API keys, database passwords, and access tokens sometimes end up inside HTML source code, JavaScript files, or JSON responses — accidentally left there by developers during testing or deployment. TruffleHog scans every page and script your server sends to the public.
It matches against 700+ known secret formats: AWS access keys, GitHub tokens, Stripe API secrets, Slack webhooks, private certificates, and more. A single exposed credential can give an attacker full access to your cloud infrastructure or third-party services — and you'd never know until it was too late.
700+ secret patterns
AWS / GitHub / Stripe
live HTTP scanning