apexdrift

Exposed Secret Scanner

Paste hostnames — ideally the assets your attack-surface scan turned up — and this pulls their JavaScript and public files, then scans for leaked API keys, tokens, and credentials.

Only scan assets you are authorised to assess. Findings are matched, not verified — confirm a secret is live before reporting.