detect-secrets (Yelp) vs KeyDrift
Yelp’s detect-secrets baselines secrets in codebases efficiently. Deployed artifacts stay out of scope by design.
detect-secrets introduced the baseline workflow that made enterprise secret scanning tolerable at scale.
This page compares the two honestly: strengths credited specifically, differences traced to structure rather than quality, and a decision rule at the end. Verified August 2026.
What detect-secrets does well
It documents plugin-based detection with a baseline model that filters known/accepted findings during review.
- Baseline workflow keeps noise manageable in large codebases.
- Plugin architecture extends detection cleanly.
- Enterprise pedigree from Yelp’s internal use.
The gap KeyDrift fills: the deployed bundle
The structural difference is the artifact under inspection. detect-secrets watches inputs to the build — commits, branches, configuration. KeyDrift watches the output: the HTML and JavaScript a browser downloads from the live URL. Build-time substitution, agent-written client calls and streamed payloads live in that output and in none of the inputs, which is why a green detect-secrets report and a leaking deployment can coexist without anyone being wrong.
- Fetched-and-diffed scanning of live URLs, including chunks reachable only through route manifests.
- Streamed server data (
self.__next_f.push,window.__NUXT__) read as carefully as chunk files. - Calibrated dispositions: Supabase anon keys, publishable keys and Firebase web keys recognised as public-by-design instead of reported as leaks.
- Drift transitions — created, regressed, resolved — so a reintroduced key alerts as a regression, not as news.
Feature-by-feature
- Surfaces scanned. Source files within repositories. versus KeyDrift: deployed web artifacts fetched live, or pasted bundle source for anything behind a login.
- Detection approach. Plugin-based heuristics plus entropy checks. versus KeyDrift: 21 secret detectors across 13 providers with placeholder rejection, alphabet-normalised entropy, payload decoding and a confidence floor below which matches are dropped rather than caveated.
- Change over time. Baseline diffs reviewed in pull requests. versus KeyDrift: scheduled scans diffed into created/regressed/resolved with alert routing to email, Slack, Discord and webhooks.
- Getting started. pip-installed CLI integrated into pre-commit or CI. versus KeyDrift: paste a URL at /scan — free, no account — or paste source for private surfaces.
Side-by-side
Every cell below states a specific capability. Where detect-secrets documents more detail than fits here, follow their docs; where KeyDrift claims something, it is verifiable in a two-minute free scan.
| Capability | detect-secrets | KeyDrift |
| --- | --- | --- |
| Primary surfaces | Source files within repositories. | Deployed web artifacts fetched live: HTML, all chunks (incl. route-manifest-only), streamed payloads |
| Build-time substitution (NEXT_PUBLIC_/VITE_) | Source-side only — substitution happens after these scans complete | Detected in served output — exactly where it lands |
| Hydration payloads (self.__next_f.push, window.__NUXT__) | Outside source-scan scope | Read as carefully as chunk files |
| Public-vs-secret calibration | Varies by engine; anon-key false positives remain the classic complaint | Dispositions built-in: anon/publishable/Firebase-web reported informational, sample keys rejected by name |
| Change over time | Baseline diffs reviewed in pull requests. | Scheduled scans diffed into created/regressed/resolved; regression alerts name comebacks |
| Alert routing | Baseline diffs reviewed in pull requests. | Email · Slack · Discord · raw webhooks with per-destination severity thresholds |
| Getting started | pip-installed CLI integrated into pre-commit or CI. | Paste any URL at keydrift.dev/scan — free, no account; paste-source mode for behind-login surfaces |
| Privacy of findings | Varies by vendor | Masks + salted fingerprints only; no column anywhere can hold a live secret |
_Cells describing detect-secrets summarize their public documentation as of the verified date above._
Where each one wins
- detect-secrets wins when teams institutionalizing secret review culture inside PR flow.
- KeyDrift wins when the question is “what credentials can strangers retrieve from this deployment right now?” — live fetching, calibrated dispositions, and regression alerting without agents installed.
Switching from detect-secrets
Teams arriving from detect-secrets usually keep their existing setup and add one job: point KeyDrift at production, staging, and preview URLs. First week looks like this — day one, run the free scan on every deployment and triage findings by severity; day two, fix or schedule fixes using the linked guides; day three onward, monitoring watches for regressions while detect-secrets continues doing what it does best.
Baselines guard source reviews; KeyDrift watches the artifact those reviews produce afterward.
Decision rule
- Keeping detect-secrets for its documented strengths makes sense — it earns them.
- Add KeyDrift when deployment truth matters: post-build artifacts, preview URLs, and reintroduction watch on a schedule.
_Compared against detect-secrets documentation and pricing as verified August 2026. Capabilities change; check their site._ Yelp, Inc. and associated marks are trademarks of Yelp, Inc., referenced for identification and descriptive comparison.
Bottom line: choose detect-secrets for its category strengths without hesitation. Choose KeyDrift the moment someone asks what your bundles expose — then keep both, because they were never competing for the same job.
How teams actually run detect-secrets and KeyDrift together
In practice the pairing is boring in the best way: detect-secrets stays authoritative for whatever it was built to do, KeyDrift runs on a schedule against every public deployment, and alerts route into the same channels your team already reads. Nothing is migrated; nothing is turned off. The only new habit is reading one more alert type — and that one arrives masked, classified, and linked to a fix guide.
What to verify on their site before deciding
- Their current scanned-surface list (Source files within repositories.) — confirm against your stack.
- Whether drift/change-detection over time is part of their product or a roadmap item.
- Free-tier shape: what you can prove about YOUR deployment before any purchase conversation.
Common questions
Is detect-secrets bad at security?
No — the page credits specific strengths above. The difference is which artifact gets inspected, not effort or care.
Pricing comparison?
Their list pricing lives on their site and changes; ours sits on the plans page with findings visible free at every tier. Numbers go stale; philosophy does not.
Run a free scan at keydrift.dev/scan — paste a URL or the bundle source itself, no account. Findings arrive masked, with the exact chunk they live in.