{
  "product": "keydrift",
  "site": "https://keydrift.dev",
  "tool": "KeyDrift public scan (POST /api/v1/scan/public)",
  "subject": "keydrift.dev/demo-target — KeyDrift's own demo page, which deliberately ships a service_role-shaped key",
  "scanned_at": "2026-09-07T08:59:08Z",
  "result": "FOUND",
  "finding": "service_role key in the browser (Supabase JWT, critical) in demo-target/app.js; 1 public credential (Supabase anon key) recognised and ignored on purpose",
  "summary": { "critical": 1, "high": 0, "medium": 0, "low": 0, "info": 1, "actionable": 1, "worst": "critical" },
  "findings": [
    { "rule": "supabase-jwt", "disposition": "secret", "severity": "critical", "label": "Supabase service_role key" },
    { "rule": "supabase-jwt", "disposition": "public", "severity": "info", "label": "Supabase anon key" }
  ],
  "how_produced": "KeyDrift scanned its own static demo page on production. The key it finds is a syntactically valid Supabase-shaped JWT with role service_role, signed with a throwaway secret; it belongs to no project and grants nothing — it exists so the scan can be repeated by anyone (https://keydrift.dev/scan?url=https://keydrift.dev/demo-target/). The report shows only a masked prefix and a fingerprint; no key material is stored.",
  "source_url": "https://keydrift.dev/reports/5be0c687-3c2e-46b7-a4b8-8f11df34c2b0",
  "earlier_clean_scan": "https://keydrift.dev/reports/feb16dd3-81f3-4d36-a799-c62d75ef4e7f",
  "note": "A real scan, a deliberately planted test key, no customer data."
}
