Find hardcoded credentials in a codebase, and never print one into the report
- ✓Open-source license (MIT)
- ✓Actively maintained (<30d)
- ✓Clear description
- ✓Topics declared
- ✓Documented (README)
claude mcp add secrets-le -- npx -y secrets-le-mcp{
"mcpServers": {
"secrets-le": {
"command": "npx",
"args": ["-y", "secrets-le-mcp"]
}
}
}Resumen de MCP Servers
<p align="center">
<img src="src/assets/images/icon.png" alt="Secrets-LE Logo" width="96" height="96"/>
</p>
<h1 align="center">Secrets-LE: Zero Hassle Secret Detection</h1>
<p align="center">
<b>Find hardcoded credentials across your workspace, then redact them in place</b><br/>
<i>API keys, tokens, passwords, private keys — 100% local, nothing leaves your machine</i>
</p>
<p align="center">
<a href="https://marketplace.visualstudio.com/items?itemName=nolindnaidoo.secrets-le">
<img src="https://img.shields.io/badge/Install%20from-VS%20Code-blue?style=for-the-badge&logo=visualstudiocode" alt="Install from VS Code Marketplace" />
</a>
<a href="https://open-vsx.org/extension/OffensiveEdge/secrets-le">
<img src="https://img.shields.io/open-vsx/dt/OffensiveEdge/secrets-le?style=for-the-badge&label=Open%20VSX&color=blue" alt="Open VSX downloads" />
</a>
<a href="https://www.npmjs.com/package/secrets-le-mcp">
<img src="https://img.shields.io/npm/v/secrets-le-mcp?style=for-the-badge&label=MCP%20server&color=blue&logo=npm" alt="secrets-le-mcp on npm" />
</a>
<a href="https://crates.io/crates/secrets-le">
<img src="https://img.shields.io/crates/v/secrets-le?style=for-the-badge&label=Rust%20CLI&color=blue&logo=rust" alt="secrets-le on crates.io" />
</a>
<a href="https://letools.dev/tools/secrets-le">
<img src="https://img.shields.io/badge/LE%20Tools-letools.dev-blue?style=for-the-badge" alt="LE Tools" />
</a>
</p>
---
<p align="center">
<img src="src/assets/images/demo.gif" alt="Secrets-LE Demo" style="max-width: 100%; height: auto;" />
</p>
> **Useful?** A star or rating is how other developers find it —
> [★ GitHub](https://github.com/nolindnaidoo/secrets-le) ·
> [★ Open VSX](https://open-vsx.org/extension/OffensiveEdge/secrets-le/reviews) ·
> [★ Marketplace](https://marketplace.visualstudio.com/items?itemName=nolindnaidoo.secrets-le&ssr=false#review-details)
## What it does
Open a workspace, press `Ctrl+Alt+S` (`Cmd+Alt+S` on Mac), and every detected secret lands in a results document — grouped by file, with line/column positions pointing at the value itself. Run `Secrets-LE: Sanitize Secrets` to replace the secrets in the active file with a placeholder. Works in VS Code and in VS Code–based editors like Cursor and VSCodium (installable from Open VSX).
Detection is regex-based over the full text of each file, so it works on any text format — code, configs, `.env` files, YAML, JSON, logs. It is a pre-commit safety net, not a guarantee: a scanner built on patterns can miss secrets and can flag non-secrets. Review the results.
## Install
| Where | What you get | Install |
|---|---|---|
| **VS Code** | Detection and in-place sanitising, in your editor | [Marketplace](https://marketplace.visualstudio.com/items?itemName=nolindnaidoo.secrets-le) |
| **Cursor, VSCodium, Windsurf** | The same extension | [Open VSX](https://open-vsx.org/extension/OffensiveEdge/secrets-le) |
| **A terminal or a CI step** | The same run over a whole tree, with exit codes | `cargo install secrets-le` · [crates.io](https://crates.io/crates/secrets-le) |
| **Any MCP agent, via Node** | `detect_secrets` over stdio | `npx secrets-le-mcp` · [npm](https://www.npmjs.com/package/secrets-le-mcp) |
| **Zed** | The MCP server as a context server | [add it by hand](https://zed.dev/docs/ai/mcp) *(no listing yet)* |
## Use it from an AI agent
The same engine runs as an [MCP](https://modelcontextprotocol.io) server, so an agent can call it directly instead of you running a command.
| Editor | How |
|---|---|
| **VS Code** 1.101+ | Nothing to install — the extension registers `detect_secrets` with agent mode |
| **Zed** | No listing yet — [add the MCP server by hand](https://zed.dev/docs/ai/mcp) |
| **Claude Code** | `claude mcp add secrets-le -- npx -y secrets-le-mcp` |
| **Cursor, Windsurf, anything else** | point it at `npx secrets-le-mcp` |
```
detect_secrets(content, sensitivity?, includeApiKeys?, includePasswords?, includeTokens?, includePrivateKeys?, maxResults?)
```
Reports each finding by type, confidence, key name and 1-based position. **Values are never returned** — previews are truncated and length-annotated, and the context line has the secret masked out, so a finding can be located without the credential leaving the machine it was found on.
The server takes content and returns data — it reads no files and makes no network requests of its own. Published as [`secrets-le-mcp`](https://www.npmjs.com/package/secrets-le-mcp) on npm and as `io.github.nolindnaidoo/secrets-le` in the [MCP registry](https://registry.modelcontextprotocol.io).
<details>
<summary><b>Configuring it by hand</b> — any host with an MCP config file</summary>
Most hosts read a JSON config. Add one entry:
```json
{
"mcpServers": {
"secrets-le": {
"command": "npx",
"args": ["-y", "secrets-le-mcp"]
}
}
}
```
`-y` skips the install prompt on first run. Pin a version if you would rather not track releases — `secrets-le-mcp@2.4.0`.
Prefer not to go through `npx` on every launch? Install it once and point at the binary instead:
```bash
npm install -g secrets-le-mcp
```
```json
{
"mcpServers": {
"secrets-le": { "command": "secrets-le-mcp" }
}
}
```
It speaks MCP over stdio and needs no environment variables, no API key and no configuration of its own. To check it before wiring it into anything:
```bash
echo '{"jsonrpc":"2.0","id":1,"method":"tools/list"}' | npx -y secrets-le-mcp
```
That prints the tool list and exits — if you see `detect_secrets`, the server works.
</details>
## The CLI
The same detection runs from a terminal or a CI step: a Rust CLI in
[`crate/`](crate/README.md), sharing one pattern table with the extension
— [`crate/signatures/patterns.toml`](crate/signatures/patterns.toml) —
so the two can never disagree about what counts as a credential.
```bash
secrets-le . # scan a tree
secrets-le --sensitivity high . # only high-confidence findings
secrets-le --no-ignore --hidden . # reach .env and everything git ignores
secrets-le mcp # the same detection over MCP on stdio
```
The exit code is the answer: **0 nothing found · 1 findings · 2 the
question was malformed** — so `secrets-le .` is a CI step as it stands.
**It never prints a credential.** A scanner's output goes into a CI log,
which is archived, often world-readable, and outlives the secret; a
scanner that printed what it found would disclose it more widely than
the commit would have. Previews are capped at eight characters *and* at
half the value's length, context lines are masked, and there is no flag
that changes either. The extension is the half that can *fix* what it
finds; the binary only reports.
## What gets detected
Thirty-four patterns, in `crate/signatures/patterns.toml` — the one table
both frontends load.
| Category | Types |
|---|---|
| Named issuers | Anthropic `sk-ant-`, OpenAI `sk-`/`sk-proj-`, xAI `xai-`, Groq `gsk_`, Hugging Face `hf_`, Replicate `r8_`, GitHub `ghp_`/`gho_`/`ghu_`/`ghs_`/`ghr_`/`github_pat_`, GitLab, Slack `xox?-` and webhook URLs, Discord webhook URLs, Stripe `sk_`/`rk_` live and test keys and `whsec_` webhook secrets, Google `AIza…` and OAuth client secrets `GOCSPX-`, Linear `lin_api_`, DigitalOcean `dop_v1_`/`doo_v1_`/`dor_v1_`, Doppler `dp.pt.`/`dp.st.`, SendGrid, Mailgun, Sentry, npm, PyPI, Docker Hub, HashiCorp Vault, Terraform Cloud, Supabase, Shopify, Square, Azure SAS |
| Cloud credentials | AWS Access Key IDs (`AKIA…`, no key name needed), AWS Secret Access Keys, Azure account keys, GCP/Google Cloud keys |
| Tokens | Generic tokens, bearer tokens, access/refresh tokens, OAuth tokens, JWTs (key-based or bare `eyJ…` form) |
| Passwords | `password`/`passwd`/`pwd` values, including compound keys (`DATABASE_PASSWORD`) |
| Private keys | Multi-line PEM blocks — RSA/EC, OpenSSH, PGP |
| Connection data | Database URLs with embedded `user:pass@` credentials, connection strings, session IDs, cookies |
Key-based patterns accept quoted and unquoted keys, so JSON (`"apiKey": "…"`), YAML (`api_key: …`), env (`API_KEY=…`), and code (`apiKey = '…'`) all match.
**Intentional non-detections**: template placeholders (`${VAR}`, `{{var}}`, `<your-key>`, `xxxxxxxx`), version numbers and hostnames that merely look dotted (`1.2.3` is not a JWT), GCP project ids (identifiers, not credentials), and database URLs without embedded credentials.
**Known limitations**: detection is pattern-based — obfuscated, split, or unconventionally named secrets are missed; JWTs whose header isn't standard base64 JSON (`eyJ…`) are missed; a high-entropy string without a recognizable key name or prefix is not reported.
## Commands
| Command | Description |
|---|---|
| `Secrets-LE: Detect Secrets` (`Ctrl+Alt+S` / `Cmd+Alt+S`) | Scan the workspace and open a results document |
| `Secrets-LE: Sanitize Secrets` | Replace detected secrets in the active file (asks for confirmation first) |
| `Secrets-LE: Open Settings` | Open Secrets-LE settings |
| `Secrets-LE: Help` | Built-in documentation |
## Settings
| Setting | Default | Description |
|---|---|---|
| `secrets-le.detection.sensitivity` | `medium` | `low` reports everything, `medium` drops low-confidence matches, `high` keeps only high-confidence ones |
| `secrets-le.detection.includeApiKeys` | `true` | Detect API keys and cloud credentials |
| `secrets-le.detection.includePasswords` | `true` | Detect passwords |
| `secrets-le.detection.includeTokens` | `true` | Detect tokens and JWTs |
| `secrets-le.detection.includePrivateKeys` | `true` | Detect PEM private-key blocks |
| `secrets-le.sanitization.replaceWith` | `***REDACTED***` | Replacement text used by Sanitize |
| `secrets-le.workspace.scanPatterns` | `["**/*"]` | Glob patterns to scan |
| `secrets-le.workspace.scanExcludes` | node_modules, .git, dist, … | Glob patterns to skip |
| `secrets-le.workspace.scanMaxFiles` | `10000` | Cap on files scannLo que la gente pregunta sobre secrets-le
¿Qué es nolindnaidoo/secrets-le?
+
nolindnaidoo/secrets-le es mcp servers para el ecosistema de Claude AI. Find hardcoded credentials in a codebase, and never print one into the report Tiene 1 estrellas en GitHub y su última actualización registrada es del 2026-09-30.
¿Cómo se instala secrets-le?
+
Puedes instalar secrets-le clonando el repositorio (https://github.com/nolindnaidoo/secrets-le) o siguiendo las instrucciones del README en GitHub. ClaudeWave también te ofrece bloques de instalación rápida en esta misma página.
¿Es seguro usar nolindnaidoo/secrets-le?
+
Nuestro agente de seguridad ha analizado nolindnaidoo/secrets-le y le ha asignado un Trust Score de 95/100 (tier: Verified). Revisa el desglose completo de comprobaciones superadas y flags en esta página.
¿Quién mantiene nolindnaidoo/secrets-le?
+
nolindnaidoo/secrets-le es mantenido por nolindnaidoo. La última actividad registrada en GitHub es del 2026-09-30, con 0 issues abiertos.
¿Hay alternativas a secrets-le?
+
Sí. En ClaudeWave puedes explorar mcp servers similares en /categories/mcp, ordenados por popularidad o actividad reciente.
Despliega secrets-le en tu cloud
Lleva este repo a producción en minutos. Cada plataforma genera su propio entorno con variables de entorno editables.
¿Mantienes este repo? Añade un badge a tu README
Pega el badge en tu README de GitHub para mostrar que está auditado por ClaudeWave. Cada badge enlaza de vuelta a esta página y muestra el Trust Score actual.
[](https://claudewave.com/repo/nolindnaidoo-secrets-le)<a href="https://claudewave.com/repo/nolindnaidoo-secrets-le"><img src="https://claudewave.com/api/badge/nolindnaidoo-secrets-le" alt="Featured on ClaudeWave: nolindnaidoo/secrets-le" width="320" height="64" /></a>Más MCP Servers
Fair-code workflow automation platform with native AI capabilities. Combine visual building with custom code, self-host or cloud, 400+ integrations.
User-friendly AI Interface (Supports Ollama, OpenAI API, ...)
An open-source AI agent that brings the power of Gemini directly into your terminal.
Real-time global intelligence dashboard. AI-powered news aggregation, geopolitical monitoring, and infrastructure tracking in a unified situational awareness interface
🕷️ An adaptive Web Scraping framework that handles everything from a single request to a full-scale crawl! Don't be shy, join here: https://discord.gg/EMgGbDceNQ and follow here for daily tips and tricks: https://x.com/Scrapling_dev
The fastest path to AI-powered full stack observability, even for lean teams.