UnLeak — Find Leaked API Keys in Your GitHub
Overview
Scan your own GitHub repos and old commits for leaked API keys and secrets. Runs locally. Nothing is uploaded.
Deleting a secret from your code does not remove it from your Git history. Anyone can still read it in an old commit. UnLeak scans your own repos and their history for real credentials, then shows you how to revoke each one. WHAT IT LOOKS FOR UnLeak recognizes 18 kinds of credentials, including cloud access keys, payment processor keys, AI service keys, messaging and email service tokens, database connection strings, and private key files. WHY IT IS DIFFERENT - Reads history, not just current code, a key you deleted last year still shows up. - Fewer false alarms, thanks to entropy and placeholder filtering. - Every finding comes with revoke steps for that provider, sorted by urgency. - Only scans repos you own. PRIVATE BY DESIGN Runs entirely in your browser. No UnLeak server. Your token stays in local Chrome storage and only ever talks to GitHub's API. Secrets are shown masked and never saved. No analytics or tracking. GET STARTED Install, click the icon, paste a read-only GitHub token (the link is built in), and hit Scan.
0 out of 5No ratings
Details
- Version1.0.1
- UpdatedAugust 6, 2026
- Offered byDavid Andree
- Size45.76KiB
- LanguagesEnglish (United States)
- Developer
Email
davidalvaradoc0106@gmail.com - Non-traderThis developer has not identified itself as a trader. For consumers in the European Union, please note that consumer rights do not apply to contracts between you and this developer.
Privacy
UnLeak — Find Leaked API Keys in Your GitHub has disclosed the following information regarding the collection and usage of your data. More detailed information can be found in the developer's privacy policy.
UnLeak — Find Leaked API Keys in Your GitHub handles the following:
This developer declares that your data is
- Not being sold to third parties, outside of the approved use cases
- Not being used or transferred for purposes that are unrelated to the item's core functionality
- Not being used or transferred to determine creditworthiness or for lending purposes
Support
For help with questions, suggestions, or problems, visit the developer's support site