Arsenly
Tools
Free Tools
Pricing
Resources
Sign in Get started
← All tools

URL & Endpoint Extractor

Recon & Discovery Free · No sign-up

Mine URLs, hidden JS endpoints, domains, parameters and leaked secrets from any source - paste it, load a file, or fetch a remote JS.

Try it now No sign-up required. Runs entirely in your browser.

Paste or load content for instant in-browser extraction - or fetch a remote file (e.g. a JS bundle) by its URL.

Paste source, load a file, or fetch a URL - then Extract to mine
URLs, JS endpoints, domains, parameters and leaked secrets.

What is URL & Endpoint Extractor?

URL Extractor turns a blob of HTML / JavaScript / logs into structured recon. Beyond absolute URLs, it pulls out relative API endpoints hidden in JS (the LinkFinder workflow), the domains and query parameters referenced, sensitive files, and scans for leaked secrets (API keys, tokens, JWTs, private keys).

Extraction runs entirely in your browser. Optionally, the tool can fetch a remote file (e.g. a target’s main.js) server-side - SSRF-guarded and size-capped - so you can mine it without CORS getting in the way.

What it does

  • URLs & JS endpoints - absolute links plus relative API paths buried in JavaScript.
  • Secret scanning - flags AWS / Google / GitHub / Stripe / Slack keys, JWTs, bearer & api-key assignments and private keys.
  • Domains & parameters - every host and query-parameter name referenced.
  • Sensitive files - surfaces .env / .sql / .bak / key / config references.
  • Fetch remote files - pull a target’s JS/HTML (SSRF-guarded, 3 MB cap) and extract from it.
  • Filter & export - category chips, regex filter, per-view copy/download, pivots to SiteMapper / ProbeMaster / Vulnerability Scanner.

Where it fits in your workflow

  • Mine a JavaScript bundle for hidden API endpoints and hard-coded secrets.
  • Pull every domain/subdomain and parameter referenced in a page or app.
  • Feed the endpoint list straight into ProbeMaster or the Vulnerability Scanner.
Want more?

This one is free in your browser. Sign up for server-side recon, scan history, and projects.

Create free account Sign in

At a glance

CategoryRecon & Discovery
RunsIn your browser
Token cost Free - no tokens
Access No login needed
Status● Live

Frequently asked questions

Where does extraction happen?

In your browser - pasted/loaded content never leaves your machine. Only the optional “Fetch URL” uses the server (SSRF-guarded) to retrieve a remote file, which is then extracted client-side.

Are the detected secrets verified?

No - they are pattern matches and may include false positives. Confirm a key is live with the KeyHacks tool before reporting.

Other free tools you might like

Explore more tools →