pasteShield
API keys, tokens, passwords, DB strings & private keys.
Every scan runs on-device. No network calls, ever.
Define patterns for your own internal tokens.
Deploy & manage across a team via MDM.
Category-specific detection, not a black box. Here’s exactly what it looks for.
OpenAI, Anthropic, AWS, GitHub, GitLab, and Stripe key formats, matched by their known prefixes and structure.
Authorization headers and encoded JWT payloads, decoded locally just enough to confirm the pattern.
Hardcoded credentials in config files, .env dumps, and inline scripts.
Postgres, MySQL, MongoDB, and Redis URIs with embedded credentials.
PEM and SSH private key blocks, matched at the header/footer boundary.
Define your own patterns for internal tokens, proprietary formats, or company-specific identifiers.
No, never. Detection runs entirely on-device, with no network calls.
No tool can guarantee that. PasteShield meaningfully reduces risk — it doesn’t eliminate it.
Not for the free tier.
PasteShield doesn’t keep a history of anything you copy. It’s a security tool, not a convenience tool.