Sign inSign up

adityabhatt3010/keysentry

By adityabhatt3010

โ€ขUpdated about 1 year ago

KeySentry โ€“ Find leaked API keys & secrets in any GitHub repo. No mercy.

Image
Security
Integration & delivery
API management
1

407

adityabhatt3010/keysentry repository overview

โ ๐Ÿ›ก๏ธ KeySentry

๐Ÿ” KeySentry: Find leaked API keys & secrets in any GitHub repo or local project. No mercy.

A powerful, no-nonsense tool to detect unsecured API keys, tokens, and sensitive files โ€” either via command-line scan or a beautifully built frontend web scanner.

KeySentry Cover


โ ๐Ÿš€ Features

  • ๐Ÿ”Ž Scans for 25+ common API key formats (AWS, Slack, Stripe, OpenAI, etc.)
  • ๐Ÿง  Regex + entropy-inspired patterns for high accuracy
  • ๐Ÿ—‚๏ธ Flags sensitive files like .env, id_rsa, firebase.json, etc.
  • ๐Ÿ’พ Outputs structured results to JSON
  • ๐Ÿงฉ Supports both GitHub repo URLs and local folder paths
  • ๐Ÿ’ป No GitHub API tokens needed
  • โšก Styled terminal banner and colorful terminal logs
  • ๐ŸŒ Frontend scanner hosted on Netlify for ease of use

โ ๐ŸŒ Live Frontend

We now have a frontend interface (located in project/ folder) for easier scanning.

Paste a GitHub repo URL and instantly view results in your browser.


โ ๐Ÿณ Docker Support

You can build and run the CLI version via Docker.

โ ๐Ÿ“ Dockerfile Provided

A ready-to-use Dockerfile is included.

โ ๐Ÿ“ค DockerHub Image

โžก๏ธ https://hub.docker.com/r/adityabhatt3010/keysentryโ 


โ ๐Ÿ“ฆ Installation

โ ๐Ÿ”ง Local Installation
git clone https://github.com/AdityaBhatt3010/KeySentry.git
cd KeySentry
pip install -r requirements.txt
โ ๐Ÿณ Pull from DockerHub
docker pull adityabhatt3010/keysentry

โ ๐Ÿงช Usage

โ ๐Ÿ” Scan a GitHub repository:
python KeySentry.py --repo https://github.com/username/repo-name --output results.json
โ ๐Ÿ’ป Scan a local directory:
python KeySentry.py --local /path/to/codebase --output results_local.json
โ โ–ถ๏ธ Using Docker:
docker run --rm adityabhatt3010/keysentry --repo https://github.com/username/repo-name --output results.json

โ ๐Ÿ“ Sample Output

[
  {
    "file": "/tmp/tmpabcd1234/app/settings.py",
    "type": "AWS",
    "match": "AKIAIOSFODNN7EXAMPLE"
  },
  {
    "file": "/tmp/tmpabcd1234/.env",
    "type": "Sensitive File",
    "match": ".env"
  }
]

โ ๐Ÿ” What It Detects

โ API Keys:
  • AWS, Google, Slack, Stripe, OpenAI, SendGrid, Twilio
  • GitHub, DigitalOcean, Heroku, Mailgun, Firebase
  • Cloudflare, JWT, Facebook, Dropbox, Azure
  • Netlify, Notion, Terraform, CircleCI, BasicAuth
  • RSA Private Keys, Base64 blobs, and more
โ Sensitive Files:
  • .env, .env.local, .aws/credentials, .dockercfg
  • credentials.json, firebase.json, id_rsa, .pypirc, etc.

โ ๐Ÿง  Future Roadmap

  • โœ… Full local & GitHub scanning
  • โœ… Structured JSON reporting
  • โœ… Docker support
  • ๐Ÿ”œ Live token validation (OpenAI/AWS, etc.)
  • ๐Ÿ”œ GitHub username/org-wide scan
  • ๐Ÿ”œ FastAPI dashboard w/ SQLite visualization
  • ๐Ÿ”œ Discord/Telegram alert integrations

โ ๐Ÿ‘จโ€๐Ÿ’ป Crafted By

Made with โค๏ธ by Aditya Bhattโ  โ€” Cybersecurity & VAPT Specialist.


โ โš ๏ธ Disclaimer

For educational & auditing use only. Do not use this tool on repositories you don't own or lack permission to scan.


Tag summary

Content type

Image

Digest

sha256:d3a59059cโ€ฆ

Size

94.8 MB

Last updated

about 1 year ago

docker pull adityabhatt3010/keysentry