Scan websites for exposed AI API keys and tokens, then verify which keys are still live.
Enter a URL to scrape for exposed API tokens.
Automatically search for exposed AI API tokens across paste sites and code repositories.
All unique keys ever collected, accumulated across every hunt (backfilled from historical findings) and kept across restarts. Click a column header to sort.
Which search queries produce the most keys, and the most productive domains. Aggregate counts only — no key values. Attribution grows as new keys are found (older keys have no recorded origin query).
Persisted query pool with per-query cycles-run and attributed keys. Zero-yield grown queries (run many cycles, 0 keys) are flagged for pruning. Base seed queries are never pruned. Removal is dry-run only unless auto-prune is enabled on the server.
Per-hunt telemetry snapshots (newest first), persisted across restarts. Watch the search 429 column: a value trending UP across successive hunts means the search backend is being throttled repeatedly — time to rotate or slow the query pool. One-off spikes in fetch 429 are just individual page rate-limits.
Probe collected keys against their provider to see which are still Active vs Revoked. These endpoints require the operator token.
Paste a raw key value, or give the DB id of a stored key.
Only keys verified Active against their provider. Click a column header to sort. Full token values require operator unlock.