Mine URLs, hidden JS endpoints, domains, parameters and leaked secrets from any source - paste it, load a file, or fetch a remote JS.
Paste or load content for instant in-browser extraction - or fetch a remote file (e.g. a JS bundle) by its URL.
Paste source, load a file, or fetch a URL - then Extract to mine
URLs, JS endpoints, domains, parameters and leaked secrets.
URL Extractor turns a blob of HTML / JavaScript / logs into structured recon. Beyond absolute URLs, it pulls out relative API endpoints hidden in JS (the LinkFinder workflow), the domains and query parameters referenced, sensitive files, and scans for leaked secrets (API keys, tokens, JWTs, private keys).
Extraction runs entirely in your browser. Optionally, the tool can fetch a remote file (e.g. a target’s main.js) server-side - SSRF-guarded and size-capped - so you can mine it without CORS getting in the way.
This one is free in your browser. Sign up for server-side recon, scan history, and projects.
Create free account Sign inIn your browser - pasted/loaded content never leaves your machine. Only the optional “Fetch URL” uses the server (SSRF-guarded) to retrieve a remote file, which is then extracted client-side.
No - they are pattern matches and may include false positives. Confirm a key is live with the KeyHacks tool before reporting.