 4 (screenshot) for KeySpotter – Exposed API Key Finder

Overview

Warns you when a website exposes secret API keys or test-mode payment keys, scanning locally as you browse.

Websites sometimes ship secret keys to every visitor by mistake. A forgotten line in a script bundle, a settings object or a response from the site's own backend can hand out access that was meant to stay private. A live shop still running on test-mode payment keys is a quieter version of the same slip: it may let people check out without paying. KeySpotter looks for these slips while you browse. It checks the source code, the scripts that were loaded, browser storage and the responses the page receives from its backend, then scores each finding by how likely it is to be real. A small alert appears in the corner only at 90% confidence or higher, once per finding on each site. You can mute any site with one click. The full report explains what each finding means, how serious it is and how to fix it. You can copy a short, masked note for the site owner, so the problem gets reported without repeating the secret. Detection covers providers such as OpenAI, Anthropic, Stripe, AWS and GitHub, along with many others. Privacy comes first. Scanning happens inside your browser. KeySpotter never sends a found key anywhere, never tests a key against any service, and has no analytics, accounts or servers. To scan scripts, it downloads them once more; cookies are sent only to the website you are on, and redirects and private-network addresses are refused. Source maps and security.txt are requested only when you click. Scan results, including found values, are deleted when you close the tab. Made by Tahir Nazir.

Details

  • Version
    0.1.0
  • Updated
    October 8, 2026
  • Size
    434KiB
  • Languages
    English
  • Developer
    Tahir Nazir
    Chak Baig Wazirabad 52000 PK
    Website
    Email
    hello@its-tahir.com
    Phone
    +92 348 4441893
  • Trader
    This developer has identified itself as a trader per the definition from the European Union and committed to only offer products or services that comply with EU laws.

Privacy

Manage extensions and learn how they're being used in your organization

KeySpotter – Exposed API Key Finder has disclosed the following information regarding the collection and usage of your data. More detailed information can be found in the developer's privacy policy.

KeySpotter – Exposed API Key Finder handles the following:

Authentication information
Website content

This developer declares that your data is

  • Not being sold to third parties, outside of the approved use cases
  • Not being used or transferred for purposes that are unrelated to the item's core functionality
  • Not being used or transferred to determine creditworthiness or for lending purposes

Support

For help with questions, suggestions, or problems, please open this page on your desktop browser

Google apps