API Key Health treats leak detection carefully. The platform can ingest safe leak signals such as GitHub secret-scanning webhooks and provider-reported leak states, while avoiding raw public code searches with user secrets.
Safe GitHub secret-scanning webhook route
Rotation-required metadata
No raw-key public code search
Each solution page is written to answer a real search question while still explaining exactly what API Key Health can and cannot see from provider APIs.
Record leak findings without exposing raw keys to public search.
Mark affected keys for rotation when safe leak signals arrive.
Store redacted finding metadata for audit and review.
Keep leak wording scoped to what has actually been detected.
Configure GitHub secret scanning or provider leak signal where supported.
Send safe webhook events to API Key Health.
Review affected keys and rotate credentials.
Keep historical findings redacted and auditable.
These pages use clear answers, schema, internal links, and provider-specific language so crawlers can understand the product without guessing.
No. Sending raw API keys to public code search would create a security risk. API Key Health is designed around safe signals such as GitHub secret-scanning webhooks and provider-reported leak states.