Skip to content
KeyDrift
Scan for free

About

The key was never in your repository

KeyDrift reads the JavaScript your app actually serves and finds the credentials that should never have left your server.

Why it exists

Prefixes like NEXT_PUBLIC_ and VITE_ substitute an environment variable’s literal value into the bundle at build time. Your .env stays correctly git-ignored, every secret scanner in CI passes, and the key still ships to every visitor who loads the page.

That failure has become common for one specific reason: AI coding tools reach for the variable that makes the feature work, and a service-role key makes the feature work. Nobody reviewing the diff sees a secret, because in the source there is only a variable name.

So KeyDrift does not read your repository. It fetches the deployed JavaScript, walks the chunks your app loads, and reports what is actually in them — while recognising the publishable keys that are supposed to be there and are not leaks.

Evidence you can check

Every finding names the chunk it came from and the byte range inside it. You can open the same file in your own browser and see it.

Live secrets are never stored

Findings keep a masked prefix and a fingerprint — enough to identify and track a key, never enough to use one. A scanner that hoards secrets has become the exposure.

No credentials, no account

The public scanner fetches assets that are already being served to the internet. The first answer costs nothing and requires nothing.

Public keys are not findings

Publishable keys have recognisable formats. Reporting them as leaks is how a scanner teaches its users to ignore it.

Questions we get asked

Why do AI coding tools leak API keys into the frontend?
Because the elevated key is the one that makes the feature work, and a prefix makes it reachable from the browser. When a query returns nothing under a restricted key, the shortest path to working code is the service_role or secret key — and using it client-side requires a NEXT_PUBLIC_ or VITE_ prefix. Those prefixes are build instructions, not security settings: they mean "inline this literal value into the bundle".
My repository secret scan passed. Why would my bundle still leak?
Because build-time environment variables are substituted into the bundle during the build, on a CI runner, after the scan has already passed. The repository stays clean, the scanner stays green, and the key ships to every visitor. Checking the built output is a separate step that most pipelines simply do not perform.
What does NEXT_PUBLIC_ actually do?
It tells the bundler to replace the variable with its literal value at build time, so the value can be read in the browser. It is documented, intended behaviour and it is not a security control. The problem is never the mechanism — it is which variable ends up behind the prefix.
Which keys are safe to ship to the browser?
Publishable credentials designed for it: a Supabase anon key, a Stripe publishable key, a Firebase web API key, a Mapbox public token, a Sentry DSN. These have recognisable formats and belong in client code. KeyDrift recognises them and does not report them, because a scanner that flags safe keys teaches people to ignore it.
I found a key in my bundle. What do I do first?
Rotate it, immediately, at the provider. The key is already compromised — anyone who loaded that page has it, and CDN caches may keep serving the old bundle after you deploy again. Only then move the call to a server route or edge function, give the client the publishable key, redeploy, and confirm the value is gone.

Part of Veristria

KeyDrift is a Veristria product

Veristria builds verification infrastructure for teams shipping software faster than they can review it. It was founded by Lars O. Horpestad, the author of Å ta smartere beslutninger med AI (2023), a practical guide to large language models.

All three Veristria products work the same way: look at what actually shipped rather than what the source intended, prove the finding, and say plainly what to change. KeyDrift applies that to the bundle you serve.

RowShield

Checks what your Supabase anon key can read from a deployed URL — free, read-only, under ten seconds. Connecting one project is free and runs the nine-rule audit daily; paid plans add projects, faster scans, and more alert channels.

rowshield.dev

FeeGuard

Finds the Stripe Connect application fees a refund leaves behind, from an export you paste — read-only, no credentials. 90-day lookback. Detection stays free.

feeguard.dev

Who runs this

Lars O. Horpestad, founder of Veristria

KeyDrift is built by Veristria (Norway), founded by Lars O. Horpestad. Veristria is a Norwegian aksjeselskap (AS) under incorporation (filed 24 August 2026); the organisation number is published on veristria.com/imprint when registration completes. Veristria is separate from AI ThinkLab AS (org.nr. 933 078 523), the founder’s prior company.

Address: Veristria, Sofie Steinnes'veg 9A, 4352 Kleppe, Norway.

The full company details are on the imprint and on Veristria’s About page. Sales, support, security, legal, press and billing each have a desk at @teamveristria.com, or call +47 988 36 369. We only email from @teamveristria.com, @useveristria.com, @meetveristria.com, @veristriagroup.com, @veristriahq.com, @veristriaworks.com and @withveristria.com.

KeyDrift lives on keydrift.dev, but its mail comes from the Veristria domains above, so any sender can be checked against the imprint.

Scan your site for freeRead the blog