{"uid":"cap_45ybZ1mcs4O781BWI9J2A","slug":"payai-secret-scanner-55b653b1","name":"PayAI Secret Scanner","description":"Static scan of source code or config for hardcoded secrets and credentials. Detects cloud keys, VCS and CI tokens, payment keys, messaging tokens, AI-provider keys, database URIs with passwords, private keys and high-entropy generic secrets. Returns a go/no-go verdict (pass, caution, block) with per-finding rule, provider, severity and location. Secret indicators, not a guarantee.","url":"https://payai.agentstools.dev/secret/scan","method":"POST","headers":{},"bodySchema":{"type":"object","properties":{"files":{"type":"array","items":{"type":"object"},"description":"Alternatively a batch of objects, each with path and content"},"rules":{"type":"array","items":{"type":"string"},"description":"Optional list of rule ids to restrict to (see GET /secret/rules)"},"content":{"type":"string","description":"Source code / config text to scan (single blob)"},"filename":{"type":"string","description":"Optional path/name of the blob (affects fixture downgrade)"},"min_entropy":{"type":"number","description":"Raise the entropy floor for generic rules"},"allow_test_fixtures":{"type":"boolean","description":"Drop findings in test/example/doc paths entirely"}}},"responseSchema":null,"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.01","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.01/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.01","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.01","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_zwohNFVmmx89LI5-fGy6Z","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.01","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Statically scans source code or config files for hardcoded secrets and credentials, returning a verdict (pass/caution/block) with per-finding details including rule, provider, severity, and location.","exampleAgentPrompt":"Scan this source code snippet for any hardcoded secrets, API keys, or credentials before I push it — I need a pass/caution/block verdict with details on each finding including which provider and severity.","exampleUseCases":[{"title":"Pre-commit secret check for developer","prompt":"Before I commit this Python file, scan it for any hardcoded secrets or API keys — if anything is flagged, tell me the exact line, what kind of secret it is, and how severe the risk is."},{"title":"CI pipeline credential gate","prompt":"I'm setting up an automated check in my CI pipeline — scan this config file for hardcoded database URIs, cloud keys, or tokens and give me a block, caution, or pass verdict so I can fail the build if anything critical is found."},{"title":"Pre-deployment .env audit","prompt":"I want to audit my .env file before deploying to production — check it for any exposed private keys, payment processor tokens, or AI provider API keys and list every finding with its severity and location."}],"resultDescription":"Returns a top-level verdict of 'pass', 'caution', or 'block' along with an array of per-finding objects. Each finding includes the matched rule name, the provider associated with the secret (e.g. AWS, GitHub, Stripe, OpenAI), a severity rating, and the location (e.g. line number or file path) where the potential secret was detected.","failureModes":["Empty or missing input body returns an error response","Very large files may exceed payload limits","High-entropy strings may produce false positives flagged as generic secrets","Obfuscated or base64-encoded secrets may not be detected","Service may return caution instead of block for ambiguous patterns","Network timeout if input is extremely large"],"whenToPreferThis":"Choose this endpoint when you need a fast, automated static check for hardcoded secrets in code or config before committing, deploying, or merging. It covers a broad range of secret types — cloud keys, CI/VCS tokens, payment keys, messaging tokens, AI provider keys, database URIs, and private keys — in a single call with a clear go/no-go verdict. Prefer it over manual review or full SAST tools when speed and breadth of secret-type coverage matter more than deep semantic analysis of business logic.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-14T12:57:52.550Z","isFirstParty":false}