Gitleaks Cloud - GitHub API Key Hunter & Secret Scanner MCP server
Gitleaks Cloud - GitHub API Key Hunter & Secret Scanner
2 stars
Reviews
Write oneNobody has reviewed Gitleaks Cloud - GitHub API Key Hunter & Secret Scanner yet.
If you have run it, two minutes of your experience saves the next person an afternoon.
Gitleaks Cloud - GitHub API Key Hunter & Secret Scanner tools
Tool list not cached yet. `describe` through the gateway fetches it live.
Public scan report
scanner v0.1.9 · 2026-09-24 · same rubric, same numbers if you re-run it
- –Code scanremote-only server, no package to scann/a
- Live reliabilityremote reachable in 9ms (auth required)20/20
- –Tool poisoningtools not inspected (endpoint requires auth); not countedn/a
- Auth qualityOAuth resource metadata advertised on 40115/15
- Maintenancelast push 0 days ago15/15
- Maintainer identityregistry namespace matches repository owner; GitHub account older than a year8/10
What the publisher says
From the Gitleaks Cloud - GitHub API Key Hunter & Secret Scanner repository's README, as published. We do not edit it. Read it on GitHub
Gitleaks Cloud - GitHub API Key Hunter & Secret Scanner
Cloud-hosted gitleaks for hunting leaked API keys, tokens, and credentials across GitHub - 30+ services including Indian fintech.
Available as an Apify Actor. Pay-per-event. The lightweight cheaper tier; sibling betterleaks-cloud adds live vendor-API validation.
What does it do?
Scans a GitHub user, org, or repo for leaked API keys and credentials across 30+ critical services: Razorpay, Stripe, AWS, OpenAI, Anthropic, Gemini, Supabase, Firebase, GitHub PATs, Twilio, SendGrid, Slack, Discord, Telegram, plus Indian fintech APIs (Cashfree, PayU, Surepass, Decentro, Karza, Attestr, Tartan). Smart key-secret pairing detects related credentials in the same file (e.g., Razorpay's two-part keyid + keysecret).
How is it different from running gitleaks CLI locally OR GitGuardian / Snyk Code subscriptions?
Tested on real Indian fintech repos: 47 razorpay-named GitHub repos scanned, 22 had leaks, 4 had production credentials in .env files including paired keyid + keysecret.
When should I use it?
- DevSecOps - scan your own org for accidental commits of secrets
- Bug bounty - hunt for live credentials in customer-facing public repos
- Pre-acquisition security audit - check target company's open-source posture
- Indian fintech compliance - sweep for Razorpay / Cashfree / PayU keys before regulator audit
- Cheap secret-scanner alternative to GitGuardian / Snyk for low-volume use
What does it cost?
Pay-per-event:
Typical scan costs
- Single repo: $0.03
- 10-repo scan: $0.21
- 100-repo bulk scan: $2.01
Which inputs does it take?
What does the output look like?
Each dataset record:
{
"rule_id": "razorpay-key-id",
"match": "rzp_live_AbCdEfGhIjKlMn",
"secret": "rzp_live_AbCdEfGhIjKlMn",
"paired_secret": "9p8q7r6s5t4u3v2w1x0y",
"file": "config/.env",
"line": 12,
"commit": "abcd1234",
"url": "https://github.com/owner/repo/blob/abcd1234/config/.env#L12"
}Common questions
Q: Need live validation that the leaked key still works? Use sibling betterleaks-cloud instead - it probes vendor APIs to confirm key status.
Q: Service detector missing? DM LinkedIn for 1-2 hour custom detector addition. Specific Indian fintech APIs are a specialty.
Q: Can I scan a private repo? Yes, provide a GitHub PAT with repo scope as github_token input.
About the maintainer (priority response within 1-2 hours)
Built and maintained by Anshuman Atrey (@AnshumanAtrey).
Shortened. The full README is on GitHub.
Nothing above is checked by us. What we check is on the safety report.
Install directly
claude mcp add --transport http gitleaks-github-secret-scanner https://mcp.apify.com/?tools=anshumanatrey/gitleaks-github-secret-scanner
Gitleaks Cloud - GitHub API Key Hunter & Secret Scanner: common questions
- Is Gitleaks Cloud - GitHub API Key Hunter & Secret Scanner MCP server safe?
- Yes, by our scan: it is graded A (97/100). Read the Gitleaks Cloud - GitHub API Key Hunter & Secret Scanner safety report
- How do I install Gitleaks Cloud - GitHub API Key Hunter & Secret Scanner?
- It runs remotely at mcp.apify.com. Add it to Claude Code, Claude Desktop or Cursor with the snippets above, or call it through the mcp.market gateway without installing anything.
- Does Gitleaks Cloud - GitHub API Key Hunter & Secret Scanner need an API key?
- No key to paste: it signs you in with OAuth when your client connects.
- Is Gitleaks Cloud - GitHub API Key Hunter & Secret Scanner maintained?
- The last commit was in the last day (2026-09-24). The latest release is v0.17.2.
- Is Gitleaks Cloud - GitHub API Key Hunter & Secret Scanner up?
- 100% of our last 1 checks got an answer. We check remote servers about four times a day.
- What can I use instead of Gitleaks Cloud - GitHub API Key Hunter & Secret Scanner?
- Servers from other publishers that do the same job: Oci MCP server, GitHub MCP server and TerraVision MCP server. Compare all Gitleaks Cloud - GitHub API Key Hunter & Secret Scanner alternatives.
Alternatives to Gitleaks Cloud - GitHub API Key Hunter & Secret Scanner
Same job from other publishers: the closest match first, then the best rated.
- OciOracle Cloud discovery + Terraform generation for AI agents — read-only, secret-safe.not reviewedGrowingA
- GitHubConnect AI assistants to GitHub - manage repos, issues, PRs, and workflows through natural language.not reviewedEstablishedA
- TerraVisionCloud architecture diagrams generated from terraform plan, with official AWS, Azure, GCP iconsnot reviewedEstablishedA
uploads.shHost files from coding agents; stage on a branch and attach to GitHub PRs.not reviewedEstablishedA- Cloud FinOps Skill & MCPCloud cost + FinOps knowledge for AI agents: AWS/Azure/GCP optimisation, AI spend, waste playbooks.not reviewedEstablishedB