Skip to content

Stored Secrets

Hardcoded secrets in your code are very common sources of code weakness. If your code is publicly hosted, attackers will find these credentials and use them to try to compromise your systems.

Even if your code is not hosted publicly, attackers that compromise your developers' machines will have access to these credentials, as will malicious developers.

When viewing findings results in the dashboard, the detected secrets will appear as Secret found in repository (secret-found-in-repository) with a description specifying one of the following supported secret types.

Supported secret types

  • Generic types:

    • JSON Web Token
    • Private Key
  • Various SAAS API keys, secrets and tokens:

    • Adafruit API Key
    • Adobe Client Secret
    • Age secret key
    • Airtable API Key
    • Algolia API Key
    • Alibaba Secret Key
    • Asana Client Secret
    • Atlassian API token
    • BitBucket Client Secret
    • Bittrex Access Key and Secret Key
    • Beamer API token
    • Codecov Access Token
    • Coinbase Access Token
    • Clojars API token
    • Confluent Access Token, Secret Key and delivery API token
    • Databricks API token
    • Datadog Access Token
    • Discord API key, client secret
    • Doppler API token
    • Dropbox API secret, long lived API token
    • Droneci Access Token
    • Duffel API token
    • Dynatrace API token
    • EasyPost API token
    • Etsy Access Token
    • Facebook API key
    • Fastly API key
    • Finicity Client Secret, API token
    • Flickr Access Token
    • Finnhub Access Token
    • Flutterwave Secret Key, Encryption Key
    • Frame.io API token
    • Freshbooks Access Token
    • GoCardless API token
    • GCP API key
    • GitHub various token types
    • Gitlab Personal Access Token
    • Gitter Access Token
    • HashiCorp Terraform user/org API token
    • Heroku API Key
    • HubSpot API Token
    • Intercom API Token
    • Kraken Access Token
    • Kucoin Access Token and Secret Key
    • Launchdarkly Access Token
    • Linear API Token and Client Secret
    • LinkedIn Client secret
    • Lob API Key
    • Mailchimp API key
    • Mailgun private API token and webhook signing key
    • MapBox API token
    • Mattermost Access Token
    • MessageBird API token
    • Netlify Access Token
    • New Relic API Key
    • NPM access token
    • Nytimes Access Token
    • Okta Access Token and Secret Key
    • Plaid API Token
    • PlanetScale password, API and OAuth token
    • Postman API token
    • Pulumi API token
    • PyPI upload token
    • Rubygem API token
    • RapidAPI Access Token
    • Sendbird Access Token
    • SendGrid API token
    • Sendinblue API token
    • Sentry Access Token
    • Shippo API token
    • Shopify access tokens and shared secret
    • Slack token and webhook secret
    • Stripe (Production keys only)
    • Square Access Token
    • Squarespace Access Token
    • SumoLogic Access Token
    • Travis CI Access Token
    • Twilio API Key
    • Twitch API token
    • Twitter API Key, secrets and tokens
    • Typeform API token
    • Yandex API Key and Access Tokens
    • Zendesk Secret Key