Skip to content

API keys and passwords

An API key on screen is a bill on its way.

Bots scan code videos for API keys. A key visible for a second in a .env file can be used within the hour.

Where it appears most often

  • .env and configuration files
  • Terminal and command history
  • Cloud provider dashboards
  • Open password managers

How ScanMyVid spots it

  • Common key formats are recognized by their prefix and length.
  • Password fields shown in plain text are flagged.
  • Even a key truncated on screen is flagged: you decide afterward.

Why it's risky

A leaked key means a cloud bill in the thousands of euros, or full access to an account.

The tip before filming

Revoke any key that appeared on screen, even if blurred later: it's the only reliable protection.

Publish with peace of mind.

Drop a video: the first 3 minutes are analyzed for free, no card required.