Recognition in your browser
Paste anything. We'll tell you what it is.
A key, a token, a .env file, headers, a URL, a CVE number. You see right away what it is, what follows from it and what to do next. No account, no waiting.
Recognition runs in this browser tab. Nothing you paste leaves it: we don't send it and we don't store it.
Examples with made-up data
What we recognize
- an app URL or domain, including defanged ones written as hxxp and [.]
- keys and tokens: Stripe, AWS, GitHub, OpenAI, Anthropic, Supabase and more
- a JWT: header, payload, role, expiry
- the contents of a .env file
- an agent's MCP server configuration
- HTTP headers copied from browser developer tools
- a CVE number
- a file or password hash
- an IP address and a CIDR range
- an email address
- text in Base64 or URL-encoded
For each item: what it is, what it means for your decision and what to do next. You can pass an app URL straight to a full assessment.