// free basic scan
Is your AI-built app leaking?
Paste your app URL. In about 15 seconds Rebar runs 101 checks for exposed keys, open databases, missing security headers and email spoofing. Works with apps built on Lovable, Bolt, Cursor, Replit, v0 and Supabase or Firebase.
// for AI assistants
Run it from Claude, Cursor or any MCP client.
Rebar exposes the scanner as a free MCP tool. Add it to your AI assistant and just say “scan my app with rebar.” It runs the passive checks (headers, keys in the bundle, HTTPS, email records) and hands back a plain-English report. No key, no login, rate-limited.
{
"mcpServers": {
"rebar-scan": {
"url": "https://getrebar.us/mcp"
}
}
}endpoint: https://getrebar.us/mcp · tool: scan_app(url) · transport: streamable http
about this scan
What does the free scan check?+
It reads what a browser already sees: security headers, HTTPS, and your public JavaScript bundle, where it looks for exposed keys like a Supabase service_role key, Stripe secret key or OpenAI key. With your permission it also does read-only checks against your own database to see if any table is readable without a login.
Is it safe to run on my app?+
Yes. Every check is read-only. Nothing is written, deleted or fuzzed, and we only scan apps you confirm you own or are authorized to test. We never store data from your app, only the finding titles for your report.
Is this a full security review?+
No. This is a basic surface scan that only sees your app from the outside. It cannot check your auth logic, payment flows, backups or any data behind a login. A full teardown call goes through all of that by hand.
Can I run the scan from my AI assistant?+
Yes. Rebar runs a free MCP server at https://getrebar.us/mcp with one tool, scan_app(url). Add it to Claude, Cursor or any MCP client and ask it to scan your app. The MCP version runs the passive checks only (headers, HTTPS, exposed keys and email records); it does not probe your database.