Local-first · no keys uploaded · no account required

Stop a leaked key before it becomes an invoice.

Audit pasted code, provider restrictions and budget controls entirely in your browser. Get a prioritized containment plan in under a minute.

141public pages checked
24markets covered
25price or loss signals

THE PROBLEM

Alerts tell you the fire started. Hard controls keep it small.

Developers repeatedly report missing spend ceilings, browser-exposed keys and service-account abuse. Native controls are improving, but they differ by provider and can still leave gaps.

Abstract OpenAI risk surface symbol

OpenAI

Check public prefixes, client bundles, project limits and alert-only assumptions.

OpenAI key and project-control risk surface
Abstract Anthropic risk surface symbol

Anthropic

Spot exposed secret formats, local storage and unbounded development workflows.

Anthropic secret and spend-control risk surface
Abstract Google Gemini risk surface symbol

Google / Gemini

Review key restrictions, legacy Firebase exposure and residual service-account risk.

Google Gemini key-restriction risk surface
Illustrated solo builder profile
Solo builder checking a local prototype
Illustrated small team profile
Small team reviewing shared API controls
Illustrated operations profile
Operations owner validating budget safeguards

FREE LOCAL DIAGNOSTIC

Find the weakest link in your API bill controls.

Paste only code or configuration you are allowed to inspect. Analysis happens locally in this tab; nothing is transmitted.

  • No upload and no analytics tracker
  • Known secret prefixes are masked in the report
  • Exportable remediation plan

This is a security checklist, not a guarantee or provider-side kill switch.

CONTAINMENT, NOT PANIC

Rotate. Restrict. Cap. Revoke. Prove.

A useful response is ordered: stop exposure, remove old credentials, enforce provider restrictions, test the ceiling, then preserve an audit trail.

BUDGET BUFFER

Know how close you are to the line.

Model a conservative emergency buffer. This does not replace provider billing data, but it makes an alert-only setup visible.

PUBLIC EVIDENCE

Built from real losses, requests and counterevidence.

We do not claim every provider lacks controls. Google introduced spend caps and tightened unrestricted keys; self-hosted alternatives exist. The gap is consistent, low-ops protection across providers.

HONEST LIMITS

This scanner cannot shut down your provider account.

01

Static, local analysis

It detects risky patterns and configuration gaps, not live account activity.

02

Rotate exposed secrets

Masking a key in code is not enough. Revoke it at the provider.

03

Test native controls

Provider limits, delays and account behavior change. Verify them directly.

Make the next invoice boring.

Run the local scan now. Monitoring automation is in private beta and is not accepting payments yet.

Scan my setupJoin monitoring beta