Secret scanning patterns
Advanced Security maintains multiple sets of default secret scanning patterns:
- *Push protection patterns - used to detect potential secrets at push time in repositories with secret scanning push protection enabled.
- User alert patterns - used to detect potential secrets in repositories with secret scanning alerts enabled.
- Non-provider patterns - used to detect common occurrences of structured secrets in repositories with secret scanning alerts enabled.
Supported secrets
Section | Explanation |
---|---|
Provider | The name of the token provider. |
Token name | The type of token discovered by Advanced Security secret scanning. |
User | A token for which leaks are reported to users post-push. Applies to all repositories where Advanced Security is enabled |
Push protection | A token for which leaks are reported to users on push. Applies to all repositories where secret push protection enabled. |
Validity | Tokens for which Advanced Security attempts to perform a validity check. |
Partner provider patterns
The following table lists the partner provider patterns supported by secret scanning.
Provider | Token Name | Push Protection | User Alerts | Validity Checking |
---|---|---|---|---|
Adafruit IO | AdafruitIOKey | ![]() |
![]() |
|
Adobe | AdobeDeviceToken | ![]() |
||
Adobe | AdobeServiceToken | ![]() |
||
Adobe | AdobeShortLivedAccessToken | ![]() |
||
Akamai | AkamaiCredentials | ![]() |
||
Alibaba Cloud | AlibabaCloudCredentials | ![]() |
![]() |
|
Amazon | AmazonMwsAuthToken | ![]() |
||
Amazon | AmazonOAuthCredentials | ![]() |
![]() |
|
Amazon | AwsCredentials | ![]() |
![]() |
|
Amazon | AwsTemporaryCredentials | ![]() |
![]() |
|
Asana | AsanaPat | ![]() |
![]() |
|
Atlassian | AtlassianApiToken | ![]() |
||
Atlassian | AtlassianJwt | ![]() |
||
Atlassian | BitbucketCloudOAuthCredentials | ![]() |
||
Atlassian | BitbucketServerPat | ![]() |
![]() |
|
Beamer | BeamerApiKey | ![]() |
||
Brevo | BrevoApiKey | ![]() |
![]() |
|
Brevo | BrevoSmtpKey | ![]() |
![]() |
|
Canadian Digital Service | CdsCanadaNotifyApiKey | ![]() |
![]() |
|
Checkout.com | CheckoutIdentifiableSecretKey | ![]() |
||
Chief Tools | ChiefToolsToken | ![]() |
![]() |
|
Cisco | CiscoLocalAccountCredentials | ![]() |
||
Clojars | ClojarsDeployToken | ![]() |
||
Cloudant | CloudantCredentials | ![]() |
||
Cloudflare | CloudflareApiToken | ![]() |
||
Contentful | ContentfulPersonalAccessToken | ![]() |
||
Crates.io | CratesApiKey | ![]() |
||
DevCycle | DevCycleClientApiKey | ![]() |
![]() |
|
DevCycle | DevCycleManagementApiToken | ![]() |
||
DevCycle | DevCycleMobileApiKey | ![]() |
![]() |
|
DevCycle | DevCycleServerApiKey | ![]() |
![]() |
|
DigitalOcean | DigitalOceanOAuthToken | ![]() |
![]() |
|
DigitalOcean | DigitalOceanPat | ![]() |
![]() |
|
DigitalOcean | DigitalOceanRefreshToken | ![]() |
![]() |
|
DigitalOcean | DigitalOceanSystemToken | ![]() |
![]() |
|
Discord | DiscordApiCredentials | ![]() |
||
Discord | DiscordApiToken | ![]() |
![]() |
|
Doppler | DopplerAuditToken | ![]() |
![]() |
|
Doppler | DopplerCliToken | ![]() |
![]() |
|
Doppler | DopplerPersonalToken | ![]() |
![]() |
|
Doppler | DopplerScimToken | ![]() |
![]() |
|
Doppler | DopplerServiceToken | ![]() |
![]() |
|
Dropbox | DropboxAccessToken | ![]() |
||
Dropbox | DropboxAppCredentials | ![]() |
||
Dropbox | DropboxOAuth2ShortLivedAccessToken | ![]() |
![]() |
|
Duffel | DuffelAccessToken | ![]() |
![]() |
|
Dynatrace | DynatraceInternalToken | ![]() |
||
EasyPost | EasyPostApiKey | ![]() |
![]() |
|
Ebay | EBayProductionClientCredentials | ![]() |
||
Ebay | EBaySandboxClientCredentials | ![]() |
||
Elastic | ElasticCloudApiKey | ![]() |
||
Elastic | ElasticStackApiKey | ![]() |
||
EventBrite | PicaticApiKey | ![]() |
||
FacebookAccessToken | ![]() |
|||
FacebookAppCredentials | ![]() |
|||
OculusAccessToken | ![]() |
|||
Fastly | FastlyApiToken | ![]() |
||
Figma | FigmaPat | ![]() |
![]() |
|
Finicity | FinicityAppKey | ![]() |
||
Flutterwave | FlutterwaveLiveApiSecretKey | ![]() |
![]() |
|
Flutterwave | FlutterwaveTestApiSecretKey | ![]() |
||
Frame.io | FrameIODeveloperToken | ![]() |
||
Frame.io | FrameIOJwt | ![]() |
||
FullStory | FullStoryApiKey | ![]() |
![]() |
|
GitHub | GitHubAppCredentials | ![]() |
||
GitHub | GitHubAppToken | ![]() |
![]() |
|
GitHub | GitHubClassicPat | ![]() |
![]() |
|
GitHub | GitHubOAuthAccessToken | ![]() |
![]() |
|
GitHub | GitHubPat | ![]() |
![]() |
|
GitHub | GitHubRefreshToken | ![]() |
![]() |
|
GitHub | GitHubServerToServerToken | ![]() |
![]() |
|
GitHub | GitHubUserToServerToken | ![]() |
![]() |
|
GitLab | GitLabAccessToken | ![]() |
||
GoCardless | GoCardlessLiveAccessToken | ![]() |
||
GoCardless | GoCardlessSandboxAccessToken | ![]() |
||
FirebaseCloudMessagingServerKey | ![]() |
|||
GoogleApiKey | ![]() |
|||
GoogleCloudPrivateKeyId | ![]() |
![]() |
||
GoogleCloudStorageServiceAccountAccessKey | ![]() |
![]() |
||
GoogleCloudStorageUserAccessKey | ![]() |
![]() |
||
GoogleOAuthAccessToken | ![]() |
|||
GoogleOAuthCredentials | ![]() |
|||
GoogleOAuthRefreshToken | ![]() |
|||
GoogleServiceAccountKey | ![]() |
|||
Grafana | GrafanaApiKey | ![]() |
![]() |
|
Grafana | GrafanaCloudApiToken | ![]() |
||
Grafana | GrafanaProjectApiKey | ![]() |
||
Grafana | GrafanaProjectServiceAccountToken | ![]() |
||
Hashicorp | HashiCorpVaultBatchLegacyToken | ![]() |
![]() |
|
Hashicorp | HashiCorpVaultBatchToken | ![]() |
![]() |
|
Hashicorp | HashiCorpVaultRootServiceToken | ![]() |
![]() |
|
Hashicorp | HashiCorpVaultServiceLegacyToken | ![]() |
![]() |
|
Hashicorp | HashiCorpVaultServiceToken | ![]() |
![]() |
|
Hashicorp | TerraformCloudEnterpriseToken | ![]() |
![]() |
|
HighNote | HighnoteRkKey | ![]() |
![]() |
|
HighNote | HighnoteSkKey | ![]() |
![]() |
|
HubSpot | HubspotApiKey | ![]() |
![]() |
|
HubSpot | HubSpotApiPersonalAccessKey | ![]() |
![]() |
|
HuggingFace | HuggingFaceAccessToken | ![]() |
||
Intercom | IntercomAccessToken | ![]() |
![]() |
|
Ionic | IonicPat | ![]() |
![]() |
|
Ionic | IonicRefreshToken | ![]() |
![]() |
|
JD Cloud | JdCloudAccessKey | ![]() |
||
JFrog | JFrogPlatformAccessToken | ![]() |
![]() |
|
JFrog | JFrogPlatformApiKey | ![]() |
![]() |
|
Linear | LinearApiKey | ![]() |
![]() |
|
Linear | LinearOAuthAccessToken | ![]() |
![]() |
|
Lob | LobLiveApiKey | ![]() |
||
Lob | LobTestApiKey | ![]() |
||
LocalStack | LocalStackApiKey | ![]() |
||
LogicMonitor | LogicMonitorBearerToken | ![]() |
![]() |
|
LogicMonitor | LogicMonitorLmv1AccessKey | ![]() |
![]() |
|
MailChimp | MailChimpApiKey | ![]() |
||
Mailgun | MailgunApiCredentials | ![]() |
||
Mapbox | MapboxSecretAccessToken | ![]() |
||
MessageBird | MessageBirdApiKey | ![]() |
||
Microsoft | AadClientAppIdentifiableCredentials | ![]() |
![]() |
|
Microsoft | AdoPat | ![]() |
![]() |
|
Microsoft | AzureApimDirectManagementSas | ![]() |
||
Microsoft | AzureApimGatewaySas | ![]() |
||
Microsoft | AzureApimIdentifiableDirectManagementKey | ![]() |
![]() |
|
Microsoft | AzureApimIdentifiableGatewayKey | ![]() |
![]() |
|
Microsoft | AzureApimIdentifiableRepositoryKey | ![]() |
![]() |
|
Microsoft | AzureApimIdentifiableSubscriptionKey | ![]() |
![]() |
|
Microsoft | AzureApimLegacyDirectManagementKey | ![]() |
||
Microsoft | AzureApimLegacyGatewayKey | ![]() |
![]() |
|
Microsoft | AzureApimLegacyRepositoryKey | ![]() |
![]() |
|
Microsoft | AzureApimLegacySubscriptionKey | ![]() |
||
Microsoft | AzureApimRepositorySas | ![]() |
||
Microsoft | AzureAppConfigurationCredentials | ![]() |
![]() |
|
Microsoft | AzureApplicationInsightsCredentials | ![]() |
||
Microsoft | AzureBatchIdentifiableKey | ![]() |
![]() |
|
Microsoft | AzureBatchLegacyKey | ![]() |
||
Microsoft | AzureBlockchainCredentials | ![]() |
||
Microsoft | AzureCacheForRedisIdentifiableKey | ![]() |
![]() |
|
Microsoft | AzureCacheForRedisIdentifiablePrivateServiceKey | ![]() |
![]() |
|
Microsoft | AzureCacheForRedisLegacyKey | ![]() |
![]() |
|
Microsoft | AzureCdnSas | ![]() |
||
Microsoft | AzureCognitiveServicesKey | ![]() |
||
Microsoft | AzureCognitiveServicesTranslatorKey | ![]() |
||
Microsoft | AzureCommunicationServicesKey | ![]() |
![]() |
|
Microsoft | AzureContainerRegistryIdentifiableKey | ![]() |
![]() |
|
Microsoft | AzureContainerRegistryLegacyKey | ![]() |
![]() |
|
Microsoft | AzureCosmosDBIdentifiableKey | ![]() |
![]() |
|
Microsoft | AzureCosmosDBIdentifiablePrivateServiceKey | ![]() |
![]() |
|
Microsoft | AzureCosmosDBLegacyKey | ![]() |
![]() |
|
Microsoft | AzureDatabricksPat | ![]() |
![]() |
|
Microsoft | AzureDevOpsOAuthToken | ![]() |
||
Microsoft | AzureEventGridKey | ![]() |
![]() |
|
Microsoft | AzureEventHubIdentifiableKey | ![]() |
![]() |
|
Microsoft | AzureEventHubIdentifiablePrivateServiceSystemKey | ![]() |
![]() |
|
Microsoft | AzureFluidRelayKey | ![]() |
||
Microsoft | AzureFunctionIdentifiableKey | ![]() |
![]() |
|
Microsoft | AzureFunctionLegacyKey | ![]() |
![]() |
|
Microsoft | AzureGenomicsKey | ![]() |
||
Microsoft | AzureHDInsightCredentials | ![]() |
||
Microsoft | AzureIotDeviceIdentifiableKey | ![]() |
![]() |
|
Microsoft | AzureIotDeviceLegacyCredentials | ![]() |
![]() |
|
Microsoft | AzureIotDeviceProvisioningIdentifiableKey | ![]() |
![]() |
|
Microsoft | AzureIotDeviceProvisioningLegacyCredentials | ![]() |
![]() |
|
Microsoft | AzureIotHubIdentifiableKey | ![]() |
![]() |
|
Microsoft | AzureIotHubLegacyCredentials | ![]() |
![]() |
|
Microsoft | AzureLogicAppSas | ![]() |
||
Microsoft | AzureManagementCertificate | ![]() |
||
Microsoft | AzureMapsKey | ![]() |
||
Microsoft | AzureMixedRealityCredentials | ![]() |
||
Microsoft | AzureMLIdentifiablePrivateServicePrincipalCredentials | ![]() |
![]() |
|
Microsoft | AzureMLWebServiceClassicIdentifiableKey | ![]() |
![]() |
|
Microsoft | AzureMLWebServiceKey | ![]() |
||
Microsoft | AzureOpenAIKey | ![]() |
||
Microsoft | AzureRelayIdentifiableKey | ![]() |
![]() |
|
Microsoft | AzureSearchIdentifiableAdminKey | ![]() |
![]() |
|
Microsoft | AzureSearchIdentifiablePrivateServiceAdminKey | ![]() |
![]() |
|
Microsoft | AzureSearchIdentifiableQueryKey | ![]() |
![]() |
|
Microsoft | AzureSearchLegacyKey | ![]() |
||
Microsoft | AzureServiceBusIdentifiableKey | ![]() |
![]() |
|
Microsoft | AzureServiceBusIdentifiablePrivateServiceSystemKey | ![]() |
![]() |
|
Microsoft | AzureServiceBusLegacyCredentials | ![]() |
![]() |
|
Microsoft | AzureServiceDeploymentCredentials | ![]() |
||
Microsoft | AzureSignalRKey | ![]() |
![]() |
|
Microsoft | AzureStorageAccountIdentifiableKey | ![]() |
![]() |
|
Microsoft | AzureStorageAccountLegacyCredentials | ![]() |
![]() |
|
Microsoft | AzureStorageIdentifiablePrivateServiceKey | ![]() |
![]() |
|
Microsoft | AzureStorageLooseSas | ![]() |
||
Microsoft | AzureStorageSas | ![]() |
||
Microsoft | AzureWebAppBotCredentials | ![]() |
||
Microsoft | AzureWebAppBotKey | ![]() |
||
Microsoft | AzureWebPubSubCredentials | ![]() |
![]() |
|
Microsoft | BingApiKey | ![]() |
||
Microsoft | BingMapsKey | ![]() |
||
Microsoft | BingSearchKey | ![]() |
||
Microsoft | OfficeIncomingWebhook | ![]() |
![]() |
|
Microsoft | Sas | ![]() |
||
Microsoft | SqlIdentifiableCredentials | ![]() |
![]() |
|
Microsoft | VisualStudioAppCenterKey | ![]() |
||
Midtrans | MidtransServerKey | ![]() |
![]() |
|
New Relic | NewRelicInsightsQueryKey | ![]() |
![]() |
|
New Relic | NewRelicLicenseKey | ![]() |
||
New Relic | NewRelicPersonalApiKey | ![]() |
![]() |
|
New Relic | NewRelicRestApiKey | ![]() |
![]() |
|
Notion | NotionIntegrationToken | ![]() |
||
Notion | NotionOAuthClientCredentials | ![]() |
||
npm | NpmAuthorIdentifiableToken | ![]() |
![]() |
|
npm | NpmCredentials | ![]() |
![]() |
|
npm | NpmLegacyAuthorToken | ![]() |
||
NuGet | NuGetApiKey | ![]() |
![]() |
|
NuGet | NuGetCredentials | ![]() |
||
Octopus Deploy | OctopusDeployApiKey | ![]() |
||
Onfido | OnfidoApiToken | ![]() |
![]() |
|
OpenAI | OpenAIApiKeyV2 | ![]() |
![]() |
|
Palantir | PalantirJwt | ![]() |
||
PayPal | PayPalBraintreeAccessToken | ![]() |
||
Persona | PersonaProductionApiKey | ![]() |
![]() |
|
Persona | PersonaSandboxApiKey | ![]() |
||
PineCone | PineconeApiKey | ![]() |
||
PlanetScale | PlanetScaleDatabasePassword | ![]() |
![]() |
|
PlanetScale | PlanetScaleOAuthToken | ![]() |
![]() |
|
PlanetScale | PlanetScaleServiceToken | ![]() |
![]() |
|
Plivo | PlivoCredentials | ![]() |
||
Prefect | PrefectServerApiToken | ![]() |
![]() |
|
Prefect | PrefectUserApiToken | ![]() |
![]() |
|
Proctorio | ProctorioConsumerKey | ![]() |
||
Proctorio | ProctorioLinkageKey | ![]() |
||
Proctorio | ProctorioRegistrationKey | ![]() |
||
Proctorio | ProctorioSecretKeyV2 | ![]() |
![]() |
|
Pulumi | PulumiAccessToken | ![]() |
||
PyPi | PyPiApiToken | ![]() |
||
ReadMe | ReadMeApiKey | ![]() |
![]() |
|
redirect.pizza | RedirectPizzaApiToken | ![]() |
![]() |
|
Rubygems | RubyGemsApiKey | ![]() |
||
SAMPLE | SecretScanningSampleToken | |||
Samsara | SamsaraApiAccessToken | ![]() |
![]() |
|
Samsara | SamsaraOAuth2AccessToken | ![]() |
![]() |
|
Segment.io | SegmentPublicApiToken | ![]() |
||
SendGrid | SendGridApiKey | ![]() |
![]() |
|
Shippo | ShippoLiveApiToken | ![]() |
![]() |
|
Shippo | ShippoTestApiToken | ![]() |
||
Shopify | ShopifyAccessToken | ![]() |
![]() |
|
Shopify | ShopifyAppClientCredentials | ![]() |
||
Shopify | ShopifyAppClientSecret | ![]() |
||
Shopify | ShopifyAppOAuthAccessToken | ![]() |
||
Shopify | ShopifyCustomAppAccessToken | ![]() |
||
Shopify | ShopifyMarketplaceToken | ![]() |
||
Shopify | ShopifyMerchantToken | ![]() |
||
Shopify | ShopifyPartnerApiToken | ![]() |
||
Shopify | ShopifyPrivateAppPassword | ![]() |
||
Shopify | ShopifySharedSecret | ![]() |
![]() |
|
Slack | SlackApiKey | ![]() |
![]() |
|
Slack | SlackAppLevelToken | ![]() |
![]() |
|
Slack | SlackWebhook | ![]() |
||
Slack | SlackWorkflowKey | ![]() |
||
Splunk | SplunkHecApiKey | ![]() |
||
Splunk | SplunkJwtToken | ![]() |
||
Splunk | SplunkSessionKey | ![]() |
||
Square | SquareApplicationSecret | ![]() |
||
Square | SquareCredentials | ![]() |
||
Square | SquarePat | ![]() |
||
SSLMate | SSLMateApiKey | ![]() |
||
SSLMAte | SSLMateClusterSecret | ![]() |
||
Stripe | StripeLiveApiKey | ![]() |
![]() |
|
Stripe | StripeLiveRestrictedApiKey | ![]() |
||
Stripe | StripeTestApiKey | ![]() |
||
Stripe | StripeTestRestrictedApiKey | ![]() |
||
Stripe | StripeWebhookSigningSecret | ![]() |
||
Supabase | SupabaseServiceKey | ![]() |
||
Tableau | TableauPersonalAccessToken | ![]() |
||
Telegram | TelegramBotToken | ![]() |
||
Telnyx | TelnyxApiV2Key | ![]() |
||
Tencent Cloud | TencentCloudCredentials | ![]() |
![]() |
|
Tencent Cloud | TencentCloudSecretId | ![]() |
![]() |
|
Twilio | TwilioApiKeyCredentials | ![]() |
||
Twilio | TwilioCredentials | ![]() |
||
Typeform | TypeformPat | ![]() |
![]() |
|
Uniwise | WISEFlowApiKey | ![]() |
![]() |
|
WakaTime | WakaTimeAppCredentials | ![]() |
![]() |
|
WakaTime | WakaTimeOAuthAccessToken | ![]() |
![]() |
|
WakaTime | WakaTimeOAuthRefreshToken | ![]() |
![]() |
|
WorkOS | WorkOSProductionApiKey | ![]() |
![]() |
|
WorkOS | WorkOSStagingApiKey | ![]() |
||
Yandex | YandexCloudApiKey | ![]() |
||
Yandex | YandexCloudIamAccessSecret | ![]() |
||
Yandex | YandexCloudIamCookie | ![]() |
||
Yandex | YandexCloudIamToken | ![]() |
||
Yandex | YandexDictionaryApiKey | ![]() |
||
Yandex | YandexPassportOAuthToken | ![]() |
![]() |
|
Yandex | YandexPredictorApiKey | ![]() |
||
Yandex | YandexTranslateApiKey | ![]() |
||
Zuplo | ZuploConsumerApiKey | ![]() |
![]() |
Non-provider patterns
The following table lists the non-provider generated secrets detected by secret scanning. Non-provider secrets are viewable by selecting "Other" from the confidence dropdown on the secret scanning tab. For more information, see Manage secret scanning alerts.
Tip
The detection of non-provider patterns is currently in beta and subject to change.
Provider | Supported Secret | Token Name |
---|---|---|
Generic | ASP.NET Machine Key | AspNetMachineKey |
Generic | DER-encoded Private Key | DerPrivateKey |
Generic | Dynatrace Token | DynatraceToken |
Generic | GPG Credentials | GpgCredentials |
Generic | HTTP Request Headers | HttpAuthorizationRequestHeader |
Generic | JavaScript Web Token | GenericJwt |
Generic | LinkedIn Credentials | LinkedInCredentials |
Generic | MongoDB Connection String | MongoDbCredentials |
Generic | MySQL/MariaDB Connection String | MySqlCredentials |
Generic | PEM-encoded Private Key | PemPrivateKey |
Generic | PGP Private Key | PgpPrivateKey |
Generic | PKCS12 Formatted Private Key | Pkcs12PrivateKey |
Generic | PostgreSQL Connection String | PostgreSqlCredentials |
Generic | Putty Private Key | PuttyPrivateKey |
Generic | RabbitMQ Credentials | RabbitMqCredentials |
Generic | RSA Private Key | RsaPrivateKey |
Generic | SQL Server Connection String | SqlLegacyCredentials |
Generic | SSH PrivateKey | OpenSshPrivateKey |
Generic | SSH PrivateKey | GitHubSshPrivateKey |
Generic | URL Encoded Credentials | UrlCredentials |