Skip to content
KeyDrift
Scan for free
← Support & documentation

Scanning code behind a login

Paste-mode workflow: export built JS from DevTools for authed views; rotate-before-paste if exposure suspected; reports stay private.

2 min read

Auth walls block fetching, not inspection.

Workflow

  1. Log in normally; open DevTools Sources for the authed route.
  2. Copy relevant built chunk contents.
  3. Paste into source-scan; receive noindexed report.
  4. If exposure suspected beforehand: rotate FIRST — pasting confirms presence, not safety.

The bigger picture

It helps to name the economics honestly. Fixing this class of leak costs minutes when caught at deploy time and days when caught at invoice time, because by then the credential has been harvested, validated, resold or drained — often all four. Detection latency is the entire game, which is why the monitoring half of KeyDrift exists alongside the scanning half.

How KeyDrift reports this exact finding

When KeyDrift finds this on your deployment, the report shows a masked value (first 8 and last 4 characters only), a salted fingerprint for tracking, the exact chunk filename carrying it, and a severity with written rationale. Public-by-design neighbours — anon keys, publishable keys, Firebase web constants — appear as informational context rather than noise, because knowing what should be there is what makes the real findings credible.

Manual check, step by step

A five-minute version you can run anywhere: view-source on the landing page, copy every src= script URL, fetch each and search the results for paste mode authenticated pages. It misses manifest-only chunks and streamed payloads — which is precisely the gap between "I checked" and "it is clean" — but it catches the loud majority and builds the pattern-recognition that makes scanner output legible.

Close the loop with monitoring

Monitoring closes the loop that one-time verification leaves open. A scheduled scan refetches everything, diffs against history, and fires only on transitions: created, regressed, resolved. Regression alerts matter most here — they fire when a previously fixed finding returns, which in agent-era codebases is less a possibility than a schedule.

Where this fits

This document is part of the support knowledge base that mirrors production behaviour exactly: detector counts, plan limits and payload shapes on these pages are computed from the same catalogs that power the product, and tests assert they cannot drift. If anything here contradicts observed behaviour, report it via the false-positive process — calibration improves fastest when reality disagrees loudly.


Run a free scan at keydrift.dev/scan — paste a URL or the bundle source itself, no account. Findings arrive masked, with the exact chunk they live in.

Published by PostHat, KeyDrift’s content pipeline. Every factual claim is grounded in KeyDrift’s product documentation.