Skip to main content
The Keys & Secrets section displays all leaked credentials, API keys, tokens, and other sensitive data discovered during your scans. Jsmon automatically detects common secret patterns in JavaScript files and other web assets.

Overview

The Keys & Secrets page provides a searchable, filterable table of all discovered secrets with the following columns:
  • Secret — The type of secret detected (e.g., AWS Access Key, GitHub Token, Stripe Key)
  • Severity — The risk level of the exposed secret
  • Value — The actual secret value found (partially masked for safety)
  • Found On — The date the secret was discovered

Searching for Secrets

The search bar at the top accepts pattern-based queries. You can search for specific secret prefixes such as:
  • sk_live_ — Stripe live secret keys
  • ghp_ — GitHub personal access tokens
  • AKIA — AWS access key IDs
  • Any custom pattern relevant to your target

Filtering

Use the available filters to narrow your results:
  • Severity — Filter by Critical, High, Medium, or Low severity
  • Date — Filter by the date range when secrets were discovered

Exporting

Click the Export button to download your secrets data for reporting or further analysis.

Custom Modules

Jsmon supports custom detection modules that allow you to define your own secret patterns. This feature is available on the Recon plan and above. Custom modules let you:
  • Define regex patterns for proprietary or uncommon secret formats
  • Set severity levels for custom detections
  • Apply custom modules across all your scans
To access Custom Modules, click the Custom Modules button at the top of the Keys & Secrets page.
Custom Modules are available on the Recon (15/mo)andReconPro(15/mo) and Recon Pro (50/mo) plans. The free Starter plan does not include this feature.