MrEmpy/mantra

「🔑」A tool used to hunt down API key leaks in JS files and pages

941

stars

56

commits

Go

primary language

Mar 12, 2026

updated

amolo.com.br
api
bugbounty
files
hacking
javascript
js
key
leak
leaked-secrets
pentest
security
tool

README

「🔑」 About Mantra

The tool in question was created in Go and its main objective is to search for API keys in JavaScript files and HTML pages.

It works by checking the source code of web pages and script files for strings that are identical or similar to API keys. These keys are often used for authentication to online services such as third-party APIs and are confidential and should not be shared publicly.

By using this tool, developers can quickly identify if their API keys are leaking and take steps to fix the problem before they are compromised. Furthermore, the tool can be useful for security officers, who can use it to verify that applications and websites that use external APIs are adequately protecting their keys.

In summary, this tool is an efficient and accurate solution to help secure your API keys and prevent sensitive information leaks.

Help

Usage

Install

From go:

go install github.com/Brosck/mantra@latest

From source code:

git clone https://github.com/brosck/mantra
cd mantra
make
./build/mantra-amd64-linux -h

Results

Firebase API Key Leak: image

Buy me a coffee?



Contributors

brosck

44 commits

tomikoski

10 commits

ManojINaik

1 commits

tr3ss

1 commits

MrEmpy/mantra

「🔑」A tool used to hunt down API key leaks in JS files and pages

941

stars

56

commits

Go

primary language

Mar 12, 2026

updated

amolo.com.br
api
bugbounty
files
hacking
javascript
js
key
leak
leaked-secrets
pentest
security
tool

README

「🔑」 About Mantra

The tool in question was created in Go and its main objective is to search for API keys in JavaScript files and HTML pages.

It works by checking the source code of web pages and script files for strings that are identical or similar to API keys. These keys are often used for authentication to online services such as third-party APIs and are confidential and should not be shared publicly.

By using this tool, developers can quickly identify if their API keys are leaking and take steps to fix the problem before they are compromised. Furthermore, the tool can be useful for security officers, who can use it to verify that applications and websites that use external APIs are adequately protecting their keys.

In summary, this tool is an efficient and accurate solution to help secure your API keys and prevent sensitive information leaks.

Help

Usage

Install

From go:

go install github.com/Brosck/mantra@latest

From source code:

git clone https://github.com/brosck/mantra
cd mantra
make
./build/mantra-amd64-linux -h

Results

Firebase API Key Leak: image

Buy me a coffee?



Contributors

brosck

44 commits

tomikoski

10 commits

ManojINaik

1 commits

tr3ss

1 commits

Languages

Go

98.4%

Makefile

1.1%