Security & Compliance · Free

Check your website for exposed API keys

Eighty-two thousand dollars while you were asleep.

Run the free security checkRuns in about a minute · no card, no install

You find out on a Thursday. It is morning, you have got coffee going, and you open the billing console because you always open the billing console — it is a reflex more than a decision, the same way you check your phone at a red light. The number takes a second to parse. Not because it is big, but because your brain refuses it. You read it as $823.14. Then as $8,231. Then you count the digits one at a time with your finger on the screen like a child learning to read. $82,314.44. Your normal bill is $180 a month.

You sit there and do nothing for maybe forty seconds. Then you start moving very fast, and everything you do is correct, and none of it matters. You kill the key. You disable the Gemini APIs. You rotate every credential you can find. You force 2FA across the org. You lock IAM down until half your own team cannot deploy. You open a support case with your hands shaking slightly on the keyboard, and you write it carefully, professionally, because some animal part of your brain thinks that if you sound reasonable enough they will be reasonable back. Every one of those actions is the right action. Every one of them is about eighteen hours too late.

Because the thing already happened. Somewhere between Tuesday and Wednesday, while you were asleep, while you were eating dinner, while you were arguing with your co-founder about onboarding copy, a key you did not know was loose was pulling Gemini 3 Pro image generations in a loop. Thousands of them. Tens of thousands. Somebody found your credentials and turned them into a faucet, and the faucet ran for forty-eight hours in a data center that felt nothing about it. 455 times your normal usage. And not one system anywhere in that chain paused and said this looks insane.

You are probably here because

  • You have API keys that work in both dev and prod and you have not thought about them in months.
  • You integrated a third-party service quickly and never checked where the key ended up.
  • You have credentials in env files, CI variables, Slack messages, old deploy scripts or screenshots in tickets.
  • You received an unexpected usage or billing spike and do not know how it happened.
  • You are a small team and 'audit our credential surface' has never been the most urgent item on a Monday.

What the check looks at

  • Credentials, tokens and keys reachable in your shipped front-end code
  • Keys with excessive permission scope — master keys where a single-room key would do
  • Stale credentials that have not been rotated and may exist in places you have forgotten
  • Per-key spend caps and budget kill switches set on your side, not the provider's
  • Whether a stolen key would cause an incident or a catastrophe — and what scoping would change that

How it works

1

Paste your URL

No install, no repo access, no credit card. The check runs against your live site exactly as a visitor or crawler sees it.

2

Get a scored breakdown

Every dimension is scored and weighted, so you can see which single issue is costing you the most rather than staring at a flat list of warnings.

3

Keep the report

You get a shareable results link and a downloadable report you can hand to a developer, a client, or a buyer asking hard questions.

You did not make a dramatic mistake. That is the part people will not understand when you tell them. There was no reckless moment. Nobody pushed secrets to a public repo on a dare. You went looking for the obvious error and there was not one — which is somehow worse, because it means you cannot point to a thing and say well, I will not do that again. What you had was a key that existed too long, in too many places, with too much permission, watched by nobody. That is it. That is the whole vulnerability. It is not exotic. It is the default state of nearly every small company shipping right now. You need somebody whose entire function is to be paranoid on a schedule while you are busy building. Because you will never prioritize this yourself. Be honest. Security hygiene competes with shipping, and shipping wins every single week, forever, until the Thursday morning. A key that rotates every 30 days without anyone thinking about it caps your maximum exposure at 30 days. That is not clever. It is just plumbing. But plumbing only works when someone installs it and it runs whether or not anybody remembers it exists. And the caps have to be yours, not theirs. The platform will not save you. Your Visa declines a $400 gas station charge in another state. This platform watched you go from $180 a month to $82,000 in two days and processed every single request with perfect enthusiasm. So the ceiling has to be set on your side: per-key quotas, per-service budget kill switches, alerts that fire at 3x normal and hard-stop at 10x. Not a billing alert that emails you at 4am. A hard stop. An email that arrives at 4am is a notification of a disaster, not a prevention of one.

Run it on your own site

You get a score, the specific findings, and a report you keep — whether or not you ever talk to us.

Run the free security check

Questions

How do I check my website for exposed API keys myself?

Open developer tools, search the loaded source for your key's prefix, and look through your network requests. That catches the obvious cases. It misses keys in lazily-loaded chunks, inlined configuration and third-party bundles — and it does not find the copy sitting in your CI logs, the stale branch, the deploy script from last year or the Notion page. An external audit finds those because someone whose job is to hunt has a different set of eyes than the person who put them there.

What actually happens when an API key gets stolen?

Automated scanners crawl public code continuously. A key found at 2am is in use by 2:05am. In the case that prompted this page, the stolen key was used to run tens of thousands of Gemini 3 Pro image generations in a loop over forty-eight hours, producing a bill of $82,314.44 on a $180-a-month account. The provider cited the shared responsibility model and the team — three developers in Mexico — was left holding a bill that exceeded their bank account several times over.

Will the cloud provider refund me if my key is stolen?

Do not count on it. The phrase you will hear is shared responsibility model, which means your key, your problem. Fight it anyway — escalate past the account manager, keep your FBI report number in every message, get it in front of someone with discretionary authority, and do not accept the first three answers. People have gotten these reduced. Not always. Not reliably. But the ones it happens to are the ones who refused to go quietly.

What is the difference between an $82,000 event and a $400 event?

Whether the key that leaked was a master key or a house key to one room. Separate keys per service, per environment, per function, each with the minimum permission it needs. A stolen key should be able to do one small stupid thing, not everything you are capable of. Scoping is what turns a catastrophe into an incident.

Related free checks