# Live feed of leaked API keys on GitHub & GitLab — LeakWatch

> Every API key and secret our scanner finds in public GitHub, GitLab and Codeberg commits, updated in real time. Keys masked, repos never disclosed.

Source: https://leakwatch.net/leaks

---

[LeakWatch](/)

Sign in

Live

# Latest leaked keys

Every secret our scanner picks up across public GitHub and GitLab activity, as it happens. The list refreshes on its own, and each type is colored by the kind of provider it belongs to.

Only the provider prefix of each key is shown, and the repository is never disclosed — this page reports that leaks happen, it does not help anyone find them.

171,107

Secrets found since launch

4,523

In the last 24 hours

[

14

Key types in this feed

See the trends →

](/leaks/trends)

Right now this feed carries **JWT**, **HashiCorp Terraform Password**, **Telegram Bot API Token**, **Database Connection String** and **Groq API Key**, plus 9 other key types, spread across 6 provider families: databases, AI providers, cloud infrastructure, payment processors, messaging and email, private keys.

Key

Type

Source

Found

`eyJh••••••••••••••••`

JWT

GitHub

1 min ago

`8814••••••••••••••••`

Telegram Bot API Token

GitHub

2 min ago

`gsk_••••••••••••••••`

Groq API Key

GitHub

3 min ago

`Bear••••••••••••••••`

Generic Bearer Token

GitLab

3 min ago

`"Pis•••••••`

HashiCorp Terraform Password

GitHub

3 min ago

`rzp_••••••••••••••••`

Razorpay Key

GitHub

3 min ago

`8814••••••••••••••••`

Telegram Bot API Token

GitHub

5 min ago

`"adm••••••`

HashiCorp Terraform Password

GitHub

6 min ago

`fa21••••••••••••••••`

Generic High Confidence Secret

GitHub

6 min ago

`"yo0••••••`

HashiCorp Terraform Password

GitHub

6 min ago

Show 40 more

## What's leaking, by provider family

Share of detections over the last 30 days, grouped the same way as the feed above. [See the day-by-day evolution per provider →](/leaks/trends)

-   cloud infrastructure14%
-   messaging and email2%
-   developer platforms4%
-   other79%

Trending up this week

Deepgram · newOracle Cloud · newDocker Hub · +500%Mux · +400%Dropbox · +200%OpenAI · +175%

One of these could be yours

Sign in with GitHub, GitLab or Codeberg to see the leaks tied to your account — the repository, the commit, and how to revoke.

Check your account

## What to do when a key leaks

Every line above is someone's bad afternoon. These walk through what to do about it, and how the detection behind this feed works.

-   [One rule, one file: 381 self-contained YAML rules, and the false positive that slipped through](/blog/one-rule-one-file)
    
    How LeakWatch's secret-detection rules moved from five hand-synced Python tables to 381 self-contained YAML files, the test that reads them independently of the loader, and the Sourcegraph false positive that migration just caught.
    
-   [Tripling our secret scanner's recall: what the benchmark told us, and what we refused to fix](/blog/tripling-our-secret-scanner-recall)
    
    Recall 0.168 → 0.518 on Samsung's CredData: what the benchmark told us about regex + LLM secret detection, and the one promising idea we refused to ship.
    
-   [Deep scan: reading your entire git history, not just the last commit](/blog/deep-scan-your-whole-git-history)
    
    Why real-time monitoring can't see the key you leaked in 2021, and how LeakWatch's deep scan clones your repo, replays every commit on every ref, and does it without ever being able to touch someone else's code.
    
-   [Consuming the GitHub, GitLab and Codeberg firehose at scale: ETags, rate limits and dedup](/blog/consuming-the-firehose-at-scale)
    
    How LeakWatch ingests thousands of public commits per minute without knocking over the forges' APIs: ETag caching, a rotating token pool, circuit breakers, and distributed dedup via Redis.
    
-   [I accidentally pushed an API key to GitHub : here's exactly what to do](/blog/i-accidentally-pushed-an-api-key-to-github)
    
    A calm, step-by-step guide for when you just leaked a secret to a public repo: rotate first, clean history second, check for abuse third — with the exact commands and provider links.
    
-   [How LeakWatch's secret scanner works](/blog/how-leakwatch-secret-scanning-works)
    
    Inside the LeakWatch pipeline: ingesting the public commit firehose, 400+ regex patterns, heuristic and ML false-positive filtering, and strictly read-only secret validation.
    

Want this feed as JSON? The same detections are available through the [LeakWatch API](/docs) — search by account, pull recent leaks, or scan your own repositories.

© 2026 LeakWatch

[Blog](/blog)[API docs](/docs)[About](/about)[Privacy](/privacy)[Terms](/terms)[Contact](/contact)

LeakWatch

Secrets leak into public commits every minute. This watches the forges for yours. Built and run by [Gabriel Diyan](/about), a cybersecurity student — [why LeakWatch exists](/about).

Scan

-   [Product](/product)
-   [Live feed](/leaks)
-   [Trends](/leaks/trends)
-   [API docs](/docs)
-   [CI/CD](/docs?tab=ci)

Read

-   [Blog](/blog)
-   [Changelog](/changelog)
-   [About](/about)

Verify

-   [Security](/security)
-   [Privacy](/privacy)
-   [Terms](/terms)
-   [Legal](/legal)
-   [Contact](/contact)
-   [Status](https://status.leakwatch.net)

© 2026 LeakWatch

[GitHub](https://github.com/Leakwatch-Scan)[X](https://x.com/LeakwatchScan)
