KeyGuard — Is your app leaking API keys to anyone who opens DevTools?
A free 2-minute scanner from Global McLien Software Solutions that
checks any web app, PWA, or website for exposed API keys and
secrets visible in the browser's Network tab. Paste in a URL to
get a masked report of what was found and plain-English steps to
fix it — no login or install required.
How it works
- Paste in your website or app URL.
- KeyGuard checks the same public HTML and JavaScript any visitor's browser already downloads.
- Get a plain-English report: what was found (masked), how serious it is, and how to fix it.
Frequently asked questions
Is this legal / ethical?
Yes. We only request what your site already sends to any visitor's browser — the HTML and JavaScript files. We never log in, guess hidden paths, or use any key we find. You can also only scan sites you own or have permission to test.
Do you store the actual keys?
No. We only ever display a masked version (first/last few characters). Full values are never saved or transmitted anywhere else.
What if the scan finds nothing?
Great news — it means our pattern checks didn't spot anything obvious. It isn't a full security audit, so we'll offer a deeper manual review if you want extra peace of mind.
What happens with my email?
We'll send your report and occasional tips on keeping your app secure. Unsubscribe anytime.
Enable JavaScript to run the scanner, or email afeez20@gmail.com for a manual check.