Skip to main content

Secret scanning patterns

Lists of supported secrets and the partners that GitHub works with to prevent fraudulent use of secrets that were committed accidentally.

秘密扫描合作伙伴模式 is automatically run on all public repositories. If you have a license for GitHub Advanced Security, you can enable and configure > - 秘密扫描,用于高级安全 for any repository owned by an organization. 更多信息请参阅“GitHub 的产品”。

About 秘密扫描 patterns

GitHub Enterprise Cloud maintains two different sets of 秘密扫描 patterns:

  1. Partner patterns. Used to detect potential secrets in all public repositories. For details, see "Supported secrets for partner patterns."
  2. Advanced security patterns. Used to detect potential secrets in repositories with 秘密扫描 enabled. For details, see "Supported secrets for advanced security."

Supported secrets for partner patterns

GitHub Enterprise Cloud currently scans public repositories for secrets issued by the following service providers. For more information about 秘密扫描合作伙伴模式, see "About 秘密扫描合作伙伴模式."

合作伙伴支持的密钥
Adafruit IOAdafruit IO 密钥
AdobeAdobe 设备令牌
AdobeAdobe 服务令牌
AdobeAdobe 短暂访问令牌
AdobeAdobe JSON Web 令牌
Alibaba CloudAlibaba 云端访问密钥 ID 和访问密钥对
Amazon Web Services (AWS)Amazon AWS 访问密钥 ID 和秘密访问密钥对
AtlassianAtlassian API 令牌
AtlassianAtlassian JSON Web 令牌
AzureAzure Active Directory 应用程序密钥
AzureAzure DevOps 个人访问令牌
AzureAzure SAS 令牌
AzureAzure 服务管理证书
AzureAzure SQL 连接字符串
AzureAzure 存储账户密钥
Checkout.comCheckout.com 生产密钥
Checkout.comCheckout.com 测试密钥
ClojarsClojars 部署令牌
CloudBees CodeShipCloudBees CodeShip 凭据
Contributed SystemsContributed Systems 凭据
DatabricksDatabricks 访问令牌
DatadogDatadog API 密钥
DigitalOceanDigitalOcean 个人访问令牌
DigitalOceanDigitalOcean OAuth 令牌
DigitalOceanDigitalOcean 刷新令牌
DigitalOceanDigitalOcean 系统令牌
DiscordDiscord 自动程序令牌
DopplerDoppler 个人令牌
DopplerDoppler 服务令牌
DopplerDoppler CLI 令牌
DopplerDoppler SCIM 令牌
DopplerDoppler Audit 令牌
DropboxDropbox 访问令牌
DropboxDropbox 短暂访问令牌
DynatraceDynatrace 访问令牌
DynatraceDynatrace 内部令牌
FinicityFinicity App 密钥
Frame.ioFrame.io JSON Web 令牌
Frame.ioFrame.io Developer 令牌
FullStoryFullStory API 密钥
GitHubGitHub 个人访问令牌
GitHubGitHub OAuth 访问令牌
GitHubGitHub 刷新令牌
GitHubGitHub App 安装访问令牌
GitHubGitHub SSH 私钥
GoCardlessGoCardless 实时访问令牌
GoCardlessGoCardless Sandbox 访问令牌
Google CloudGoogle API 密钥
Google CloudGoogle Cloud 私钥 ID
Hashicorp TerraformTerraform Cloud / Enterprise API 令牌
HubspotHubspot API 密钥
IonicIonic 个人访问令牌
IonicIonic 刷新令牌
JD CloudJD Cloud 访问密钥
线性线性 API 密钥
线性线性 OAuth 访问令牌
MailchimpMailchimp API 密钥
MailchimpMandril API 密钥
MailgunMailgun API 密钥
MessageBirdMessageBird API 密钥
元数据Facebook Access Token
npmnpm 访问令牌
NuGetNuGet API 密钥
Octopus DeployOctopus Deploy API 密钥
OpenAIOpenAI API 密钥
PalantirPalantir JSON Web 令牌
PlanetScalePlanetscale 数据库密码
PlanetScalePlanetscale OAuth 令牌
PlanetScalePlanetScale 服务令牌
PlivoPlivo 验证 ID 和令牌
PostmanPostman API 密钥
ProctorioProctorio 消费者密钥
ProctorioProctorio 链接密钥
ProctorioProctorio 注册密钥
ProctorioProctorio 密钥
PulumiPulumi 访问令牌
PyPIPyPI API 令牌
redirect.pizzaredirect.pizza API 令牌
RubyGemsRubyGems API 密钥
SamsaraSamsara API 令牌
SamsaraSamsara OAuth 访问令牌
SendGridSendGrid API Key
SendinblueSendinBlue API 密钥
SendinblueSendinBlue SMTP 密钥
ShopifyShopify App 共享密钥
ShopifyShopify 访问令牌
ShopifyShopify 自定义应用访问令牌
ShopifyShopify 私人应用密码
SlackSlack API 令牌
SlackSlack 传入 web 挂钩 URL
SlackSlack 工作流程 web 挂钩 URL
SSLMateSSLMate API 密钥
SSLMateSSLMate 集群密钥
StripeStripe Live API 密钥
StripeStripe 测试 API 密钥
StripeStripe Live API 限制密钥
StripeStripe 测试 API 限制密钥
SupabaseSupabase 服务密钥
Tencent Cloud腾讯云密钥 ID
TwilioTwilio 帐户字符串标识符
TwilioTwilio API 密钥
TypeformTypeform 个人访问令牌
ValourValour 访问令牌

Supported secrets for advanced security

When > - 秘密扫描,用于高级安全 is enabled, GitHub scans for secrets issued by the following service providers. For more information about > - 秘密扫描,用于高级安全, see "About > - 秘密扫描,用于高级安全."

If you use the REST API for secret scanning, you can use the Secret type to report on secrets from specific issuers. For more information, see "Secret scanning."

Note: You can also define custom 秘密扫描 patterns for your repository, organization, or enterprise. For more information, see "Defining custom patterns for 秘密扫描."

提供者支持的密钥密钥类型
Adafruit IOAdafruit IO 密钥adafruit_io_key
AdobeAdobe Device Tokenadobe_device_token
AdobeAdobe Service Tokenadobe_service_token
AdobeAdobe Short-Lived Access Tokenadobe_short_lived_access_token
AdobeAdobe JSON Web Tokenadobe_jwt Alibaba Cloud
AmazonAmazon OAuth 客户端 IDamazon_oauth_client_id
AmazonAmazon OAuth 客户端机密amazon_oauth_client_secret Amazon Web Services (AWS)
Amazon Web Services (AWS)Amazon AWS Session Tokenaws_session_token
Amazon Web Services (AWS)Amazon AWS Temporary Access Key IDaws_temporary_access_key_id
AsanaAsana 个人访问令牌asana_personal_access_token Atlassian
AtlassianBitbucket Server Personal Access Tokenbitbucket_server_personal_access_token
AzureAzure Active Directory 应用程序密钥azure_active_directory_application_secret
AzureAzure Cache for Redis 访问密钥azure_cache_for_redis_access_key Azure
BeamerBeamer API Keybeamer_api_key
Checkout.comCheckout.com Production Secret Keycheckout_production_secret_key
Checkout.comCheckout.com 测试密钥checkout_test_secret_key Clojars
CloudBees CodeShipCloudBees CodeShip Credentialcodeship_credential
ContentfulContentful 个人访问令牌contentful_personal_access_token Databricks
DigitalOceanDigitalOcean 个人访问令牌digitalocean_personal_access_token DigitalOcean
DopplerDoppler 审核令牌doppler_audit_token Dropbox
DuffelDuffel Live Access Tokenduffel_live_access_token
DuffelDuffel 测试访问令牌duffel_test_access_token Dynatrace
EasyPostEasyPost Production API Keyeasypost_production_api_key
EasyPostEasyPost Test API Keyeasypost_test_api_key
FastlyFastly API 令牌fastly_api_token Finicity
FlutterwaveFlutterwave Live API Secret Keyflutterwave_live_api_secret_key
FlutterwaveFlutterwave 测试 API 密钥flutterwave_test_api_secret_key Frame.io
FullStoryFullStory API Keyfullstory_api_key
GitHubGitHub Personal Access Tokengithub_personal_access_token
GitHubGitHub OAuth Access Tokengithub_oauth_access_token
GitHubGitHub Refresh Tokengithub_refresh_token
GitHubGitHub App 安装访问令牌github_app_installation_access_token GitHub
GitLabGitLab 访问令牌gitlab_access_token GoCardless
GoogleFirebase Cloud Messaging Server 密钥firebase_cloud_messaging_server_key Google
GoogleGoogle Cloud Storage Access Key Secretgoogle_cloud_storage_access_key_secret
GoogleGoogle Cloud Storage Service Account Access Key IDgoogle_cloud_storage_service_account_access_key_id
GoogleGoogle Cloud Storage User Access Key IDgoogle_cloud_storage_user_access_key_id
GoogleGoogle OAuth 访问令牌google_oauth_access_token
GoogleGoogle OAuth 客户端 IDgoogle_oauth_client_id
GoogleGoogle OAuth 客户端密钥google_oauth_client_secret
GoogleGoogle OAuth 更新令牌google_oauth_refresh_token
GrafanaGrafana API 密钥grafana_api_key HashiCorp
IntercomIntercom Access Tokenintercom_access_token
IonicIonic Personal Access Tokenionic_personal_access_token
IonicIonic Refresh Tokenionic_refresh_token
JD CloudJD Cloud 访问密钥jd_cloud_access_key
JFrogJFrog Platform Access Tokenjfrog_platform_access_token
JFrogJFrog Platform API Keyjfrog_platform_api_key
LinearLinear API Keylinear_api_key
LinearLinear OAuth Access Tokenlinear_oauth_access_token
LobLob Live API Keylob_live_api_key
LobLob Test API 密钥lob_test_api_key Mailchimp
MapboxMapbox 密钥访问令牌mapbox_secret_access_token
MessageBirdMessageBird API Keymessagebird_api_key
MetaFacebook 访问令牌facebook_access_token
MidtransMidtrans Production Server 密钥midtrans_production_server_key
MidtransMidtrans Sandbox Server 密钥midtrans_sandbox_server_key
New RelicNew Relic Personal API Keynew_relic_personal_api_key
New RelicNew Relic REST API Keynew_relic_rest_api_key
New RelicNew Relic Insights Query Keynew_relic_insights_query_key
New RelicNew Relic License Keynew_relic_license_key
NotionNotion 集成令牌notion_integration_token
NotionNotion OAuth 客户端密钥notion_oauth_client_secret npm
Octopus DeployOctopus Deploy API 密钥octopus_deploy_api_key
OnfidoOnfido Live API Tokenonfido_live_api_token
OnfidoOnfido Sandbox API Tokenonfido_sandbox_api_token
OpenAIOpenAI API 密钥openai_api_key Palantir
PlanetScalePlanetScale Database Passwordplanetscale_database_password
PlanetScalePlanetScale OAuth Tokenplanetscale_oauth_token
PlanetScalePlanetScale Service Tokenplanetscale_service_token
PlivoPlivo Auth IDplivo_auth_id
PlivoPlivo 验证令牌plivo_auth_token Postman
PyPIPyPI API Tokenpypi_api_token
redirect.pizzaredirect.pizza API Tokenredirect_pizza_api_token
RubyGemsRubyGems API 密钥rubygems_api_key Samsara
SegmentSegment 公共 API 令牌segment_public_api_token
SendGridSendGrid API Keysendgrid_api_key
SendinblueSendinblue API Keysendinblue_api_key
SendinblueSendinblue SMTP Keysendinblue_smtp_key
ShippoShippo Live API Tokenshippo_live_api_token
ShippoShippo Test API Tokenshippo_test_api_token
ShopifyShopify App 客户端凭据shopify_app_client_credentials Shopify
ShopifyShopify 商家令牌shopify_merchant_token Shopify
SquareSquare 访问令牌square_access_token
SquareSquare Production Application 密钥square_production_application_secret
SquareSquare Sandbox 应用程序密钥square_sandbox_application_secret SSLMate
StripeStripe Webhook Signing Secretstripe_webhook_signing_secret
SupabaseSupabase 服务密钥supabase_service_key Tableau
TelegramTelegram Bot 令牌telegram_bot_token Tencent Cloud
TwilioTwilio 访问令牌twilio_access_token Twilio
TypeformTypeform 个人访问令牌typeform_personal_access_token
WorkOSWorkOS Production API 密钥workos_production_api_key
WorkOSWorkOS Staging API 密钥workos_staging_api_key
YandexYandex.Cloud API 密钥yandex_cloud_api_key
YandexYandex.Cloud IAM Cookieyandex_cloud_iam_cookie
YandexYandex.Cloud IAM 令牌yandex_cloud_iam_token
YandexYandex.Dictionary API 密钥yandex_dictionary_api_key
YandexYandex.Cloud 访问密钥yandex_iam_access_secret
YandexYandex.Predictor API 密钥yandex_predictor_api_key
YandexYandex.Translate API 密钥yandex_translate_api_key

Further reading