NullID public guide
Scan likely secrets before sharing
Secret Scanner reviews pasted text or supported text files for likely credentials. It is a local triage tool, not a token validation service.
What it flags
The scanner looks for JWTs, bearer tokens, private key blocks, GitHub, Slack, and AWS-style tokens, credential-like assignments, and optional high-entropy candidates.
How to use it
- Paste text, configuration, headers, or logs.
- Choose whether to include heuristic high-entropy candidates.
- Review finding type, confidence, evidence, reason, and preview.
- Apply local redaction or send findings into Text Redaction.
- Export a local scan report if you need review evidence.
Limitations
- Findings are pattern-based and do not prove a token is active.
- High-entropy candidates have a higher false-positive rate.
- Unusual credentials can be missed.
- Input remains in the current browser session until cleared or wiped.