Skip to main content
Coding agents read the same files and environment you do. passport scan lists the keys they can reach and what each key can do.
Already installed the Passport CLI? passport scan is the same command. It needs Node.js 20 or newer and no Passport account.
The last line is the next step: init connects those apps through Passport so your agents don’t need the keys. It isn’t shown when the scan finds nothing.

What it never does

  • Never shows a key. Output names the kind of key and where it is. No part of the value is printed or saved, not even its first characters or a hash.
  • Never connects to the network. The scan reads files on your computer and nothing else. Nothing leaves your machine.
  • Never changes anything. It only reads, and it never follows a link out of the project folder.

Where it looks

A sign-in kept in your system keychain isn’t flagged. The GitHub CLI does this by default, and so does the Stripe CLI for live keys. The scan says which ones it saw. The scan recognizes keys by each provider’s own format, or by a well-known variable name holding a real-looking value. Placeholders like your-key-here or ${STRIPE_KEY} are ignored. It prefers missing a key over flagging something that isn’t one, so a clean result means none of the keys it knows about, not none at all.

Severity

The same key found in several places is listed once. Add --verbose to see every place.

Options

Use it in CI or a pre-commit hook

The command exits 0 when it finds nothing high or medium, and 5 when it does. With --check the scan reads files only and skips the shell environment, so secrets your CI runner injects don’t fail the check.

JSON output

version changes only when a field changes meaning. unreadable counts files the scan found but couldn’t read.

Next

Connect these apps in Passport so agents use them through Passport instead of holding the keys. Start with the member quickstart.