Secret scanning patterns

Advanced Security maintains multiple sets of default secret scanning patterns:

  • *Push protection patterns - used to detect potential secrets at push time in repositories with secret scanning push protection enabled.
  • User alert patterns - used to detect potential secrets in repositories with secret scanning alerts enabled.
  • Non-provider patterns - used to detect common occurrences of structured secrets in repositories with secret scanning alerts enabled.

Supported secrets

Section Explanation
Provider The name of the token provider.
Token name The type of token discovered by Advanced Security secret scanning.
User A token for which leaks are reported to users post-push. Applies to all repositories where Advanced Security is enabled
Push protection A token for which leaks are reported to users on push. Applies to all repositories where secret push protection enabled.
Validity Tokens for which Advanced Security attempts to perform a validity check.

Partner provider patterns

The following table lists the partner provider patterns supported by secret scanning.

Provider Token Name Push Protection User Alerts Validity Checking
Adafruit IO AdafruitIOKey Green Checkmark Green Checkmark
Adobe AdobeDeviceToken Green Checkmark
Adobe AdobeServiceToken Green Checkmark
Adobe AdobeShortLivedAccessToken Green Checkmark
Akamai AkamaiCredentials Green Checkmark
Alibaba Cloud AlibabaCloudCredentials Green Checkmark Green Checkmark
Amazon AmazonMwsAuthToken Green Checkmark
Amazon AmazonOAuthCredentials Green Checkmark Green Checkmark
Amazon AwsCredentials Green Checkmark Green Checkmark
Amazon AwsTemporaryCredentials Green Checkmark Green Checkmark
Asana AsanaPat Green Checkmark Green Checkmark
Atlassian AtlassianApiToken Green Checkmark
Atlassian AtlassianJwt Green Checkmark
Atlassian BitbucketCloudOAuthCredentials Green Checkmark
Atlassian BitbucketServerPat Green Checkmark Green Checkmark
Beamer BeamerApiKey Green Checkmark
Brevo BrevoApiKey Green Checkmark Green Checkmark
Brevo BrevoSmtpKey Green Checkmark Green Checkmark
Canadian Digital Service CdsCanadaNotifyApiKey Green Checkmark Green Checkmark
Checkout.com CheckoutIdentifiableSecretKey Green Checkmark
Chief Tools ChiefToolsToken Green Checkmark Green Checkmark
Cisco CiscoLocalAccountCredentials Green Checkmark
Clojars ClojarsDeployToken Green Checkmark
Cloudant CloudantCredentials Green Checkmark
Cloudflare CloudflareApiToken Green Checkmark
Contentful ContentfulPersonalAccessToken Green Checkmark
Crates.io CratesApiKey Green Checkmark
DevCycle DevCycleClientApiKey Green Checkmark Green Checkmark
DevCycle DevCycleManagementApiToken Green Checkmark
DevCycle DevCycleMobileApiKey Green Checkmark Green Checkmark
DevCycle DevCycleServerApiKey Green Checkmark Green Checkmark
DigitalOcean DigitalOceanOAuthToken Green Checkmark Green Checkmark
DigitalOcean DigitalOceanPat Green Checkmark Green Checkmark
DigitalOcean DigitalOceanRefreshToken Green Checkmark Green Checkmark
DigitalOcean DigitalOceanSystemToken Green Checkmark Green Checkmark
Discord DiscordApiCredentials Green Checkmark
Discord DiscordApiToken Green Checkmark Green Checkmark
Doppler DopplerAuditToken Green Checkmark Green Checkmark
Doppler DopplerCliToken Green Checkmark Green Checkmark
Doppler DopplerPersonalToken Green Checkmark Green Checkmark
Doppler DopplerScimToken Green Checkmark Green Checkmark
Doppler DopplerServiceToken Green Checkmark Green Checkmark
Dropbox DropboxAccessToken Green Checkmark
Dropbox DropboxAppCredentials Green Checkmark
Dropbox DropboxOAuth2ShortLivedAccessToken Green Checkmark Green Checkmark
Duffel DuffelAccessToken Green Checkmark Green Checkmark
Dynatrace DynatraceInternalToken Green Checkmark
EasyPost EasyPostApiKey Green Checkmark Green Checkmark
Ebay EBayProductionClientCredentials Green Checkmark
Ebay EBaySandboxClientCredentials Green Checkmark
Elastic ElasticCloudApiKey Green Checkmark
Elastic ElasticStackApiKey Green Checkmark
EventBrite PicaticApiKey Green Checkmark
Facebook FacebookAccessToken Green Checkmark
Facebook FacebookAppCredentials Green Checkmark
Facebook OculusAccessToken Green Checkmark
Fastly FastlyApiToken Green Checkmark
Figma FigmaPat Green Checkmark Green Checkmark
Finicity FinicityAppKey Green Checkmark
Flutterwave FlutterwaveLiveApiSecretKey Green Checkmark Green Checkmark
Flutterwave FlutterwaveTestApiSecretKey Green Checkmark
Frame.io FrameIODeveloperToken Green Checkmark
Frame.io FrameIOJwt Green Checkmark
FullStory FullStoryApiKey Green Checkmark Green Checkmark
GitHub GitHubAppCredentials Green Checkmark
GitHub GitHubAppToken Green Checkmark Green Checkmark
GitHub GitHubClassicPat Green Checkmark Green Checkmark
GitHub GitHubOAuthAccessToken Green Checkmark Green Checkmark
GitHub GitHubPat Green Checkmark Green Checkmark
GitHub GitHubRefreshToken Green Checkmark Green Checkmark
GitHub GitHubServerToServerToken Green Checkmark Green Checkmark
GitHub GitHubUserToServerToken Green Checkmark Green Checkmark
GitLab GitLabAccessToken Green Checkmark
GoCardless GoCardlessLiveAccessToken Green Checkmark
GoCardless GoCardlessSandboxAccessToken Green Checkmark
Google FirebaseCloudMessagingServerKey Green Checkmark
Google GoogleApiKey Green Checkmark
Google GoogleCloudPrivateKeyId Green Checkmark Green Checkmark
Google GoogleCloudStorageServiceAccountAccessKey Green Checkmark Green Checkmark
Google GoogleCloudStorageUserAccessKey Green Checkmark Green Checkmark
Google GoogleOAuthAccessToken Green Checkmark
Google GoogleOAuthCredentials Green Checkmark
Google GoogleOAuthRefreshToken Green Checkmark
Google GoogleServiceAccountKey Green Checkmark
Grafana GrafanaApiKey Green Checkmark Green Checkmark
Grafana GrafanaCloudApiToken Green Checkmark
Grafana GrafanaProjectApiKey Green Checkmark
Grafana GrafanaProjectServiceAccountToken Green Checkmark
Hashicorp HashiCorpVaultBatchLegacyToken Green Checkmark Green Checkmark
Hashicorp HashiCorpVaultBatchToken Green Checkmark Green Checkmark
Hashicorp HashiCorpVaultRootServiceToken Green Checkmark Green Checkmark
Hashicorp HashiCorpVaultServiceLegacyToken Green Checkmark Green Checkmark
Hashicorp HashiCorpVaultServiceToken Green Checkmark Green Checkmark
Hashicorp TerraformCloudEnterpriseToken Green Checkmark Green Checkmark
HighNote HighnoteRkKey Green Checkmark Green Checkmark
HighNote HighnoteSkKey Green Checkmark Green Checkmark
HubSpot HubspotApiKey Green Checkmark Green Checkmark
HubSpot HubSpotApiPersonalAccessKey Green Checkmark Green Checkmark
HuggingFace HuggingFaceAccessToken Green Checkmark
Intercom IntercomAccessToken Green Checkmark Green Checkmark
Ionic IonicPat Green Checkmark Green Checkmark
Ionic IonicRefreshToken Green Checkmark Green Checkmark
JD Cloud JdCloudAccessKey Green Checkmark
JFrog JFrogPlatformAccessToken Green Checkmark Green Checkmark
JFrog JFrogPlatformApiKey Green Checkmark Green Checkmark
Linear LinearApiKey Green Checkmark Green Checkmark
Linear LinearOAuthAccessToken Green Checkmark Green Checkmark
Lob LobLiveApiKey Green Checkmark
Lob LobTestApiKey Green Checkmark
LocalStack LocalStackApiKey Green Checkmark
LogicMonitor LogicMonitorBearerToken Green Checkmark Green Checkmark
LogicMonitor LogicMonitorLmv1AccessKey Green Checkmark Green Checkmark
MailChimp MailChimpApiKey Green Checkmark
Mailgun MailgunApiCredentials Green Checkmark
Mapbox MapboxSecretAccessToken Green Checkmark
MessageBird MessageBirdApiKey Green Checkmark
Microsoft AadClientAppIdentifiableCredentials Green Checkmark Green Checkmark
Microsoft AdoPat Green Checkmark Green Checkmark
Microsoft AzureApimDirectManagementSas Green Checkmark
Microsoft AzureApimGatewaySas Green Checkmark
Microsoft AzureApimIdentifiableDirectManagementKey Green Checkmark Green Checkmark
Microsoft AzureApimIdentifiableGatewayKey Green Checkmark Green Checkmark
Microsoft AzureApimIdentifiableRepositoryKey Green Checkmark Green Checkmark
Microsoft AzureApimIdentifiableSubscriptionKey Green Checkmark Green Checkmark
Microsoft AzureApimLegacyDirectManagementKey Green Checkmark
Microsoft AzureApimLegacyGatewayKey Green Checkmark Green Checkmark
Microsoft AzureApimLegacyRepositoryKey Green Checkmark Green Checkmark
Microsoft AzureApimLegacySubscriptionKey Green Checkmark
Microsoft AzureApimRepositorySas Green Checkmark
Microsoft AzureAppConfigurationCredentials Green Checkmark Green Checkmark
Microsoft AzureApplicationInsightsCredentials Green Checkmark
Microsoft AzureBatchIdentifiableKey Green Checkmark Green Checkmark
Microsoft AzureBatchLegacyKey Green Checkmark
Microsoft AzureBlockchainCredentials Green Checkmark
Microsoft AzureCacheForRedisIdentifiableKey Green Checkmark Green Checkmark
Microsoft AzureCacheForRedisIdentifiablePrivateServiceKey Green Checkmark Green Checkmark
Microsoft AzureCacheForRedisLegacyKey Green Checkmark Green Checkmark
Microsoft AzureCdnSas Green Checkmark
Microsoft AzureCognitiveServicesKey Green Checkmark
Microsoft AzureCognitiveServicesTranslatorKey Green Checkmark
Microsoft AzureCommunicationServicesKey Green Checkmark Green Checkmark
Microsoft AzureContainerRegistryIdentifiableKey Green Checkmark Green Checkmark
Microsoft AzureContainerRegistryLegacyKey Green Checkmark Green Checkmark
Microsoft AzureCosmosDBIdentifiableKey Green Checkmark Green Checkmark
Microsoft AzureCosmosDBIdentifiablePrivateServiceKey Green Checkmark Green Checkmark
Microsoft AzureCosmosDBLegacyKey Green Checkmark Green Checkmark
Microsoft AzureDatabricksPat Green Checkmark Green Checkmark
Microsoft AzureDevOpsOAuthToken Green Checkmark
Microsoft AzureEventGridKey Green Checkmark Green Checkmark
Microsoft AzureEventHubIdentifiableKey Green Checkmark Green Checkmark
Microsoft AzureEventHubIdentifiablePrivateServiceSystemKey Green Checkmark Green Checkmark
Microsoft AzureFluidRelayKey Green Checkmark
Microsoft AzureFunctionIdentifiableKey Green Checkmark Green Checkmark
Microsoft AzureFunctionLegacyKey Green Checkmark Green Checkmark
Microsoft AzureGenomicsKey Green Checkmark
Microsoft AzureHDInsightCredentials Green Checkmark
Microsoft AzureIotDeviceIdentifiableKey Green Checkmark Green Checkmark
Microsoft AzureIotDeviceLegacyCredentials Green Checkmark Green Checkmark
Microsoft AzureIotDeviceProvisioningIdentifiableKey Green Checkmark Green Checkmark
Microsoft AzureIotDeviceProvisioningLegacyCredentials Green Checkmark Green Checkmark
Microsoft AzureIotHubIdentifiableKey Green Checkmark Green Checkmark
Microsoft AzureIotHubLegacyCredentials Green Checkmark Green Checkmark
Microsoft AzureLogicAppSas Green Checkmark
Microsoft AzureManagementCertificate Green Checkmark
Microsoft AzureMapsKey Green Checkmark
Microsoft AzureMixedRealityCredentials Green Checkmark
Microsoft AzureMLIdentifiablePrivateServicePrincipalCredentials Green Checkmark Green Checkmark
Microsoft AzureMLWebServiceClassicIdentifiableKey Green Checkmark Green Checkmark
Microsoft AzureMLWebServiceKey Green Checkmark
Microsoft AzureOpenAIKey Green Checkmark
Microsoft AzureRelayIdentifiableKey Green Checkmark Green Checkmark
Microsoft AzureSearchIdentifiableAdminKey Green Checkmark Green Checkmark
Microsoft AzureSearchIdentifiablePrivateServiceAdminKey Green Checkmark Green Checkmark
Microsoft AzureSearchIdentifiableQueryKey Green Checkmark Green Checkmark
Microsoft AzureSearchLegacyKey Green Checkmark
Microsoft AzureServiceBusIdentifiableKey Green Checkmark Green Checkmark
Microsoft AzureServiceBusIdentifiablePrivateServiceSystemKey Green Checkmark Green Checkmark
Microsoft AzureServiceBusLegacyCredentials Green Checkmark Green Checkmark
Microsoft AzureServiceDeploymentCredentials Green Checkmark
Microsoft AzureSignalRKey Green Checkmark Green Checkmark
Microsoft AzureStorageAccountIdentifiableKey Green Checkmark Green Checkmark
Microsoft AzureStorageAccountLegacyCredentials Green Checkmark Green Checkmark
Microsoft AzureStorageIdentifiablePrivateServiceKey Green Checkmark Green Checkmark
Microsoft AzureStorageLooseSas Green Checkmark
Microsoft AzureStorageSas Green Checkmark
Microsoft AzureWebAppBotCredentials Green Checkmark
Microsoft AzureWebAppBotKey Green Checkmark
Microsoft AzureWebPubSubCredentials Green Checkmark Green Checkmark
Microsoft BingApiKey Green Checkmark
Microsoft BingMapsKey Green Checkmark
Microsoft BingSearchKey Green Checkmark
Microsoft OfficeIncomingWebhook Green Checkmark Green Checkmark
Microsoft Sas Green Checkmark
Microsoft SqlIdentifiableCredentials Green Checkmark Green Checkmark
Microsoft VisualStudioAppCenterKey Green Checkmark
Midtrans MidtransServerKey Green Checkmark Green Checkmark
New Relic NewRelicInsightsQueryKey Green Checkmark Green Checkmark
New Relic NewRelicLicenseKey Green Checkmark
New Relic NewRelicPersonalApiKey Green Checkmark Green Checkmark
New Relic NewRelicRestApiKey Green Checkmark Green Checkmark
Notion NotionIntegrationToken Green Checkmark
Notion NotionOAuthClientCredentials Green Checkmark
npm NpmAuthorIdentifiableToken Green Checkmark Green Checkmark
npm NpmCredentials Green Checkmark Green Checkmark
npm NpmLegacyAuthorToken Green Checkmark
NuGet NuGetApiKey Green Checkmark Green Checkmark
NuGet NuGetCredentials Green Checkmark
Octopus Deploy OctopusDeployApiKey Green Checkmark
Onfido OnfidoApiToken Green Checkmark Green Checkmark
OpenAI OpenAIApiKeyV2 Green Checkmark Green Checkmark
Palantir PalantirJwt Green Checkmark
PayPal PayPalBraintreeAccessToken Green Checkmark
Persona PersonaProductionApiKey Green Checkmark Green Checkmark
Persona PersonaSandboxApiKey Green Checkmark
PineCone PineconeApiKey Green Checkmark
PlanetScale PlanetScaleDatabasePassword Green Checkmark Green Checkmark
PlanetScale PlanetScaleOAuthToken Green Checkmark Green Checkmark
PlanetScale PlanetScaleServiceToken Green Checkmark Green Checkmark
Plivo PlivoCredentials Green Checkmark
Prefect PrefectServerApiToken Green Checkmark Green Checkmark
Prefect PrefectUserApiToken Green Checkmark Green Checkmark
Proctorio ProctorioConsumerKey Green Checkmark
Proctorio ProctorioLinkageKey Green Checkmark
Proctorio ProctorioRegistrationKey Green Checkmark
Proctorio ProctorioSecretKeyV2 Green Checkmark Green Checkmark
Pulumi PulumiAccessToken Green Checkmark
PyPi PyPiApiToken Green Checkmark
ReadMe ReadMeApiKey Green Checkmark Green Checkmark
redirect.pizza RedirectPizzaApiToken Green Checkmark Green Checkmark
Rubygems RubyGemsApiKey Green Checkmark
SAMPLE SecretScanningSampleToken
Samsara SamsaraApiAccessToken Green Checkmark Green Checkmark
Samsara SamsaraOAuth2AccessToken Green Checkmark Green Checkmark
Segment.io SegmentPublicApiToken Green Checkmark
SendGrid SendGridApiKey Green Checkmark Green Checkmark
Shippo ShippoLiveApiToken Green Checkmark Green Checkmark
Shippo ShippoTestApiToken Green Checkmark
Shopify ShopifyAccessToken Green Checkmark Green Checkmark
Shopify ShopifyAppClientCredentials Green Checkmark
Shopify ShopifyAppClientSecret Green Checkmark
Shopify ShopifyAppOAuthAccessToken Green Checkmark
Shopify ShopifyCustomAppAccessToken Green Checkmark
Shopify ShopifyMarketplaceToken Green Checkmark
Shopify ShopifyMerchantToken Green Checkmark
Shopify ShopifyPartnerApiToken Green Checkmark
Shopify ShopifyPrivateAppPassword Green Checkmark
Shopify ShopifySharedSecret Green Checkmark Green Checkmark
Slack SlackApiKey Green Checkmark Green Checkmark
Slack SlackAppLevelToken Green Checkmark Green Checkmark
Slack SlackWebhook Green Checkmark
Slack SlackWorkflowKey Green Checkmark
Splunk SplunkHecApiKey Green Checkmark
Splunk SplunkJwtToken Green Checkmark
Splunk SplunkSessionKey Green Checkmark
Square SquareApplicationSecret Green Checkmark
Square SquareCredentials Green Checkmark
Square SquarePat Green Checkmark
SSLMate SSLMateApiKey Green Checkmark
SSLMAte SSLMateClusterSecret Green Checkmark
Stripe StripeLiveApiKey Green Checkmark Green Checkmark
Stripe StripeLiveRestrictedApiKey Green Checkmark
Stripe StripeTestApiKey Green Checkmark
Stripe StripeTestRestrictedApiKey Green Checkmark
Stripe StripeWebhookSigningSecret Green Checkmark
Supabase SupabaseServiceKey Green Checkmark
Tableau TableauPersonalAccessToken Green Checkmark
Telegram TelegramBotToken Green Checkmark
Telnyx TelnyxApiV2Key Green Checkmark
Tencent Cloud TencentCloudCredentials Green Checkmark Green Checkmark
Tencent Cloud TencentCloudSecretId Green Checkmark Green Checkmark
Twilio TwilioApiKeyCredentials Green Checkmark
Twilio TwilioCredentials Green Checkmark
Typeform TypeformPat Green Checkmark Green Checkmark
Uniwise WISEFlowApiKey Green Checkmark Green Checkmark
WakaTime WakaTimeAppCredentials Green Checkmark Green Checkmark
WakaTime WakaTimeOAuthAccessToken Green Checkmark Green Checkmark
WakaTime WakaTimeOAuthRefreshToken Green Checkmark Green Checkmark
WorkOS WorkOSProductionApiKey Green Checkmark Green Checkmark
WorkOS WorkOSStagingApiKey Green Checkmark
Yandex YandexCloudApiKey Green Checkmark
Yandex YandexCloudIamAccessSecret Green Checkmark
Yandex YandexCloudIamCookie Green Checkmark
Yandex YandexCloudIamToken Green Checkmark
Yandex YandexDictionaryApiKey Green Checkmark
Yandex YandexPassportOAuthToken Green Checkmark Green Checkmark
Yandex YandexPredictorApiKey Green Checkmark
Yandex YandexTranslateApiKey Green Checkmark
Zuplo ZuploConsumerApiKey Green Checkmark Green Checkmark

Non-provider patterns

The following table lists the non-provider generated secrets detected by secret scanning. Non-provider secrets are viewable by selecting "Other" from the confidence dropdown on the secret scanning tab. For more information, see Manage secret scanning alerts.

Tip

The detection of non-provider patterns is currently in beta and subject to change.

Provider Supported Secret Token Name
Generic ASP.NET Machine Key AspNetMachineKey
Generic DER-encoded Private Key DerPrivateKey
Generic Dynatrace Token DynatraceToken
Generic GPG Credentials GpgCredentials
Generic HTTP Request Headers HttpAuthorizationRequestHeader
Generic JavaScript Web Token GenericJwt
Generic LinkedIn Credentials LinkedInCredentials
Generic MongoDB Connection String MongoDbCredentials
Generic MySQL/MariaDB Connection String MySqlCredentials
Generic PEM-encoded Private Key PemPrivateKey
Generic PGP Private Key PgpPrivateKey
Generic PKCS12 Formatted Private Key Pkcs12PrivateKey
Generic PostgreSQL Connection String PostgreSqlCredentials
Generic Putty Private Key PuttyPrivateKey
Generic RabbitMQ Credentials RabbitMqCredentials
Generic RSA Private Key RsaPrivateKey
Generic SQL Server Connection String SqlLegacyCredentials
Generic SSH PrivateKey OpenSshPrivateKey
Generic SSH PrivateKey GitHubSshPrivateKey
Generic URL Encoded Credentials UrlCredentials