Secrets
Reads every JavaScript file your site ships and looks for keys that should never be there: a Supabase service_role key (full access to your database), Stripe, OpenAI and Anthropic keys, AWS, GitHub and email-service tokens.
Security check for apps you built with AI
You shipped an app with Lovable, Bolt, Cursor or another AI assistant. Paste its URL and Lockright checks it the way a stranger would, for the mistakes that actually get people: leaked keys, Supabase tables and buckets anyone can read, functions and admin pages with no login check. You get a score, and every problem comes with a fix prompt you paste straight into your AI editor.
One-time purchase · Universal Mac app for Apple silicon and Intel (tested on Apple silicon) · No account, no subscription
These are the boring, predictable holes, not exotic exploits. They're also the ones AI-built apps leave open most often.
Reads every JavaScript file your site ships and looks for keys that should never be there: a Supabase service_role key (full access to your database), Stripe, OpenAI and Anthropic keys, AWS, GitHub and email-service tokens.
Asks your Supabase tables for rows and your storage buckets for file lists using only the public key, exactly like a stranger's browser would. If Row Level Security or a storage policy is wrong, it shows you what came back.
Calls your edge functions with no login and with a fake one, and tries /admin and routes like /api/users. Anything that answers can be used by anyone, on your bill.
Browser protections (CSP, HSTS, clickjacking), your HTTPS certificate and redirects, cookie flags, and the SPF and DMARC records that stop strangers sending email as you.
Looks for a deployed .env under every name and folder it hides in, an exposed .git folder, backups, source maps and folders that list every file inside them.
Tests whether any website can call your API with your visitors' logins attached.
Point it at your project folder and it lists risky leftovers: a .env that got committed or dropped in the public folder, a secret under a VITE_ or NEXT_PUBLIC_ name, placeholder secrets, security TODOs nobody finished, disabled auth checks, eval(). It never edits your files.
Lockright reads the JavaScript your site already ships and finds your Supabase project, its public key, and the tables, functions and buckets the app uses. You check the list and save.
Usually under thirty seconds. You see exactly which checks will run, and why any are skipped, before it starts. The result is a score: 4 of 6 locked.
Every problem has a fix prompt written for your AI editor. Copy one, or copy the fix pack to fix them all worst first, then re-run to see the lock close. History keeps every run.
Lockright doesn't stop at a report. It hands the fix to the tool that wrote the code, and keeps checking after you ship.
--fail-on high fails a CI build when a lock opens. A ready GitHub Action is included.Every check makes the same kinds of requests a normal browser makes. Nothing is written, changed or deleted.
service_role key by mistake and it stops and tells you.A static site or PWA on Cloudflare Pages, GitHub Pages, Netlify or Vercel, with an optional Supabase backend and edge functions.
It isn't a penetration test or a substitute for a security review. It checks the common holes, fast. No Supabase? You still get the secrets, headers, HTTPS, cookies, email, public files, admin routes and CORS checks.
A universal Mac app for Apple silicon and Intel, tested on Apple silicon. Run it as often as you like, on every app you own.
Buy LockrightSold through Gumroad. Your receipt has the license key. Needs macOS 11 or later.
No. You paste your app's address and Lockright finds the rest. Results come in plain English, and every problem has a fix prompt you can hand to your AI editor.
Yes. Lockright includes an MCP server. Add it to Claude Code or Cursor with the command shown in Settings, then ask your editor to scan your site and fix what's open.
Yes. lockright scan https://your-app.com --fail-on high exits with an error when a High or Critical problem shows up. A GitHub Action example is included. Build servers read your license key from a secret and don't count as one of your computers.
Your Gumroad receipt has one key. Paste it into Lockright once and that computer is activated for the app, the command line and the MCP server, online or off. One key covers up to five of your own computers, and you can release one in Settings to move it.
Yes. The anon key is the public key your app already sends to every visitor's browser. Lockright uses it to see what a visitor could see. It refuses to run with a service_role key, which is the one you must never share.
No. The app is read-only. Write tests exist only on the command line, only against staging or local databases, and only after you type the app's name to confirm.
To check your site the way a stranger would, it has to read another site's responses, and browsers block websites from doing that. So Lockright runs on your computer instead.
Lockright isn't notarized by Apple yet. Open it once, then go to System Settings › Privacy & Security and click Open Anyway. You only do this the first time.
Not yet. The Mac app comes first.
Secrets, headers, HTTPS, cookies, email, public files, admin routes and CORS work on any website. The Supabase table, storage and edge-function checks are skipped, the score says so ("4 of 4 locked · 2 not checked"), and Lockright tells you why.