Skip to main content

Patrones de examen de secretos admitidos

Listas de los secretos admitidos y los asociados con los que trabaja GitHub para evitar el uso fraudulento de secretos que se confirmaron por accidente.

ยฟQuiรฉn puede utilizar esta caracterรญstica?

Secret scanning estรก disponible para los tipos de repositorio siguientes:

  • Repositorios pรบblicos en GitHub.com
  • Repositorios propiedad de la organizaciรณn en GitHub Team o GitHub Enterprise Cloud con GitHub Secret Protection habilitado
  • Repositorios propiedad del usuario para GitHub Enterprise Cloud con Enterprise Managed Users

About secret scanning patterns

There are three types of secret scanning alerts:

  • User alerts: Reported to users in the Security tab of the repository, when a supported secret is detected in the repository.
  • Push protection alerts: Reported to users in the Security tab of the repository, when a contributor bypasses push protection.
  • Partner alerts: Reported directly to secret providers that are part of secret scanning's partner program. These alerts are not reported in the Security tab of the repository.

For in-depth information about each alert type, see About secret scanning alerts.

For details about all the supported patterns, see the Supported secrets section below.

If you use the REST API for secret scanning, you can use the Secret type to report on secrets from specific issuers. For more information, see REST API endpoints for secret scanning.

If you believe that secret scanning should have detected a secret committed to your repository, and it has not, you first need to check that GitHub supports your secret. For more information, refer to the following sections. For more advanced troubleshooting information, see Troubleshooting secret scanning.

Supported secrets

This table lists the secrets supported by secret scanning. You can see the types of alert that get generated for each token, as well as whether a validity check is performed on the token.

  • Provider: Name of the token provider.

  • Partner: Token for which leaks are reported to the relevant token partner. Applies to public repositories only.

  • User: Token for which leaks are reported to users on GitHub.

    • Applies to public repositories, and to private repositories where GitHub Secret Protection and secret scanning are enabled.
    • Includes default tokens, which relate to supported patterns and specified custom patterns, as well as non-provider tokens such as private keys, which usually have a higher ratio of false positives.
    • For secret scanning to scan for non-provider patterns, the detection of non-provider patterns must be enabled for the repository or the organization. For more information, see Enabling secret scanning for your repository.
  • Push protection: Token for which leaks are reported to users on GitHub. Applies to repositories with secret scanning and push protection enabled.

  • Validity check: Token for which a validity check is implemented. For partner tokens, GitHub sends the token to the relevant partner. Note that not all partners are based in the United States. For more information, see Advanced Security in the Site Policy documentation.

Non-provider patterns

ProviderToken
Genericec_private_key
Generichttp_basic_authentication_header
Generichttp_bearer_authentication_header
Genericmongodb_connection_string
Genericmysql_connection_string
Genericopenssh_private_key
Genericpgp_private_key
Genericpostgres_connection_string
Genericrsa_private_key

Nota:

Validity checks are not supported for non-provider patterns.

Copilot secret scanning

Secret scanning uses Copilot to detect generic passwords. See Responsible detection of generic secrets with Copilot secret scanning.

ProviderToken
Genericpassword

Nota:

Push protection and validity checks are not supported for passwords.

Default patterns

Nota:

Validity checks are only available to users with GitHub Team or GitHub Enterprise who enable the feature as part of GitHub Secret Protection.

ProviderTokenPartnerUserPush protectionValidity checkBase64
1Password1password_service_account_tokenโœ—โœ“โœ“โœ—โœ—
Adafruitadafruit_io_keyโœ“โœ“โœ“โœ“โœ—
Adobeadobe_client_secretโœ“โœ“โœ“โœ—โœ—
Adobeadobe_device_tokenโœ“โœ“โœ“โœ—โœ—
Adobeadobe_pac_tokenโœ“โœ“โœ“โœ—โœ—
Adobeadobe_refresh_tokenโœ“โœ“โœ“โœ—โœ—
Adobeadobe_service_tokenโœ“โœ“โœ“โœ—โœ—
Adobeadobe_short_lived_access_tokenโœ“โœ“โœ“โœ—โœ—
Aikidoaikido_api_client_secretโœ—โœ“โœ“โœ—โœ—
Aikidoaikido_ci_scanning_tokenโœ—โœ“โœ“โœ—โœ—
Airtableairtable_api_keyโœ—โœ“โœ—โœ—โœ—
Airtableairtable_personal_access_tokenโœ—โœ“โœ“โœ—โœ—
Aivenaiven_auth_tokenโœ“โœ“โœ“โœ—โœ—
Aivenaiven_service_passwordโœ“โœ“โœ“โœ—โœ—
Alibabaalibaba_cloud_access_key_id
alibaba_cloud_access_key_secret
โœ“โœ“โœ“โœ—โœ—
Amazon AWSaws_access_key_id
aws_secret_access_key
โœ“โœ“โœ“โœ“โœ—
Amazon AWSaws_api_keyโœ“โœ“โœ—โœ—โœ—
Amazon AWSaws_secret_access_key
aws_session_token
aws_temporary_access_key_id
โœ—โœ“โœ“โœ“โœ—
Anthropicanthropic_admin_api_keyโœ“โœ“โœ“โœ“โœ—
Anthropicanthropic_api_keyโœ“โœ“โœ“โœ“โœ—
Anthropicanthropic_session_idโœ“โœ“โœ“โœ—โœ—
Apifyapify_actor_run_api_tokenโœ“โœ“โœ“โœ—โœ—
Apifyapify_actor_run_proxy_passwordโœ“โœ“โœ“โœ—โœ—
Apifyapify_api_tokenโœ“โœ“โœ“โœ“โœ—
Apifyapify_integration_api_tokenโœ“โœ“โœ“โœ—โœ—
Apifyapify_proxy_passwordโœ“โœ“โœ“โœ—โœ—
Apifyapify_ui_tokenโœ“โœ“โœ“โœ—โœ—
Apifyapify_webhook_dispatch_api_tokenโœ“โœ“โœ“โœ—โœ—
Asaasasaas_api_tokenโœ“โœ“โœ—โœ“โœ—
Asanaasana_legacy_format_personal_access_tokenโœ—โœ“โœ—โœ—โœ—
Asanaasana_personal_access_token
Token versions
โœ—โœ“โœ“โœ—โœ—
Atlassianatlassian_api_token
Token versions
โœ“โœ“โœ“โœ—โœ—
Atlassianatlassian_jwtโœ“โœ“โœ“โœ—โœ—
Authressauthress_service_client_access_keyโœ“โœ“โœ“โœ—โœ—
Azureazure_active_directory_application_secret
Token versions
โœ“โœ“โœ“โœ—โœ—
Azureazure_active_directory_user_credentialโœ“โœ“โœ—โœ—โœ—
Azureazure_ai_services_keyโœ“โœ“โœ“โœ—โœ—
Azureazure_anomaly_detector_ee_keyโœ“โœ“โœ“โœ—โœ—
Azureazure_anomaly_detector_keyโœ“โœ“โœ“โœ—โœ—
Azureazure_apim_direct_management_keyโœ“โœ“โœ“โœ—โœ—
Azureazure_apim_gateway_keyโœ“โœ“โœ“โœ—โœ—
Azureazure_apim_repository_keyโœ“โœ“โœ“โœ“โœ—
Azureazure_apim_subscription_keyโœ“โœ“โœ“โœ—โœ—
Azureazure_app_configuration_connection_stringโœ—โœ“โœ“โœ“โœ—
Azureazure_app_configuration_keyโœ“โœ“โœ“โœ—โœ—
Azureazure_batch_key_identifiableโœ“โœ“โœ“โœ—โœ—
Azureazure_cache_for_redis_access_keyโœ“โœ“โœ“โœ—โœ—
Azureazure_cognitive_services_keyโœ“โœ“โœ“โœ—โœ—
Azureazure_communication_services_connection_stringโœ—โœ“โœ“โœ“โœ—
Azureazure_communication_services_keyโœ“โœ“โœ“โœ—โœ—
Azureazure_computer_vision_keyโœ“โœ“โœ“โœ—โœ—
Azureazure_container_registry_key_identifiableโœ“โœ“โœ“โœ—โœ—
Azureazure_content_moderator_keyโœ“โœ“โœ“โœ—โœ—
Azureazure_content_safety_keyโœ“โœ“โœ“โœ—โœ—
Azureazure_cosmosdb_key_identifiableโœ“โœ“โœ“โœ—โœ—
Azureazure_custom_vision_prediction_keyโœ“โœ“โœ“โœ—โœ—
Azureazure_custom_vision_training_keyโœ“โœ“โœ“โœ—โœ—
Azureazure_devops_personal_access_token
Token versions
โœ“โœ“โœ“โœ“โœ—
Azureazure_event_grid_key_identifiable
Token versions
โœ“โœ“โœ“โœ—โœ—
Azureazure_event_hub_key_identifiableโœ“โœ“โœ“โœ—โœ—
Azureazure_face_keyโœ“โœ“โœ“โœ—โœ—
Azureazure_fluid_relay_keyโœ“โœ“โœ“โœ—โœ—
Azureazure_form_recognizer_keyโœ“โœ“โœ“โœ—โœ—
Azureazure_function_keyโœ“โœ“โœ“โœ—โœ—
Azureazure_health_decision_support_keyโœ“โœ“โœ“โœ—โœ—
Azureazure_health_insights_keyโœ“โœ“โœ“โœ—โœ—
Azureazure_immersive_reader_keyโœ“โœ“โœ“โœ—โœ—
Azureazure_internal_all_in_one_keyโœ“โœ“โœ“โœ—โœ—
Azureazure_iot_device_connection_stringโœ—โœ“โœ“โœ“โœ—
Azureazure_iot_device_keyโœ“โœ“โœ“โœ—โœ—
Azureazure_iot_device_provisioning_keyโœ“โœ“โœ“โœ—โœ—
Azureazure_iot_hub_connection_stringโœ—โœ“โœ“โœ“โœ—
Azureazure_iot_hub_keyโœ“โœ“โœ“โœ—โœ—
Azureazure_iot_provisioning_connection_stringโœ—โœ“โœ“โœ“โœ—
Azureazure_knowledge_keyโœ“โœ“โœ“โœ—โœ—
Azureazure_luis_authoring_keyโœ“โœ“โœ“โœ—โœ—
Azureazure_luis_keyโœ“โœ“โœ“โœ—โœ—
Azureazure_management_certificateโœ“โœ“โœ“โœ—โœ—
Azureazure_maps_keyโœ“โœ“โœ“โœ“โœ—
Azureazure_metrics_advisor_keyโœ“โœ“โœ“โœ—โœ—
Azureazure_mixed_reality_keyโœ“โœ“โœ“โœ—โœ—
Azureazure_ml_inference_identifiable_keyโœ“โœ“โœ“โœ—โœ—
Azureazure_ml_internal_service_principal_identifiable_keyโœ“โœ—โœ—โœ—โœ—
Azureazure_ml_web_service_classic_identifiable_keyโœ“โœ“โœ“โœ—โœ—
Azureazure_openai_keyโœ“โœ“โœ“โœ—โœ—
Azureazure_personalizer_keyโœ“โœ“โœ“โœ—โœ—
Azureazure_qna_maker_keyโœ“โœ“โœ“โœ—โœ—
Azureazure_qna_maker_v2_keyโœ“โœ“โœ“โœ—โœ—
Azureazure_quantum_keyโœ“โœ“โœ“โœ—โœ—
Azureazure_relay_key_identifiableโœ“โœ“โœ“โœ—โœ—
Azureazure_sas_tokenโœ“โœ“โœ“โœ—โœ—
Azureazure_search_admin_keyโœ“โœ“โœ“โœ—โœ—
Azureazure_search_query_keyโœ“โœ“โœ“โœ—โœ—
Azureazure_service_bus_identifiableโœ“โœ“โœ“โœ—โœ—
Azureazure_signalr_connection_stringโœ—โœ“โœ“โœ—โœ—
Azureazure_signalr_key
Token versions
โœ“โœ“โœ“โœ—โœ—
Azureazure_speech_services_keyโœ“โœ“โœ“โœ—โœ—
Azureazure_speech_translation_keyโœ“โœ“โœ“โœ—โœ—
Azureazure_sql_connection_stringโœ“โœ“โœ—โœ—โœ—
Azureazure_sql_internal_default_cloudsa_keyโœ“โœ—โœ—โœ—โœ—
Azureazure_sql_passwordโœ“โœ“โœ“โœ—โœ—
Azureazure_storage_account_key
Token versions
โœ“โœ“โœ“โœ—โœ—
Azureazure_storage_account_key_base64โœ“โœ“โœ“โœ—โœ“
Azureazure_text_analytics_keyโœ“โœ“โœ“โœ—โœ—
Azureazure_text_translation_keyโœ“โœ“โœ“โœ—โœ—
Azureazure_video_intelligence_keyโœ“โœ“โœ“โœ—โœ—
Azureazure_web_app_bot_keyโœ“โœ“โœ“โœ—โœ—
Azureazure_web_pub_sub_connection_stringโœ—โœ“โœ“โœ—โœ—
Azureazure_web_pub_sub_key
Token versions
โœ“โœ“โœ“โœ—โœ—
Azuremicrosoft_azure_entra_id_tokenโœ—โœ“โœ“โœ“โœ—
Azuremicrosoft_corporate_network_user_credentialโœ“โœ“โœ—โœ—โœ—
Baidubaiducloud_api_accesskeyโœ“โœ“โœ“โœ—โœ—
Beamerbeamer_api_keyโœ—โœ“โœ“โœ—โœ—
Bitbucketbitbucket_server_personal_access_tokenโœ—โœ“โœ“โœ—โœ—
Bitrisebitrise_personal_access_tokenโœ“โœ“โœ“โœ“โœ—
Bitrisebitrise_workspace_api_tokenโœ“โœ“โœ“โœ“โœ—
Block Protocolblock_protocol_api_keyโœ—โœ“โœ—โœ“โœ—
Brevosendinblue_api_keyโœ“โœ“โœ“โœ“โœ—
Brevosendinblue_smtp_keyโœ“โœ“โœ“โœ—โœ—
Buildkitebuildkite_agent_access_tokenโœ“โœ“โœ“โœ—โœ—
Buildkitebuildkite_agent_job_tokenโœ“โœ“โœ“โœ—โœ—
Buildkitebuildkite_agent_registration_tokenโœ“โœ“โœ“โœ—โœ—
Buildkitebuildkite_cluster_queue_tokenโœ“โœ“โœ“โœ—โœ—
Buildkitebuildkite_cluster_tokenโœ“โœ“โœ“โœ—โœ—
Buildkitebuildkite_packages_registry_tokenโœ“โœ“โœ“โœ—โœ—
Buildkitebuildkite_packages_temporary_tokenโœ“โœ“โœ“โœ—โœ—
Buildkitebuildkite_portal_secretโœ“โœ“โœ“โœ—โœ—
Buildkitebuildkite_portal_tokenโœ“โœ“โœ“โœ—โœ—
Buildkitebuildkite_user_access_tokenโœ“โœ“โœ—โœ—โœ—
Canadian Digital Servicecds_canada_notify_api_keyโœ“โœ“โœ“โœ“โœ—
Canvacanva_app_secretโœ“โœ“โœ“โœ—โœ—
Canvacanva_connect_api_secretโœ“โœ“โœ“โœ—โœ—
Canvacanva_secretโœ“โœ“โœ“โœ—โœ—
Cashfreecashfree_api_keyโœ“โœ“โœ“โœ—โœ—
Cfx.recfxre_server_keyโœ“โœ“โœ—โœ—โœ—
Checkout.comcheckout_production_secret_key
Token versions
โœ“โœ“โœ“โœ“โœ—
Checkout.comcheckout_test_secret_key
Token versions
โœ“โœ“โœ“โœ“โœ—
Chief Toolschief_tools_tokenโœ“โœ“โœ“โœ—โœ—
CircleCIcircleci_bot_access_tokenโœ“โœ“โœ“โœ—โœ—
CircleCIcircleci_personal_access_tokenโœ“โœ“โœ“โœ“โœ—
CircleCIcircleci_project_access_tokenโœ“โœ“โœ“โœ—โœ—
CircleCIcircleci_release_integration_tokenโœ“โœ“โœ“โœ—โœ—
Clojarsclojars_deploy_tokenโœ“โœ“โœ“โœ—โœ—
CloudBeescodeship_credentialโœ“โœ—โœ—โœ—โœ—
Cockroach Labsccdb_api_keyโœ“โœ“โœ—โœ“โœ—
Coherecohere_api_keyโœ—โœ“โœ—โœ—โœ—
Contentfulcontentful_personal_access_tokenโœ“โœ“โœ“โœ“โœ—
Contentfulcontentful_web_tokenโœ“โœ“โœ“โœ—โœ—
Contributed Systemscontributed_systems_credentialsโœ“โœ—โœ—โœ—โœ—
Coveocoveo_access_tokenโœ“โœ—โœ—โœ—โœ—
Coveocoveo_api_keyโœ“โœ—โœ—โœ—โœ—
crates.iocratesio_api_tokenโœ“โœ“โœ“โœ—โœ—
Databentodatabento_api_keyโœ“โœ“โœ—โœ“โœ—
Databricksdatabricks_access_tokenโœ“โœ“โœ“โœ—โœ—
Datadogdatadog_api_keyโœ“โœ—โœ—โœ—โœ—
Datadogdatadog_app_keyโœ“โœ—โœ—โœ—โœ—
Datadogdatadog_rcmโœ—โœ“โœ—โœ—โœ—
Datastaxdatastax_astracs_tokenโœ“โœ“โœ“โœ—โœ—
DeepSeekdeepseek_api_keyโœ—โœ“โœ—โœ—โœ—
Defined Networkingdefined_networking_nebula_api_keyโœ“โœ“โœ“โœ“โœ—
DevCycledevcycle_client_api_keyโœ“โœ“โœ“โœ—โœ—
DevCycledevcycle_mobile_api_keyโœ“โœ“โœ“โœ—โœ—
DevCycledevcycle_server_api_keyโœ“โœ“โœ“โœ—โœ—
DigitalOceandigitalocean_oauth_tokenโœ“โœ“โœ“โœ“โœ—
DigitalOceandigitalocean_personal_access_tokenโœ“โœ“โœ“โœ“โœ—
DigitalOceandigitalocean_refresh_tokenโœ“โœ“โœ“โœ—โœ—
DigitalOceandigitalocean_system_tokenโœ“โœ“โœ“โœ—โœ—
Discorddiscord_bot_token
Token versions
โœ“โœ“โœ“โœ“โœ—
Dockerdocker_organization_access_tokenโœ“โœ“โœ“โœ—โœ—
Dockerdocker_personal_access_tokenโœ“โœ“โœ“โœ—โœ—
Dockerdocker_swarm_join_tokenโœ—โœ“โœ—โœ—โœ—
Dockerdocker_swarm_unlock_keyโœ—โœ“โœ—โœ—โœ—
Dopplerdoppler_audit_tokenโœ“โœ“โœ“โœ“โœ—
Dopplerdoppler_cli_tokenโœ“โœ“โœ“โœ“โœ—
Dopplerdoppler_personal_tokenโœ“โœ“โœ“โœ“โœ—
Dopplerdoppler_scim_tokenโœ“โœ“โœ“โœ“โœ—
Dopplerdoppler_service_account_tokenโœ“โœ“โœ“โœ“โœ—
Dopplerdoppler_service_tokenโœ“โœ“โœ“โœ“โœ—
Dropboxdropbox_access_tokenโœ“โœ“โœ“โœ“โœ—
Dropboxdropbox_short_lived_access_tokenโœ“โœ“โœ“โœ“โœ—
Duffelduffel_live_access_tokenโœ—โœ“โœ“โœ“โœ—
Duffelduffel_test_access_tokenโœ—โœ“โœ“โœ“โœ—
Dynatracedynatrace_api_tokenโœ“โœ“โœ“โœ—โœ—
Dynatracedynatrace_internal_tokenโœ“โœ“โœ“โœ—โœ—
EasyPosteasypost_production_api_keyโœ—โœ“โœ“โœ—โœ—
EasyPosteasypost_test_api_keyโœ—โœ“โœ—โœ—โœ—
eBayebay_production_client_id
ebay_production_client_secret
โœ—โœ“โœ“โœ—โœ—
eBayebay_sandbox_client_id
ebay_sandbox_client_secret
โœ—โœ“โœ“โœ—โœ—
Elasticelastic_cloud_api_keyโœ—โœ“โœ“โœ—โœ—
Facebookfacebook_access_tokenโœ“โœ“โœ“โœ“โœ—
Fastlyfastly_api_token
Token versions
โœ“โœ“โœ—โœ“โœ—
Figmafigma_patโœ“โœ“โœ“โœ“โœ—
Finicityfinicity_app_keyโœ“โœ“โœ—โœ—โœ—
Firebasefirebase_cloud_messaging_server_keyโœ—โœ“โœ—โœ—โœ—
Flutterwaveflutterwave_live_api_secret_keyโœ—โœ“โœ“โœ“โœ—
Flutterwaveflutterwave_test_api_secret_keyโœ—โœ“โœ—โœ“โœ—
Frame.ioframeio_developer_tokenโœ“โœ“โœ“โœ“โœ—
Frame.ioframeio_jwtโœ“โœ“โœ“โœ“โœ—
FullStoryfullstory_api_key
Token versions
โœ“โœ“โœ“โœ“โœ—
GitHubgithub_app_installation_access_token
Token versions
โœ“โœ“โœ“โœ“โœ“
GitHubgithub_oauth_access_token
Token versions
โœ“โœ“โœ“โœ“โœ“
GitHubgithub_personal_access_token
Token versions
โœ“โœ“โœ“โœ“โœ“
GitHubgithub_refresh_token
Token versions
โœ“โœ“โœ“โœ“โœ“
GitHubgithub_ssh_private_keyโœ“โœ“โœ“โœ“โœ—
GitHubgithub_test_tokenโœ“โœ“โœ—โœ—โœ—
GitHub Secret Scanningsecret_scanning_sample_tokenโœ“โœ“โœ“โœ—โœ—
GitHub Secret Scanningsecret_scanning_sample_token_base64โœ“โœ“โœ“โœ—โœ“
GitLabgitlab_access_tokenโœ—โœ“โœ“โœ“โœ—
GoCardlessgocardless_live_access_tokenโœ“โœ“โœ—โœ“โœ—
GoCardlessgocardless_sandbox_access_tokenโœ“โœ“โœ—โœ“โœ—
Googlegoogle_api_keyโœ“โœ“โœ—โœ“โœ—
Googlegoogle_cloud_service_account_credentialsโœ“โœ“โœ“โœ“โœ—
Googlegoogle_cloud_storage_access_key_secret
google_cloud_storage_service_account_access_key_id
โœ“โœ“โœ“โœ—โœ—
Googlegoogle_cloud_storage_access_key_secret
google_cloud_storage_user_access_key_id
โœ“โœ“โœ“โœ—โœ—
Googlegoogle_gcp_api_key_bound_service_accountโœ“โœ“โœ—โœ—โœ—
Googlegoogle_gemini_api_keyโœ—โœ“โœ—โœ—โœ—
Googlegoogle_oauth_access_tokenโœ“โœ“โœ“โœ“โœ—
Googlegoogle_oauth_client_id
google_oauth_client_secret
โœ“โœ“โœ“โœ—โœ—
Googlegoogle_oauth_refresh_tokenโœ“โœ“โœ“โœ—โœ—
Grafanagrafana_cloud_api_keyโœ“โœ“โœ“โœ—โœ—
Grafanagrafana_cloud_api_tokenโœ“โœ“โœ“โœ“โœ—
Grafanagrafana_project_api_keyโœ“โœ“โœ“โœ—โœ—
Grafanagrafana_project_service_account_tokenโœ“โœ“โœ“โœ—โœ—
Groqgroq_api_keyโœ“โœ“โœ“โœ“โœ—
GuardSquareguardsquare_appsweep_api_keyโœ“โœ“โœ“โœ—โœ—
GuardSquareguardsquare_cli_access_tokenโœ“โœ“โœ“โœ—โœ—
GuardSquareguardsquare_maven_tokenโœ“โœ“โœ“โœ—โœ—
HashiCorphashicorp_vault_batch_token
Token versions
โœ—โœ“โœ“โœ—โœ—
HashiCorphashicorp_vault_root_service_tokenโœ—โœ“โœ“โœ—โœ—
HashiCorphashicorp_vault_service_token
Token versions
โœ—โœ“โœ“โœ—โœ—
HashiCorpterraform_api_tokenโœ“โœ“โœ“โœ“โœ—
hCaptchahcaptcha_siteverify_secretโœ—โœ“โœ“โœ—โœ—
Herokuheroku_platform_api_oauth2_tokenโœ—โœ“โœ“โœ“โœ—
Herokuheroku_postgres_connection_urlโœ—โœ“โœ—โœ—โœ—
Highnotehighnote_rk_live_keyโœ“โœ“โœ“โœ—โœ—
Highnotehighnote_rk_test_keyโœ“โœ“โœ“โœ—โœ—
Highnotehighnote_sk_live_keyโœ“โœ“โœ“โœ“โœ—
Highnotehighnote_sk_test_keyโœ“โœ“โœ“โœ“โœ—
HOPhop_bearerโœ“โœ“โœ“โœ—โœ—
HOPhop_patโœ“โœ“โœ“โœ—โœ—
HOPhop_ptkโœ“โœ“โœ“โœ—โœ—
Hubspothubspot_api_key
Token versions
โœ“โœ“โœ“โœ—โœ—
Hubspothubspot_personal_access_keyโœ“โœ“โœ“โœ—โœ—
Hubspothubspot_private_apps_user_tokenโœ“โœ“โœ—โœ—โœ—
Hubspothubspot_smtp_credential
Token versions
โœ“โœ“โœ—โœ—โœ—
Hugging Facehf_org_api_keyโœ“โœ“โœ“โœ—โœ—
Hugging Facehf_user_access_tokenโœ“โœ“โœ“โœ“โœ—
Hugging Facehf_user_access_token_base64โœ“โœ“โœ“โœ—โœ“
Intercomintercom_access_tokenโœ—โœ“โœ“โœ“โœ—
Ionicionic_personal_access_token
Token versions
โœ“โœ“โœ“โœ—โœ—
Ionicionic_refresh_token
Token versions
โœ“โœ“โœ“โœ—โœ—
Iterativeiterative_dvc_studio_access_tokenโœ“โœ—โœ—โœ—โœ—
JFrogjfrog_platform_access_tokenโœ—โœ“โœ“โœ—โœ—
JFrogjfrog_platform_api_keyโœ—โœ“โœ“โœ—โœ—
JFrogjfrog_platform_reference_tokenโœ—โœ“โœ“โœ—โœ—
Langchainlangchain_api_personal_keyโœ—โœ“โœ“โœ—โœ—
Langchainlangchain_api_server_keyโœ—โœ“โœ—โœ—โœ—
LaunchDarklylaunchdarkly_access_tokenโœ“โœ“โœ—โœ—โœ—
Lichesslichess_oauth_access_tokenโœ“โœ“โœ“โœ“โœ—
Lichesslichess_personal_access_tokenโœ“โœ“โœ“โœ“โœ—
Lightspeedlightspeed_xs_patโœ—โœ“โœ“โœ—โœ—
Linearlinear_api_keyโœ“โœ“โœ“โœ—โœ—
Linearlinear_oauth_access_tokenโœ“โœ“โœ“โœ—โœ—
LinkedInlinkedin_client_secretโœ—โœ“โœ“โœ—โœ—
Loblob_live_api_keyโœ—โœ“โœ—โœ“โœ—
Loblob_test_api_keyโœ—โœ“โœ“โœ“โœ—
Localstacklocalstack_api_keyโœ“โœ“โœ“โœ—โœ—
LogicMonitorlogicmonitor_bearer_tokenโœ“โœ“โœ“โœ—โœ—
LogicMonitorlogicmonitor_lmv1_access_keyโœ“โœ“โœ“โœ—โœ—
Login with Amazonamazon_oauth_client_id
amazon_oauth_client_secret
amazon_oauth_client_secret
โœ“โœ“โœ“โœ—โœ—
Mailchimpmailchimp_api_keyโœ“โœ“โœ“โœ“โœ—
Mailchimpmandrill_api_keyโœ“โœ—โœ—โœ—โœ—
Mailersendmailersend_api_tokenโœ“โœ—โœ—โœ—โœ—
Mailersendmailersend_smtp_passwordโœ“โœ—โœ—โœ—โœ—
Mailersendmailersend_smtp_usernameโœ“โœ—โœ—โœ—โœ—
Mailgunmailgun_api_key
Token versions
โœ“โœ“โœ“โœ“โœ—
Mailgunmailgun_smtp_credentialโœ“โœ—โœ—โœ—โœ—
Mapboxmapbox_secret_access_tokenโœ—โœ“โœ—โœ“โœ—
MaxMindmaxmind_license_keyโœ“โœ“โœ“โœ“โœ—
Mercurymercury_non_production_api_tokenโœ“โœ“โœ“โœ“โœ—
Mercurymercury_production_api_tokenโœ“โœ“โœ“โœ“โœ—
Mergifymergify_application_keyโœ“โœ“โœ“โœ—โœ—
MessageBirdmessagebird_api_keyโœ“โœ“โœ“โœ—โœ—
Midtransmidtrans_production_server_keyโœ—โœ“โœ“โœ“โœ—
Midtransmidtrans_sandbox_server_keyโœ—โœ“โœ—โœ“โœ—
Mistral AImistral_ai_api_keyโœ—โœ“โœ—โœ—โœ—
MongoDBmongodb_atlas_db_uri_with_credentialsโœ“โœ“โœ—โœ“โœ—
MongoDBmongodb_atlas_service_account_secretโœ“โœ“โœ“โœ—โœ—
Naver Cloudnavercloud_gov_access_keyโœ“โœ“โœ“โœ—โœ—
Naver Cloudnavercloud_gov_access_key_secretโœ“โœ“โœ“โœ—โœ—
Naver Cloudnavercloud_gov_stsโœ“โœ“โœ“โœ—โœ—
Naver Cloudnavercloud_gov_sts_secretโœ“โœ“โœ“โœ—โœ—
Naver Cloudnavercloud_pub_access_keyโœ“โœ“โœ“โœ—โœ—
Naver Cloudnavercloud_pub_access_key_secretโœ“โœ“โœ“โœ—โœ—
Naver Cloudnavercloud_pub_stsโœ“โœ“โœ“โœ—โœ—
Naver Cloudnavercloud_pub_sts_secretโœ“โœ“โœ“โœ—โœ—
Neonneon_api_keyโœ“โœ—โœ—โœ—โœ—
Neonneon_connection_uriโœ“โœ—โœ—โœ—โœ—
Netflixnetflix_netkeyโœ“โœ“โœ—โœ—โœ—
New Relicnew_relic_insights_query_keyโœ—โœ“โœ“โœ—โœ—
New Relicnew_relic_license_keyโœ—โœ“โœ—โœ—โœ—
New Relicnew_relic_personal_api_keyโœ—โœ“โœ“โœ—โœ—
New Relicnew_relic_rest_api_keyโœ—โœ“โœ“โœ—โœ—
Notionnotion_api_tokenโœ“โœ“โœ“โœ—โœ—
Notionnotion_integration_tokenโœ—โœ“โœ“โœ“โœ—
Notionnotion_oauth_client_secretโœ—โœ“โœ“โœ—โœ—
npmnpm_access_token
Token versions
โœ“โœ“โœ“โœ—โœ—
NuGetnuget_api_key
Token versions
โœ“โœ“โœ“โœ“โœ—
Octopus Deployoctopus_deploy_api_keyโœ“โœ“โœ—โœ—โœ—
Oculusoculus_access_tokenโœ—โœ“โœ“โœ—โœ—
OneChronosonechronos_api_keyโœ—โœ“โœ“โœ—โœ—
OneChronosonechronos_eb_api_keyโœ—โœ“โœ“โœ—โœ—
OneChronosonechronos_eb_encryption_keyโœ—โœ“โœ“โœ—โœ—
OneChronosonechronos_oauth_tokenโœ—โœ“โœ“โœ—โœ—
OneChronosonechronos_refresh_tokenโœ—โœ“โœ“โœ—โœ—
Onfidoonfido_live_api_tokenโœ“โœ“โœ“โœ“โœ—
Onfidoonfido_sandbox_api_tokenโœ“โœ“โœ—โœ“โœ—
OpenAIopenai_api_key
Token versions
โœ“โœ“โœ“โœ“โœ—
OpenRouteropenrouter_api_keyโœ“โœ“โœ—โœ“โœ—
OpenVSXopenvsx_access_token
Token versions
โœ—โœ“โœ—โœ—โœ—
Openweatheropenweather_api_keyโœ—โœ“โœ—โœ—โœ—
Oracleoracle_api_keyโœ“โœ—โœ—โœ—โœ—
Orbitorbit_api_tokenโœ—โœ“โœ“โœ—โœ—
PagerDutypagerduty_oauth_secretโœ—โœ“โœ“โœ—โœ—
PagerDutypagerduty_oauth_tokenโœ—โœ“โœ“โœ—โœ—
Palantirpalantir_jwtโœ“โœ“โœ“โœ—โœ—
Pangeapangea_tokenโœ—โœ“โœ“โœ—โœ—
Perplexityperplexity_api_keyโœ—โœ“โœ“โœ—โœ—
Persona Identitiespersona_production_api_keyโœ“โœ“โœ“โœ“โœ—
Persona Identitiespersona_sandbox_api_keyโœ“โœ“โœ“โœ“โœ—
Pineconepinecone_api_key
pinecone_environment
โœ—โœ“โœ—โœ—โœ—
Pinterestpinterest_access_tokenโœ“โœ“โœ“โœ—โœ—
Pinterestpinterest_refresh_tokenโœ“โœ“โœ“โœ—โœ—
PlanetScaleplanetscale_database_passwordโœ“โœ“โœ“โœ—โœ—
PlanetScaleplanetscale_oauth_tokenโœ“โœ“โœ“โœ—โœ—
PlanetScaleplanetscale_service_tokenโœ“โœ“โœ“โœ—โœ—
Planning Centerplanning_center_oauth_access_tokenโœ“โœ“โœ“โœ“โœ—
Planning Centerplanning_center_oauth_app_secretโœ“โœ“โœ“โœ—โœ—
Planning Centerplanning_center_personal_access_tokenโœ“โœ“โœ“โœ—โœ—
Plivoplivo_auth_id
plivo_auth_token
โœ“โœ“โœ“โœ—โœ—
Polarpolar_access_token
Token versions
โœ“โœ“โœ“โœ“โœ—
Polarpolar_authorization_code
Token versions
โœ“โœ“โœ“โœ—โœ—
Polarpolar_client_registration_token
Token versions
โœ“โœ“โœ“โœ—โœ—
Polarpolar_client_secret
Token versions
โœ“โœ“โœ“โœ—โœ—
Polarpolar_customer_session_tokenโœ“โœ“โœ“โœ—โœ—
Polarpolar_personal_access_token
Token versions
โœ“โœ“โœ“โœ—โœ—
Polarpolar_refresh_token
Token versions
โœ“โœ“โœ“โœ—โœ—
Polarpolar_user_session_tokenโœ“โœ“โœ“โœ—โœ—
Postmanpostman_api_keyโœ“โœ“โœ“โœ“โœ—
Postmanpostman_collection_keyโœ“โœ“โœ“โœ“โœ—
Prefectprefect_server_api_keyโœ“โœ“โœ“โœ—โœ—
Prefectprefect_user_api_keyโœ“โœ“โœ“โœ—โœ—
Proctorioproctorio_consumer_keyโœ“โœ“โœ—โœ—โœ—
Proctorioproctorio_linkage_keyโœ“โœ“โœ—โœ—โœ—
Proctorioproctorio_registration_keyโœ“โœ“โœ—โœ—โœ—
Proctorioproctorio_secret_key
Token versions
โœ“โœ“โœ“โœ—โœ—
Pulumipulumi_access_tokenโœ“โœ“โœ“โœ“โœ—
PyPIpypi_api_tokenโœ“โœ“โœ“โœ—โœ—
Rampramp_client_idโœ“โœ“โœ“โœ—โœ—
Rampramp_client_secretโœ“โœ“โœ“โœ—โœ—
Rampramp_oauth_tokenโœ“โœ“โœ—โœ—โœ—
ReadMereadmeio_api_access_tokenโœ“โœ“โœ“โœ“โœ—
redirect.pizzaredirect_pizza_api_tokenโœ“โœ“โœ“โœ“โœ—
Replicatereplicate_api_tokenโœ“โœ“โœ“โœ“โœ—
Rootlyrootly_api_keyโœ—โœ“โœ“โœ“โœ—
RubyGemsrubygems_api_keyโœ“โœ“โœ“โœ“โœ—
RunPodrunpod_api_keyโœ“โœ“โœ“โœ“โœ—
Salesforcesalesforce_access_tokenโœ—โœ“โœ“โœ—โœ—
Salesforcesalesforce_oauth2_consumer_key
salesforce_oauth2_consumer_secret
โœ—โœ“โœ“โœ—โœ—
Salesforcesalesforce_refresh_tokenโœ—โœ“โœ“โœ—โœ—
Samsarasamsara_api_tokenโœ“โœ“โœ“โœ—โœ—
Samsarasamsara_oauth_access_tokenโœ“โœ“โœ“โœ—โœ—
Scalrscalr_api_tokenโœ“โœ“โœ“โœ“โœ—
Segmentsegment_public_api_tokenโœ“โœ“โœ“โœ“โœ—
SendGridsendgrid_api_keyโœ“โœ“โœ“โœ“โœ—
Sentrysentry_integration_tokenโœ—โœ“โœ“โœ—โœ—
Sentrysentry_org_auth_tokenโœ—โœ“โœ“โœ—โœ—
Sentrysentry_user_app_auth_tokenโœ—โœ“โœ“โœ—โœ—
Sentrysentry_user_auth_tokenโœ—โœ“โœ“โœ—โœ—
Shipposhippo_live_api_tokenโœ—โœ“โœ“โœ—โœ—
Shipposhippo_test_api_tokenโœ—โœ“โœ“โœ—โœ—
Shopeeshopee_open_platform_partner_keyโœ“โœ“โœ“โœ—โœ—
Shopifyshopify_access_tokenโœ“โœ“โœ“โœ—โœ—
Shopifyshopify_app_client_credentialsโœ“โœ“โœ“โœ—โœ—
Shopifyshopify_app_client_secretโœ“โœ“โœ—โœ—โœ—
Shopifyshopify_app_shared_secretโœ“โœ“โœ“โœ—โœ—
Shopifyshopify_custom_app_access_tokenโœ“โœ“โœ“โœ—โœ—
Shopifyshopify_marketplace_tokenโœ“โœ“โœ—โœ—โœ—
Shopifyshopify_merchant_tokenโœ“โœ“โœ“โœ—โœ—
Shopifyshopify_partner_api_tokenโœ“โœ“โœ“โœ—โœ—
Shopifyshopify_private_app_passwordโœ“โœ“โœ“โœ—โœ—
Siemenssiemens_api_tokenโœ“โœ“โœ“โœ“โœ—
Siemenssiemens_code_tokenโœ“โœ—โœ—โœ—โœ—
Sindrisindri_api_key
Token versions
โœ“โœ“โœ—โœ“โœ—
Slackslack_api_token
Token versions
โœ“โœ“โœ“โœ“โœ—
Slackslack_incoming_webhook_urlโœ“โœ“โœ“โœ“โœ—
Slackslack_workflow_webhook_urlโœ“โœ“โœ“โœ—โœ—
Snowflakesnowflake_programmatic_access_tokenโœ“โœ“โœ“โœ—โœ—
Sourcegraphsourcegraph_access_tokenโœ“โœ“โœ—โœ“โœ—
Sourcegraphsourcegraph_dotcom_user_gatewayโœ“โœ“โœ“โœ—โœ—
Sourcegraphsourcegraph_instance_identifier_access_tokenโœ“โœ“โœ—โœ“โœ—
Sourcegraphsourcegraph_license_key_tokenโœ“โœ“โœ“โœ—โœ—
Sourcegraphsourcegraph_product_subscription_tokenโœ“โœ“โœ—โœ—โœ—
Squaresquare_access_token
Token versions
โœ—โœ“โœ“โœ“โœ—
Squaresquare_production_application_secretโœ—โœ“โœ“โœ—โœ—
Squaresquare_sandbox_application_secretโœ—โœ“โœ“โœ—โœ—
SSLMatesslmate_api_key
Token versions
โœ“โœ“โœ“โœ“โœ—
SSLMatesslmate_cluster_secretโœ“โœ“โœ“โœ—โœ—
Stripestripe_api_keyโœ“โœ“โœ“โœ“โœ—
Stripestripe_legacy_api_keyโœ“โœ“โœ—โœ—โœ—
Stripestripe_live_restricted_keyโœ“โœ“โœ“โœ—โœ—
Stripestripe_test_restricted_keyโœ“โœ“โœ“โœ—โœ—
Stripestripe_test_secret_keyโœ“โœ“โœ“โœ“โœ—
Stripestripe_webhook_signing_secretโœ“โœ“โœ—โœ—โœ—
Supabasesupabase_service_key
Token versions
โœ“โœ“โœ—โœ—โœ—
Tableautableau_personal_access_tokenโœ—โœ“โœ“โœ—โœ—
Tailscaletailscale_api_keyโœ“โœ“โœ—โœ“โœ—
Telegramtelegram_bot_tokenโœ—โœ“โœ—โœ“โœ—
Telnyxtelnyx_api_v2_keyโœ“โœ“โœ“โœ“โœ—
Temporaltemporal_cloud_api_keyโœ“โœ“โœ“โœ—โœ—
Tencenttencent_cloud_intl_access_tokenโœ“โœ“โœ—โœ—โœ—
Tencenttencent_cloud_secret_idโœ“โœ“โœ“โœ—โœ—
Tencenttencent_wechat_api_app_idโœ“โœ“โœ—โœ—โœ—
Tencenttencent_wechat_pay_tokenโœ—โœ“โœ—โœ—โœ—
Thunderstorethunderstore_io_api_tokenโœ—โœ“โœ“โœ—โœ—
Twiliotwilio_access_tokenโœ—โœ“โœ“โœ—โœ—
Twiliotwilio_account_sidโœ“โœ“โœ“โœ—โœ—
Twiliotwilio_account_sid_base64โœ“โœ“โœ“โœ—โœ“
Twiliotwilio_api_keyโœ“โœ“โœ“โœ—โœ—
Typeformtypeform_personal_access_tokenโœ“โœ“โœ“โœ“โœ—
Uniwisewiseflow_api_keyโœ“โœ“โœ“โœ“โœ—
Unkeyunkey_root_keyโœ“โœ“โœ—โœ“โœ—
Val Townval_town_api_tokenโœ“โœ“โœ“โœ“โœ—
VolcEnginevolcengine_access_key_idโœ“โœ“โœ“โœ—โœ—
Wakatimewakatime_api_keyโœ“โœ“โœ“โœ“โœ—
Wakatimewakatime_app_secretโœ“โœ“โœ“โœ—โœ—
Wakatimewakatime_oauth_access_tokenโœ“โœ“โœ“โœ“โœ—
Wakatimewakatime_oauth_refresh_tokenโœ“โœ“โœ“โœ—โœ—
Weights & Biaseswandb_api_keyโœ—โœ“โœ—โœ—โœ—
Workatoworkato_developer_api_token
Token versions
โœ“โœ“โœ“โœ“โœ—
WorkOSworkos_production_api_key
Token versions
โœ“โœ“โœ“โœ—โœ—
WorkOSworkos_staging_api_key
Token versions
โœ“โœ“โœ“โœ—โœ—
xAIxai_api_keyโœ“โœ“โœ“โœ“โœ—
Yandexyandex_cloud_api_keyโœ“โœ“โœ“โœ“โœ—
Yandexyandex_cloud_iam_access_secretโœ“โœ“โœ“โœ—โœ—
Yandexyandex_cloud_iam_cookieโœ“โœ“โœ“โœ—โœ—
Yandexyandex_cloud_iam_tokenโœ“โœ“โœ“โœ“โœ—
Yandexyandex_cloud_smartcaptcha_server_keyโœ“โœ“โœ“โœ—โœ—
Yandexyandex_dictionary_api_keyโœ—โœ“โœ“โœ—โœ—
Yandexyandex_passport_oauth_tokenโœ“โœ“โœ“โœ“โœ—
Yandexyandex_predictor_api_keyโœ—โœ“โœ“โœ—โœ—
Yandexyandex_translate_api_keyโœ—โœ“โœ“โœ“โœ—
ZenHubzenhub_personal_api_keyโœ—โœ“โœ“โœ—โœ—
Zuplozuplo_consumer_api_keyโœ“โœ“โœ“โœ“โœ—

Token versions

Service providers update the patterns used to generate tokens periodically and may support more than one version of a token. Push protection only supports the most recent token versions that secret scanning can identify with confidence. This avoids push protection blocking commits unnecessarily when a result may be a false positive, which is more likely to happen with legacy tokens.

Multi-part secrets

By default, secret scanning supports validation for pair-matched access keys and key IDs.

Secret scanning also supports validation for individual key IDs for Amazon AWS Access Key IDs, in addition to existing pair matching.

A key ID will show as active if secret scanning confirms the key ID exists, regardless of whether or not a corresponding access key is found. The key ID will show as inactive if it's invalid (for example, if it is not a real key ID).

Where a valid pair is found, the secret scanning alerts will be linked.

Further reading