Credential screenshot cleaner

Hide API keys in screenshots

A leaked screenshot can turn a harmless support question into a compromised account. Check it locally before posting.

Local firstNo sign upFree

Privacy studio

Nothing uploads during local scan

Paste anywhere

What it checks

A careful first pass, under your control.

  • Common API key prefixes
  • Bearer tokens
  • JSON Web Tokens
  • Long secret strings
  • Authorization headers
  • Anything you mark manually

How to use it

Done in three steps.

  1. 01

    Paste the screenshot from your clipboard.

  2. 02

    Run the local pattern scan.

  3. 03

    Cover anything uncertain manually and export.

Questions

Useful details.

Does this revoke a leaked key?+

No. If a secret was already shared, revoke and rotate it with the provider immediately. Redaction only protects the new image.

Can every key format be detected?+

No detector can guarantee that. MaskSnap checks common patterns and lets you draw over anything it misses.

What if the scanner misses a key?+

Draw a solid block over it manually. Avoid sending active secrets to any external service.

See all tools