Zaim Abbasi

Zaim Abbasi

APIRadar – Open-Source API Key ScannerAPIRadar – Open-Source API Key Scanner
fast UIs. wild backends.

About

Full‑stack developer, focused on turning messy, real‑world problems into reliable, production‑ready systems. I enjoy owning products end‑to‑end: from designing the data model and APIs to shipping clean frontends that developers actually want to use.

Badges

Tastemaker
Tastemaker
Gone streaking
Gone streaking
Gone streaking 5
Gone streaking 5

Maker History

Forums

5d ago

APIRadar – Open-Source API Key Scanner - Real-time leaked API key scanner for public GitHub repos

APIRadar is now 100% open-source with an upgraded multi-stage validation engine and live threat radar. It monitors public GitHub commits and code search for exposed credentials across 10+ providers (OpenAI, Anthropic, Google Gemini, OpenRouter, xAI, Groq, Cerebras, Slack, Discord, Telegram). Matches undergo regex filtering, static prefix stripping, Shannon Entropy scoring (H >= 2.5), and a custom trigram Markov model trained on the Google 10k English corpus to eliminate false positives.

Questions about API Radar – Live Feed of Leaked API Keys

I m a solo dev working on API Radar a live feed of leaked API keys and secrets found in public GitHub repos. Later today I m shipping a big rebuild of the search/detection engine, and I d love to sanity check a few things with this crowd before it goes fully live on Product Hunt.

A couple of questions for folks in security, DevOps/SRE, or backend roles:

  • What s the most useful way to present this kind of data so it actually helps you fix issues? (per repo view, per provider, timelines, alerts, something else?)

  • Where s the ethical line for you? The data is from public repos only, but what would make a tool like this clearly defensive and helpful rather than sketchy or abusable?

Blunt feedback is welcome on the idea, UX, or even whether this should exist at all.

9mo ago

API Radar - See your leaked API keys before attackers do

API Radar turns leaked API keys into a searchable threat feed for your own org. This new version rebuilds the core engine so it continuously discovers exposed keys in public GitHub, then lets you slice them by provider, repo, file path, and time to see exactly what’s out and where. Instead of digging through noisy scanners or random alerts, you get a focused view of real leaked credentials you can revoke and rotate fast.
View more