LeakWatch LogoLeakWatch
secrets detected since launch

Your secrets are public. Find them first.

LeakWatch listens to every public commit on GitHub, GitLab and Codeberg and flags exposed API keys, tokens and credentials within seconds. Scan your username free — your code is never stored.

Free scan · read-only · nothing stored
example/billing-worker · config/deploy.ymlcritical

AKIA3NF83FJ384FT

Key still valid at provider
AWS access keydetected 4s after push

Deep scan
Every key you ever committed — not just the ones still there
Deleting a secret from a file does not remove it from your git history. A deep scan clones your repository and replays every commit on every branch, including the branches you abandoned years ago.
The full history, back to the first commit
All branches and tags, not just the default one
Your own repositories only — ownership is verified
Signing in is what proves the repository is yours.
Free plan
One deep scan every 30 days.
Paid plans
Unlimited deep scans, plus continuous monitoring of new commits.

How it works
01
Continuous monitoring
We continuously scan public GitHub, GitLab and Codeberg repositories for exposed secrets and securely index detected leaks.
02
Instant lookup
Enter your GitHub, GitLab or Codeberg username to instantly check whether any leaks linked to your account have already been detected.
03
Unlock full protection
Subscribers see exactly where leaks were found and enable continuous monitoring of their public repositories with real-time alerts.

Detection engine

Built to catch what others miss

Every match is tested against the provider. A pattern only says a string looks like a key. We ask the provider whether it still opens the door.

Stripe live secret keystill valid
GitHub personal access tokenalready revoked
AWS access keystill valid

Read as they land. Public commits on GitHub, GitLab and Codeberg are scanned within seconds of being pushed — not on a nightly sweep.

firehose · live
push a3f9c21 → scanned clean
push 7b1e004 → scanned clean
push c04d2f8 → 1 secret
push 19ab7cc → scanned clean

400+ patterns. Cloud, payments, databases, CI tokens.

AKIA… aws
sk_live_… stripe
ghp_… github
xoxb-… slack
SG.… sendgrid

False positives filtered. A classifier reviews every match before it reaches you.

Real keyalerted
Test fixturedropped
Example in docsdropped

Your code is never stored. Only the matched value and enough context to act on it.

kept · the matched secret
kept · repo, commit, date
discarded · the file
discarded · the repository

Stop leaks in their tracks

Detect and block secrets
before they spread

Initial commita1b2c3d
A developer pushes code to a public repository. Everything looks clean.
Setup projecte4f5g6h
Config files, environment setup, dependencies. Business as usual.
Add API keyx7y8z9aLeak detected
A live secret slips into the commit. LeakWatch flags it within seconds and alerts you instantly.
API_KEY = "sk-live-4f9a•••••••••••"
Revoke keyb1c2d3eSecured
Alert received, key rotated and revoked — before anyone could exploit it.

Pricing

Continuous secret monitoring

The one-off scan is free. Upgrade to continuous monitoring to be alerted to every new leak.

Free
0€
Forever
Access to affected repositories
Leaks type and severity
One deep scan every 30 days
No detailed commit history
No continuous monitoring
MOST POPULAR
Solo
4.99€/month
1 user · billed monthly, cancel anytime
Continuous monitoring
Real-time email / discord / slack alerts
Full commit history
Secret validation & dismissal
Unlimited deep scans
Launch pricing