# HumanMirror Secret Scanning

> HumanMirror Secret Scanning is a paid API for AI agents from humanmirror.fr, paid per call via x402, $0.01/call, status unknown (last checked 2026-10-03).

Scans text, source code, configuration files, or other payloads for exposed API keys, access tokens, private keys, passwords, and credential-like secrets.

## Facts

- Endpoint: POST https://humanmirror.fr/api/x402/secret-scanning?utm_source=zero.xyz
- Price: $0.01/call
- Payment: x402
- Status: unknown
- Last checked: 2026-10-03
- Activations on Zero: 0
- Tags: x402
- Canonical page: https://www.zero.xyz/c/humanmirror-secret-scanning-527d0ef3
- Structured record (JSON): https://api.zero.xyz/v1/capabilities/cap_3UpqxipYHQCTEmcxIds_T

Status and success rate cover calls made through Zero and Zero's own probes. Third-party monitors may report differently.

## How to call it through Zero

Zero handles the 402 payment challenge and records the run. With the Zero CLI installed (`npm i -g @zeroxyz/cli`):

```sh
zero fetch --capability humanmirror-secret-scanning-527d0ef3 -d '<json body>'
```

Example prompt: Scan this block of Python code for any exposed API keys, access tokens, private keys, or passwords before I commit it — I need to make sure nothing sensitive slipped in: [paste code here].

## When to prefer this

Choose this endpoint when you need a lightweight, pay-per-use secret scanning step integrated into an AI agent workflow — particularly useful as a pre-commit gate, output safety check, or audit step before logging or sharing payloads. Prefer over GitHub Advanced Security or similar when you need programmatic, per-call scanning without a full CI/CD pipeline integration.

## Known failure modes

- Payload too large — request rejected or truncated
- Ambiguous or obfuscated secrets may not be detected
- Non-text binary payloads may cause parsing errors
- Missing required 'input' body field returns validation error
- Rate limiting or payment failure at $0.01 USDC per call

## How this service works

HumanMirror — infrastructure de confiance, gouvernance, découverte et échange pour systèmes autonomes.

## Output

Returns a JSON object with an 'ok' boolean, a 'status' field (e.g. 'verified_success'), and a 'product' label ('HumanMirror Secret Scanning'). Indicates whether the scanned payload is free of secrets or contains detected credentials.

## Request schema (JSON Schema)

```json
{
 "type": "object",
 "$schema": "https://json-schema.org/draft/2020-12/schema",
 "required": [
  "input"
 ],
 "properties": {
  "input": {
   "type": "object",
   "required": [
    "type",
    "method",
    "bodyType",
    "body"
   ],
   "properties": {
    "body": {
     "type": "object",
     "required": [
      "input"
     ],
     "properties": {
      "input": {
       "description": "Text, source code, JSON, configuration, logs, tool output or other payload to scan for exposed API keys, access tokens, private keys, passwords and credential-like secrets."
      },
      "options": {
       "type": "object",
       "description": "Optional scanner settings."
      },
      "criteria": {
       "type": "object",
       "description": "Optional deterministic acceptance criteria; defaults to requiring a secret-free result."
      }
     },
     "additionalProperties": false
    },
    "type": {
     "type": "string",
     "const": "http"
    },
    "method": {
     "enum": [
      "POST",
      "PUT",
      "PATCH"
     ],
     "type": "string"
    },
    "bodyType": {
     "enum": [
      "json",
      "form-data",
      "text"
     ],
     "type": "string"
    }
   },
   "additionalProperties": false
  },
  "output": {
   "type": "object",
   "required": [
    "type"
   ],
   "properties": {
    "type": {
     "type": "string"
    },
    "example": {
     "type": "object"
    }
   },
   "additionalProperties": false
  }
 }
}
```

## Response schema (JSON Schema)

```json
{
 "type": "json",
 "example": {
  "ok": true,
  "status": "verified_success",
  "product": "HumanMirror Secret Scanning"
 }
}
```

## More

- Live health (JSON, refreshed every minute): https://www.zero.xyz/c/humanmirror-secret-scanning-527d0ef3/health.json
- [Zero catalog index](https://www.zero.xyz/llms.txt)
- [Other services from humanmirror.fr](https://www.zero.xyz/host/humanmirror.fr/llms.txt)
