KeyDrift
Free scan

Fix guides

Every credential KeyDrift detects, crossed with the tool that put it in your bundle. Each guide explains why that tool produces the leak and gives the exact change that moves the call back to a server.

Bolt.new

Bolt scaffolds Vite projects inside a WebContainer, where everything runs in the browser by definition. Code that works in the preview keeps the key client-side when it is deployed, because nothing in the generated project ever moved it to a server.

Fix guides — exposed keys by tool and credential · KeyDrift