Sensitive Field Exposure Analyzer
Flag suspicious field names like password, secret, apiKey, and token in API responses and schemas when they appear in outbound data. Free by Graph Tools.
Use this free sensitive field exposure analyzer to scan API response payloads and OpenAPI schemas for field names that suggest credentials or private data. The tool flags fields named password, secret, apiKey, privateKey, token, ssn, and similar patterns when they appear in outbound response data. Useful for security auditors, GDPR compliance reviews, and developers checking whether write-only fields are leaking into GET responses.