Agencies: run a secret audit on every client site you touch
Scan-before-touch gives a dated baseline deliverable at kickoff and defensible offboarding evidence. Portfolio monitoring maps to retainers.
Your stack, your exposures
Agency stacks inherit other people’s decisions: prior contractors, abandoned scaffolds, legacy marketing sites nobody owns. Your kickoff scan documents reality before you become responsible for it.
The three leaks we keep finding here
Inherited scaffolds
service_role defaults live on unnoticed through three redesigns.
Ex-contractor tokens
GitHub PATs and provider keys from whoever “set things up” remain bundled long after offboarding.
The marketing-site fossil
A 2019 CRA site still serving REACT_APP_ credentials alongside the shiny new app.
The check, time-boxed
Set aside ten minutes and run the audit yourself before trusting anyone’s dashboard, ours included:
- Open the deployed site in a browser you do not usually use, logged out.
- View source, then search the built JavaScript for
eyJ— any hit is a JWT; decode its payload and read the role claim before reacting. - Repeat for provider prefixes:
sk_live_,sk-proj-,sk-ant-,AKIA,xoxb-,SG.,whsec_. - Search for connection schemes —
postgres://,postgresql://,mongodb+srv://— and for-----BEGIN PRIVATE KEY-----. - For every hit, classify: public-by-design (anon keys, publishable keys, Firebase web keys) or genuinely secret. Only the second category is an incident.
That routine works, with two caveats: it only covers what the landing page loads unless you chase route-manifest chunks yourself, and it says nothing about yesterday’s deploy. Automation exists precisely because the check decays.
After the first scan
Team plan ($89/mo) watches fifteen client properties at 15-minute cadence with webhook routing into your ops channel — retainer math that survives procurement.
Boundaries, stated plainly
KeyDrift scans deployed web artifacts — URLs and pasted bundle source. It does not scan mobile binaries, private networks, or repositories; code behind a login is covered by paste mode, and runtime-assembled keys are outside every bundle scanner’s honest reach.
The bigger picture
Zoom out and the pattern is bigger than one repo. AI-assisted output has outgrown review capacity everywhere at once, which means thousands of teams are making the same reasonable-looking tradeoffs in the same week. Nobody using modern tooling is uniquely exposed. The failure mode documented above is the modal outcome of velocity without verification, not evidence of carelessness.
How KeyDrift reports this exact finding
Report anatomy matters during incidents, so it is worth reading once calmly: masked string (never the live value — it ceases to exist outside the detection engine), salted fingerprint (trackable within your workspace, useless to strangers), chunk path (your starting point for a "git log -S" hunt), disposition (secret versus public-by-design), confidence (matches below 0.5 never reach the page at all).
Manual check, step by step
The full manual drill, for readers who want zero dependence on any tool: open the deployed site in a private window; launch DevTools → Sources; use Search-all-files (Ctrl/Cmd+Shift+F) for eyJ; then repeat for the other marker families — eyJ, sk_live_, sk-proj-, AKIA, postgres, BEGIN PRIVATE KEY. Decode anything JWT-shaped before reacting, and classify public-by-design formats as expected guests rather than intruders.
Close the loop with monitoring
If you take one operational step from this page, make it this: put the URL under continuous monitoring (free tier covers one project daily). The first scan tells you whether you have a problem today; the schedule tells you whether the problem comes back next month after someone re-adds the convenient line.
What the plans change
- Free $0 — 1 project · daily scans · email alerts · findings always visible.
- Indie $29/mo — 3 projects · hourly · Slack added · 80 chunks per scan.
- Team $89/mo — 15 projects · every 15 minutes · Discord + webhooks · 150 chunks.
- Growth — from $249/mo, quoted display-only until checkout ships.
The constant across every tier: plans limit how much is watched, never what a scan found. Visibility is structural, not promotional — asserted by tests over the entitlements model itself.
Common questions
White-label reports?
Reports are KeyDrift-branded today; stated plainly rather than promised vaguely.
Run a free scan at keydrift.dev/scan — paste a URL or the bundle source itself, no account. Findings arrive masked, with the exact chunk they live in.