Scan GitHub repositories for leaked AI API keys and validate them. Supports 50+ platforms including OpenAI, Claude, Gemini, and basically everything else you'd want to check.
Latest update (July 2026): Added support for OpenRouter, AWS Bedrock, xAI Grok, and a bunch of other platforms that appeared this year.
Searches GitHub for exposed API keys, then validates them to see if they actually work. Simple as that.
The tool is fast (430x faster than doing it manually), has a nice terminal UI, and won't waste time re-checking keys you've already found.
Major AI platforms:
- OpenAI (GPT-4, GPT-5)
- Anthropic (Claude)
- Google (Gemini)
- Azure OpenAI
- xAI (Grok)
- Meta (Llama API)
API aggregators (these are gold mines):
- OpenRouter
- Portkey
- LiteLLM
- Cloudflare Workers AI
Cloud provider AI services:
- AWS Bedrock
- Google Vertex AI
- Alibaba Cloud
- Volcano Engine
- Tencent Cloud
- Baidu Qianfan
Regional providers:
- DeepSeek, Moonshot, Zhipu (Chinese platforms)
- Groq, Mistral, Cohere (International)
- Plus 20+ more platforms
Full list: OpenAI, Anthropic, Google Gemini, Azure, xAI, Meta Llama, OpenRouter, Portkey, LiteLLM, Cloudflare AI, AWS Bedrock, Vertex AI, Alibaba Cloud, Volcano Engine, Tencent Hunyuan, Baidu Qianfan, DeepSeek, Moonshot, Zhipu, Yi AI, StepFun, iFlytek, HuggingFace, Groq, Cohere, Mistral, Together AI, Replicate, Perplexity, Fireworks, AI21, Writer, Forefront, Modal, RunPod, Baseten, and generic services like AWS, GitHub tokens, Stripe, etc.
Tested on 1000 keys:
Original version: 103 seconds
This version: 0.24 seconds (430x faster)
How? Async everything, smart caching, connection pooling, and batch processing.
Requirements:
- Python 3.10+
- GitHub personal access token (free, takes 2 minutes to get)
Install:
git clone https://github.com/YourUsername/AI-API-Scanner.git
cd AI-API-Scanner
pip install -r requirements.txtConfigure:
Create config_local.py:
GITHUB_TOKENS = [
"ghp_your_token_here", # Get from github.com/settings/tokens
]
# Optional proxy
PROXY_URL = "" # e.g., "http://127.0.0.1:7890"To get a GitHub token:
- Go to https://github.com/settings/tokens
- Click "Generate new token (classic)"
- Check
public_repo - Copy the token
Run:
python main_v2.2.pyThat's it. The terminal UI will show what's happening in real-time.
Basic commands:
# Start scanning
python main_v2.2.py
# View stats
python main_v2.2.py --stats
# Export valid keys
python main_v2.2.py --export results.txt --status valid
# Export to CSV
python main_v2.2.py --export-csv results.csv --status valid
# Encrypted export (recommended)
python main_v2.2.py --export-encrypted secure.binAdvanced options:
# Disable cache (slower but uses less memory)
python main_v2.2.py --no-cache
# Scan all sources (GitHub, Gist, GitLab, Pastebin, etc.)
python main_v2.2.py --all-sources
# Use custom database
python main_v2.2.py --db custom.db- Scan: Searches GitHub using optimized queries (93 different search patterns)
- Filter: Removes test keys, fake keys, and garbage using entropy analysis
- Deduplicate: Checks cache and database to avoid re-validating
- Validate: Tests keys against actual API endpoints (100+ concurrent requests)
- Store: Saves results to SQLite database
The tool uses a 3-layer cache:
- L1: Validation results (30-50% hit rate)
- L2: Domain health (skips dead domains)
- L3: Key fingerprints (duplicate detection)
Edit config.yaml to tune performance:
# High-performance setup (16GB+ RAM)
validator:
max_concurrency: 200
num_workers: 4
database:
batch_size: 100
flush_interval: 2.0
# Low-resource setup (8GB RAM)
validator:
max_concurrency: 50
num_workers: 1
database:
batch_size: 20
flush_interval: 10.0├── main_v2.2.py # Latest version (recommended)
├── main_v2.1.py # Connection pool version
├── main.py # Original version
│
├── scanner.py # GitHub scanning
├── validator.py # Key validation
├── database.py # SQLite storage
├── config.py # Platform config (50+ platforms)
│
├── cache_manager.py # Smart caching
├── batch_validator.py # Batch processing
├── connection_pool.py # HTTP connection reuse
├── retry_handler.py # Retry logic
│
├── source_*.py # Additional sources (Gist, GitLab, etc.)
├── monitor.py # Real-time monitoring
├── ui.py # Terminal UI
└── config.yaml # User config
v3.0 (2026-07-24):
- Added 20+ new platforms (OpenRouter, AWS Bedrock, xAI Grok, etc.)
- Updated GitHub search syntax (removed deprecated
NOToperator) - All comments and docs now in English
- 93 optimized search queries (up from 70)
v2.2 (2026-01-12):
- Smart caching system (30-50% cache hit rate)
- Batch validation (40-60% fewer requests)
- Domain health tracking
v2.1 (2026-01-11):
- HTTP connection pooling
- Smart retry mechanism
- Performance monitoring
v2.0 (2026-01-11):
- Async database (100-430x faster)
- Queue expansion (1000 → 10000)
- Encrypted export
This tool is for authorized security testing only. Don't use it to:
- Scan repos you don't have permission to test
- Exploit keys you find
- Do anything illegal
If you find leaked keys:
- Report them to the repo owner
- Don't use them
- Don't share them
The authors are not responsible for misuse. You're an adult, act like one.
For researchers:
- Always get authorization first
- Use encrypted export for findings
- Report through proper channels
- Rate limit your scans
For developers who got breached:
If this tool found your key:
# 1. Revoke the key NOW (don't wait)
# 2. Remove from git history
git filter-repo --path path/to/file --invert-paths
# 3. Add to .gitignore
echo ".env*" >> .gitignore
echo "config_local.py" >> .gitignore
# 4. Use environment variables
export OPENAI_API_KEY="sk-..."
# 5. Install pre-commit hooks
pip install pre-commit gitleaks
pre-commit installHardware: Intel i7-10700K, 32GB RAM, 1Gbps
| Keys | Original | v2.2 Cache | Speedup |
|---|---|---|---|
| 100 | 10.38s | 0.10s | 108x |
| 500 | 52.08s | 0.16s | 320x |
| 1000 | 103.29s | 0.24s | 430x |
Cache effectiveness:
- Validation cache: 42% hit rate
- Domain cache: 68% hit rate
- Fingerprint cache: 78% hit rate
- Total requests saved: 61%
- QUICKSTART.md - Get started in 5 minutes
- OPTIMIZATION.md - Technical details
- MIGRATION.md - Upgrade guide
- CHANGELOG_V3.0.md - What's new
Found a bug? Want to add a platform? PRs welcome.
# Fork and clone
git clone https://github.com/YourUsername/AI-API-Scanner.git
# Create branch
git checkout -b feature/new-platform
# Make changes and test
python test_v2.2.py
# Submit PR
git push origin feature/new-platformQ: Is this legal?
A: Yes, if you have authorization. No, if you don't.
Q: Why do I need a GitHub token?
A: GitHub rate limits unauthenticated requests to 10/min. With a token you get 30/min per token.
Q: Can I scan private repos?
A: No. This tool only scans public repositories.
Q: What if a key is rate limited?
A: The tool marks it as "quota_exceeded" instead of "invalid". Still a valid key, just hit the limit.
Q: Why are some platforms missing?
A: Either they don't have a public API, or I haven't added them yet. PRs welcome.
Q: Can this get me in trouble?
A: Only if you use it irresponsibly. Don't be stupid.
MIT License. See LICENSE file.
Built by security researchers, for security researchers.
Uses: aiohttp, Rich, PyGithub, loguru, and other open source libraries.
Use responsibly. Don't be the reason GitHub adds more rate limits.
