Secrets Scrubber
A secrets scrubber finds API keys, passwords, tokens, and personal details in pasted text and replaces each one with a labelled tag such as [AWS_KEY] or [EMAIL], so code and logs can be shared without exposing the original values.
Scanned live as you type. Nothing you paste leaves your browser.
How to remove secrets from logs and code
Paste your code or logs
Drop the file contents, config, or log output into the text box. Scanning starts immediately.
Review the findings
Each detected value is listed with its label, line number, and a masked preview so you can confirm what was caught.
Adjust what gets redacted
Uncheck a finding to put the original value back in the output, or toggle a whole category off to stop scanning for it.
Copy the cleaned text
Copy cleaned text puts the redacted version, with every kept secret replaced by its tag, on your clipboard.
Why use this tool
Labelled, not just blanked
Each redacted value is replaced with a tag naming what it was, like [PASSWORD] or [JWT], so a reviewer can still see the shape of the data without seeing the value.
Four detection categories
Keys and passwords, personal info, IP addresses, and random-looking strings can each be toggled on or off, and the text re-scans instantly when you change one.
Undo any single finding
Every finding has its own checkbox. Uncheck one to keep that exact value in the cleaned output, for cases where a match is actually fine to share.
Line numbers and masked previews
The findings list shows which line each value came from and a short, partial preview, never the full secret, so you can confirm a match before trusting the result.
Built for large pastes
Scanning is debounced so a long log file stays responsive while you type, and the input and output both scroll instead of growing the page.
Nothing leaves your browser
The text you paste, and every secret found in it, stays on your device. Nothing is uploaded or logged.
About this tool
This tool scans pasted code, configuration files, or server logs for values that should not be shared and replaces each one with a labelled tag. It recognises common formats for API keys, access tokens, passwords in connection strings, authorization headers, private keys, emails, phone numbers, card numbers, IP addresses, and long random-looking strings that look like an unrecognised key format. A JSON web token is caught the same way, by its own tag, rather than being flattened into a generic match.
The findings list shows exactly what was caught: a label, the line it came from, and a short masked preview, so you can check the tool found the right thing before you trust the cleaned text. Unchecking a finding puts that exact value back in the output, which matters when a match is actually safe to share, such as a placeholder that happens to look like a key. The four detection categories can also be turned off as a group, for cases like log output full of internal IP addresses that do not need redacting.
Everything runs on your device, so pasting a real log file or a config with live credentials never sends that data anywhere. Once a file is clean, a generator can produce a fresh credential to replace a key that was exposed, and this converter is useful for turning the cleaned config back into a structured format before it goes into version control.
Frequently asked questions
- How does the tool decide what counts as a secret?
- It checks the text against known formats for API keys, tokens, passwords, private keys, authorization headers, emails, phone numbers, card numbers, IBANs, IP addresses, and strings with enough randomness to look like an unrecognised key. Values that cannot be shaped-matched this way are not caught, so a quick review of the findings list before copying is worth doing on anything sensitive.
- Is the text I paste uploaded anywhere?
- No. Scanning, redaction, and the findings list are all computed on your device. The text you paste, and every value found in it, is never sent to a server, stored, or logged.
- What kind of input works best?
- Any plain text: source code, .env files, YAML or JSON config, and raw server or application logs. The tool works on the pasted text directly, so formatting like indentation and line breaks is preserved in the cleaned output.
- Can I keep a specific match instead of redacting it?
- Yes. Uncheck any finding in the list and its original value is put back in the cleaned output instead of the tag. This resets whenever the text or the detection categories change, since the findings themselves change too.
- Is there a limit on how much text I can scan?
- No fixed limit. Scanning is debounced so a large paste stays responsive while you type, and both the input and the cleaned output scroll instead of stretching the page.
Related tools
JWT Decoder
Decode a JSON Web Token and optionally verify its signature, right in your browser.
Password Generator
Create strong random passwords or memorable passphrases, with control over length, characters, word count, and bulk output.
Env to JSON Converter
Convert a .env file of KEY=value lines to a JSON object, or turn a JSON object back into KEY=value lines, with quoted and multi-line values handled correctly.
CSV Anonymizer
Detect personal columns in a spreadsheet and replace them with consistent fake data.
Metadata Stripper
Drop photos, PDFs, audio, or video and get clean copies back, with a list of the GPS location, device, and dates each file was carrying.
Redaction Checker
Drop a redacted PDF to find text still hiding under black boxes, redactions never applied, comments, metadata, and old versions, then download a safe copy.