API keys and passwords
An API key on screen is a bill on its way.
Bots scan code videos for API keys. A key visible for a second in a .env file can be used within the hour.
live-setup-bureau.mp4 · 2:47:10 · 4.6 GB
EmailPhone00:12:16:08
0:000:451:302:152:47
5 clips to review
1m 06s to review out of 2h 47m- Emailjulie.m•••••@gmail.com00:12:14
- PlateAB-•••-CD00:38:48
- Address“12 Linden R••••…”01:09:03
- Phone06 •• •• •• 7801:52:37
- TabInbox · 3 unread02:31:02
Where it appears most often
- .env and configuration files
- Terminal and command history
- Cloud provider dashboards
- Open password managers
How ScanMyVid spots it
- Common key formats are recognized by their prefix and length.
- Password fields shown in plain text are flagged.
- Even a key truncated on screen is flagged: you decide afterward.
Why it's risky
A leaked key means a cloud bill in the thousands of euros, or full access to an account.
The tip before filming
Revoke any key that appeared on screen, even if blurred later: it's the only reliable protection.
Publish with peace of mind.
Drop a video: the first 3 minutes are analyzed for free, no card required.