Paste safely into
AI chats.
SecretPaste protects you in the browser and on desktop — detecting secrets before they reach AI chats, and helping you mask or block API keys instantly.
SecretPaste blocked a potential leak
An API key was detected in your message. It has been masked to prevent accidental exposure.
Why SecretPaste?
A small tool that prevents a big mistake: pasting secrets into AI chats.
Local-only detection
Secret detection runs in your browser. No servers, no accounts, no data leaving your device.
Low-ops install
Install and forget. Sensible defaults with quick toggles for allowlist and masking.
Mask or block
Stop accidental leaks with instant masking and clear warnings before you hit paste.
Built for dev flow
Fast UI, minimal permissions, and patterns that match the tokens developers paste every day.
SecretPaste
Never accidentally leak an API key in ChatGPT, Claude, or any AI chat again.
Key Features
- Real-time paste detection
- Support for 15+ secret patterns
- Instant visual masking
- Configurable allowlist
- Zero network requests
Simple, transparent pricing
Start free, upgrade when you need more. No hidden fees, no surprises.
Free
For individual developers getting started.
- ChatGPT protection
- 5 secret patterns
- 10 allowlist entries
- Visual warnings
- Desktop app (macOS)
- Desktop app (Windows/Linux) — coming soon
- Multi-site support
- Mask & Paste
- Unlimited allowlist
Pro
For professionals who need more power. Includes 2 devices per license.
Billed monthly
- Everything in Free
- 7 AI chat sites supported
- 15+ secret patterns
- Unlimited allowlist
- Mask & Paste feature
- Desktop app (macOS)
- Priority support
- 2 devices per license
Lifetime
One-time payment for permanent Pro access. No recurring charges.
Pay once, use forever
- Everything in Free
- 7 AI chat sites supported
- 15+ secret patterns
- Unlimited allowlist
- Mask & Paste feature
- Desktop app (macOS)
- Priority support
- 3 devices per license
- No recurring billing
Frequently asked questions
Your secrets stay yours
We built SecretPaste with a simple principle: your data should never leave your device. No exceptions, no compromises.
No telemetry by default
We don't track usage, collect analytics, or monitor what you type. Your workflow is yours alone.
Local-only detection
All secret detection happens in your browser. Nothing is sent to our servers or any third party.
No cloud dependency for detection
All secret detection runs locally — no accounts, no sign-ins required. Pro license validation makes a brief periodic check with our payment provider; your clipboard content is never involved.
Security Note
While SecretPaste helps prevent accidental leaks, it is not a substitute for proper secret management. Always:
- •Use environment variables for API keys in code
- •Rotate compromised credentials immediately
- •Use dedicated secret management tools for teams
- •Review AI chat history for sensitive data