Skip to main content

Secret scanning patterns

Lists of supported secrets and the partners that GitHub works with to prevent fraudulent use of secrets that were committed accidentally.

秘密扫描 is available for organization-owned repositories in GitHub Enterprise Server if your enterprise has a license for GitHub Advanced Security. 更多信息请参阅“GitHub 的产品”。

Note: Your site administrator must enable 秘密扫描 for 您的 GitHub Enterprise Server 实例 before you can use this feature. For more information, see "Configuring 秘密扫描 for your appliance."

Supported secrets

When > - 秘密扫描 is enabled, GitHub scans for secrets issued by the following service providers.

If you use the REST API for secret scanning, you can use the Secret type to report on secrets from specific issuers. For more information, see "Secret scanning."

Note: You can also define custom 秘密扫描 patterns for your repository, organization, or enterprise. For more information, see "Defining custom patterns for 秘密扫描."

提供者支持的密钥密钥类型
Adafruit IOAdafruit IO 密钥adafruit_io_key
AdobeAdobe Device Tokenadobe_device_token
AdobeAdobe Service Tokenadobe_service_token
AdobeAdobe Short-Lived Access Tokenadobe_short_lived_access_token
AdobeAdobe JSON Web Tokenadobe_jwt Alibaba Cloud
AmazonAmazon OAuth 客户端 IDamazon_oauth_client_id
AmazonAmazon OAuth 客户端机密amazon_oauth_client_secret Amazon Web Services (AWS)
Amazon Web Services (AWS)Amazon AWS Session Tokenaws_session_token
Amazon Web Services (AWS)Amazon AWS Temporary Access Key IDaws_temporary_access_key_id
AsanaAsana 个人访问令牌asana_personal_access_token Atlassian
AtlassianBitbucket Server Personal Access Tokenbitbucket_server_personal_access_token
AzureAzure Active Directory 应用程序密钥azure_active_directory_application_secret
AzureAzure Cache for Redis 访问密钥azure_cache_for_redis_access_key Azure
BeamerBeamer API Keybeamer_api_key
Checkout.comCheckout.com Production Secret Keycheckout_production_secret_key
Checkout.comCheckout.com 测试密钥checkout_test_secret_key Clojars
CloudBees CodeShipCloudBees CodeShip Credentialcodeship_credential
ContentfulContentful 个人访问令牌contentful_personal_access_token Databricks
DopplerDoppler 审核令牌doppler_audit_token Dropbox
DuffelDuffel Live Access Tokenduffel_live_access_token
DuffelDuffel 测试访问令牌duffel_test_access_token Dynatrace
EasyPostEasyPost Production API Keyeasypost_production_api_key
EasyPostEasyPost Test API Keyeasypost_test_api_key
FastlyFastly API 令牌fastly_api_token Finicity
FlutterwaveFlutterwave Live API Secret Keyflutterwave_live_api_secret_key
FlutterwaveFlutterwave 测试 API 密钥flutterwave_test_api_secret_key Frame.io
FullStoryFullStory API Keyfullstory_api_key
GitHubGitHub Personal Access Tokengithub_personal_access_token
GitHubGitHub OAuth Access Tokengithub_oauth_access_token
GitHubGitHub Refresh Tokengithub_refresh_token
GitHubGitHub App 安装访问令牌github_app_installation_access_token GitHub
GitLabGitLab 访问令牌gitlab_access_token GoCardless
GoogleFirebase Cloud Messaging Server 密钥firebase_cloud_messaging_server_key Google
GoogleGoogle Cloud Storage Access Key Secretgoogle_cloud_storage_access_key_secret
GoogleGoogle Cloud Storage Service Account Access Key IDgoogle_cloud_storage_service_account_access_key_id
GoogleGoogle Cloud Storage User Access Key IDgoogle_cloud_storage_user_access_key_id
GoogleGoogle OAuth 访问令牌google_oauth_access_token
GoogleGoogle OAuth 客户端 IDgoogle_oauth_client_id
GoogleGoogle OAuth 客户端密钥google_oauth_client_secret
GoogleGoogle OAuth 更新令牌google_oauth_refresh_token
GrafanaGrafana API 密钥grafana_api_key HashiCorp
IntercomIntercom Access Tokenintercom_access_token
IonicIonic Personal Access Tokenionic_personal_access_token
IonicIonic Refresh Tokenionic_refresh_token
JFrogJFrog Platform Access Tokenjfrog_platform_access_token
JFrogJFrog Platform API Keyjfrog_platform_api_key
LinearLinear API Keylinear_api_key
LinearLinear OAuth Access Tokenlinear_oauth_access_token
LobLob Live API Keylob_live_api_key
LobLob Test API 密钥lob_test_api_key Mailchimp
MapboxMapbox 密钥访问令牌mapbox_secret_access_token
MessageBirdMessageBird API Keymessagebird_api_key
MetaFacebook 访问令牌facebook_access_token
MidtransMidtrans Production Server 密钥midtrans_production_server_key
MidtransMidtrans Sandbox Server 密钥midtrans_sandbox_server_key
New RelicNew Relic Personal API Keynew_relic_personal_api_key
New RelicNew Relic REST API Keynew_relic_rest_api_key
New RelicNew Relic Insights Query Keynew_relic_insights_query_key
New RelicNew Relic License Keynew_relic_license_key
NotionNotion 集成令牌notion_integration_token
NotionNotion OAuth 客户端密钥notion_oauth_client_secret npm
Octopus DeployOctopus Deploy API 密钥octopus_deploy_api_key
OnfidoOnfido Live API Tokenonfido_live_api_token
OnfidoOnfido Sandbox API Tokenonfido_sandbox_api_token
OpenAIOpenAI API 密钥openai_api_key Palantir
PlanetScalePlanetScale Database Passwordplanetscale_database_password
PlanetScalePlanetScale OAuth Tokenplanetscale_oauth_token
PlanetScalePlanetScale Service Tokenplanetscale_service_token
PlivoPlivo Auth IDplivo_auth_id
PlivoPlivo 验证令牌plivo_auth_token Postman
PyPIPyPI API Tokenpypi_api_token
RubyGemsRubyGems API 密钥rubygems_api_key Samsara
SendGridSendGrid API Keysendgrid_api_key
SendinblueSendinblue API Keysendinblue_api_key
SendinblueSendinblue SMTP Keysendinblue_smtp_key
ShippoShippo Live API Tokenshippo_live_api_token
ShippoShippo Test API Tokenshippo_test_api_token Shopify
SquareSquare 访问令牌square_access_token
SquareSquare Production Application 密钥square_production_application_secret
SquareSquare Sandbox 应用程序密钥square_sandbox_application_secret SSLMate
StripeStripe Webhook Signing Secretstripe_webhook_signing_secret
SupabaseSupabase 服务密钥supabase_service_key Tableau
TelegramTelegram Bot 令牌telegram_bot_token Tencent Cloud
TwilioTwilio 访问令牌twilio_access_token Twilio
TypeformTypeform 个人访问令牌typeform_personal_access_token
YandexYandex.Cloud API 密钥yandex_cloud_api_key
YandexYandex.Cloud IAM Cookieyandex_cloud_iam_cookie
YandexYandex.Cloud IAM 令牌yandex_cloud_iam_token
YandexYandex.Dictionary API 密钥yandex_dictionary_api_key
YandexYandex.Predictor API 密钥yandex_predictor_api_key
YandexYandex.Translate API 密钥yandex_translate_api_key

Further reading