passport scan lists the keys they can reach and what each key can do.
passport scan is the same command. It needs Node.js 20 or newer and no Passport account.
init connects those apps through Passport so your agents don’t need the keys. It isn’t shown when the scan finds nothing.
What it never does
- Never shows a key. Output names the kind of key and where it is. No part of the value is printed or saved, not even its first characters or a hash.
- Never connects to the network. The scan reads files on your computer and nothing else. Nothing leaves your machine.
- Never changes anything. It only reads, and it never follows a link out of the project folder.
Where it looks
A sign-in kept in your system keychain isn’t flagged. The GitHub CLI does this by default, and so does the Stripe CLI for live keys. The scan says which ones it saw.
The scan recognizes keys by each provider’s own format, or by a well-known variable name holding a real-looking value. Placeholders like
your-key-here or ${STRIPE_KEY} are ignored. It prefers missing a key over flagging something that isn’t one, so a clean result means none of the keys it knows about, not none at all.
Severity
The same key found in several places is listed once. Add
--verbose to see every place.
Options
Use it in CI or a pre-commit hook
--check the scan reads files only and skips the shell environment, so secrets your CI runner injects don’t fail the check.
JSON output
version changes only when a field changes meaning. unreadable counts files the scan found but couldn’t read.