Skip to main content

Secret scanning patterns

Lists of supported secrets and the partners that GitHub works with to prevent fraudulent use of secrets that were committed accidentally.

Secret scanning alerts for partners run automatically on public repositories in all products on Secret scanning alerts for users are available for public repositories, as well as repositories owned by organizations that use GitHub Enterprise Cloud and have a license for GitHub Advanced Security. For more information, see "About secret scanning alerts for users" and "About GitHub Advanced Security."

About secret scanning patterns

GitHub maintains these different sets of secret scanning patterns:

  1. Partner patterns. Used to detect potential secrets in all public repositories. For details, see "Supported secrets for partner alerts."
  2. User alert patterns. Used to detect potential secrets in public repositories with secret scanning alerts for users enabled. For details, see "Supported secrets for user alerts."

Owners of public repositories, as well as organizations using GitHub Enterprise Cloud with GitHub Advanced Security, can enable secret scanning alerts for users on their repositories. For details of these patterns, see the "Supported secrets for user alerts section below.

Supported secrets for partner alerts

GitHub currently scans public repositories for secrets issued by the following service providers and alerts the relevant service provider whenever a secret is detected in a commit. For more information about secret scanning alerts for partners, see "About secret scanning alerts for partners."

If access to a resource requires paired credentials, then secret scanning will create an alert only when both parts of the pair are detected in the same file. This ensures that the most critical leaks are not hidden behind information about partial leaks.

PartnerSupported secret
Adafruit IOAdafruit IO Key
AdobeAdobe Device Token
AdobeAdobe Service Token
AdobeAdobe Short-Lived Access Token
AdobeAdobe JSON Web Token
Alibaba CloudAlibaba Cloud Access Key ID and Access Key Secret pair
Amazon Web Services (AWS)Amazon AWS Access Key ID and Secret Access Key pair
AtlassianAtlassian API Token
AtlassianAtlassian JSON Web Token
AzureAzure Active Directory Application Secret
AzureAzure Batch Key Identifiable
AzureAzure CosmosDB Key Identifiable
AzureAzure DevOps Personal Access Token
AzureAzure ML Studio (classic) Web Service Key
AzureAzure SAS Token
AzureAzure Search Admin Key
AzureAzure Search Query Key
AzureAzure Service Management Certificate
AzureAzure SQL Connection String
AzureAzure Storage Account Key Production Secret Key Test Secret Key
Chief ToolsChief Tools Token
ClojarsClojars Deploy Token
CloudBees CodeShipCloudBees CodeShip Credential
Contributed SystemsContributed Systems Credentials API Token
DatabricksDatabricks Access Token
DatadogDatadog API Key
DevCycleDevCycle Client API Key
DevCycleDevCycle Server API Key
DigitalOceanDigitalOcean Personal Access Token
DigitalOceanDigitalOcean OAuth Token
DigitalOceanDigitalOcean Refresh Token
DigitalOceanDigitalOcean System Token
DiscordDiscord Bot Token
DopplerDoppler Personal Token
DopplerDoppler Service Token
DopplerDoppler CLI Token
DopplerDoppler SCIM Token
DopplerDoppler Audit Token
DropboxDropbox Access Token
DropboxDropbox Short Lived Access Token
DynatraceDynatrace Access Token
DynatraceDynatrace Internal Token
FigmaFigma Personal Access Token
FinicityFinicity App Key JSON Web Token Developer Token
FullStoryFullStory API Key
GitHubGitHub Personal Access Token
GitHubGitHub OAuth Access Token
GitHubGitHub Refresh Token
GitHubGitHub App Installation Access Token
GitHubGitHub SSH Private Key
GoCardlessGoCardless Live Access Token
GoCardlessGoCardless Sandbox Access Token
Google CloudGoogle API Key
Google CloudGoogle Cloud Private Key ID
Hashicorp TerraformTerraform Cloud / Enterprise API Token
HubspotHubspot API Key
HubspotHubspot API Personal Access Key
IonicIonic Personal Access Token
IonicIonic Refresh Token
JD CloudJD Cloud Access Key
LinearLinear API Key
LinearLinear OAuth Access Token
LocalStackLocalStack API Key
MailchimpMailchimp API Key
MailchimpMandrill API Key
MailgunMailgun API Key
MessageBirdMessageBird API Key
MetaFacebook Access Token
npmnpm Access Token
NuGetNuGet API Key
Octopus DeployOctopus Deploy API Key
OpenAIOpenAI API Key
PalantirPalantir JSON Web Token
PlanetScalePlanetScale Database Password
PlanetScalePlanetScale OAuth Token
PlanetScalePlanetScale Service Token
PlivoPlivo Auth ID and Token
PostmanPostman API Key
PrefectPrefect Server API Key
PrefectPrefect User API Token
ProctorioProctorio Consumer Key
ProctorioProctorio Linkage Key
ProctorioProctorio Registration Key
ProctorioProctorio Secret Key
PulumiPulumi Access Token
ReadMeReadMe API Access Key API Token
RubyGemsRubyGems API Key
SamsaraSamsara API Token
SamsaraSamsara OAuth Access Token
SegmentSegment Public API Token
SendGridSendGrid API Key
SendinblueSendinblue API Key
SendinblueSendinblue SMTP Key
ShopifyShopify App Shared Secret
ShopifyShopify Access Token
ShopifyShopify Custom App Access Token
ShopifyShopify Private App Password
SlackSlack API Token
SlackSlack Incoming Webhook URL
SlackSlack Workflow Webhook URL
SSLMateSSLMate Cluster Secret
StripeStripe Live API Secret Key
StripeStripe Test API Secret Key
StripeStripe Live API Restricted Key
StripeStripe Test API Restricted Key
SupabaseSupabase Service Key
TelnyxTelnyx API V2 Key
Tencent CloudTencent Cloud Secret ID
Tencent WeChatTencent WeChat API App ID
TwilioTwilio Account String Identifier
TwilioTwilio API Key
TypeformTypeform Personal Access Token
UniwiseWISEflow API Key
ValourValour Access Token
YandexYandex.Cloud API Key
YandexYandex.Cloud IAM Cookie
YandexYandex.Cloud IAM Token
YandexYandex.Dictionary API Key
YandexYandex.Cloud Access Secret
YandexYandex.Passport OAuth Token
ZuploZuplo Consumer API

Supported secrets for user alerts

Note: The secret scanning alerts for users feature is available as a beta for users on GitHub Free, GitHub Pro, or GitHub Team plans and is subject to change.

When secret scanning alerts for users are enabled, GitHub scans repositories for secrets issued by the following service providers and generates secret scanning alerts. You can see these alerts on the Security tab of the repository. For more information about secret scanning alerts for users, see "About secret scanning alerts for users."

If access to a resource requires paired credentials, then secret scanning will create an alert only when both parts of the pair are detected in the same file. This ensures that the most critical leaks are not hidden behind information about partial leaks.

If you use the REST API for secret scanning, you can use the Secret type to report on secrets from specific issuers. For more information, see "Secret scanning."

ProviderSupported secretSecret type
Adafruit IOAdafruit IO Keyadafruit_io_key
AdobeAdobe Device Tokenadobe_device_token
AdobeAdobe Service Tokenadobe_service_token
AdobeAdobe Short-Lived Access Tokenadobe_short_lived_access_token
AdobeAdobe JSON Web Tokenadobe_jwt
Alibaba CloudAlibaba Cloud Access Key ID with Alibaba Cloud Access Key Secretalibaba_cloud_access_key_id
AmazonAmazon OAuth Client ID with Amazon OAuth Client Secretamazon_oauth_client_id
Amazon Web Services (AWS)Amazon AWS Access Key ID with Amazon AWS Secret Access Keyaws_access_key_id
Amazon Web Services (AWS)Amazon AWS Session Token with Amazon AWS Temporary Access Key ID and Amazon AWS Secret Access Keyaws_session_token
AsanaAsana Personal Access Tokenasana_personal_access_token
AtlassianAtlassian API Tokenatlassian_api_token
AtlassianAtlassian JSON Web Tokenatlassian_jwt
AtlassianBitbucket Server Personal Access Tokenbitbucket_server_personal_access_token
AzureAzure Active Directory Application Secretazure_active_directory_application_secret
AzureAzure Batch Key Identifiableazure_batch_key_identifiable
AzureAzure Cache for Redis Access Keyazure_cache_for_redis_access_key
AzureAzure CosmosDB Key Identifiableazure_cosmosdb_key_identifiable
AzureAzure DevOps Personal Access Tokenazure_devops_personal_access_token
AzureAzure ML Studio (classic) Web Service Keyazure_ml_studio_classic_web_service_key, azure_ml_web_service_classic_identifiable_key
AzureAzure SAS Tokenazure_sas_token
AzureAzure Search Admin Keyazure_search_admin_key
AzureAzure Search Query Keyazure_search_query_key
AzureAzure Service Management Certificateazure_management_certificate
AzureAzure Storage Account Keyazure_storage_account_key
BeamerBeamer API Keybeamer_api_key Production Secret Keycheckout_production_secret_key Test Secret Keycheckout_test_secret_key
Chief ToolsChief Tools Tokenchief_tools_token
ClojarsClojars Deploy Tokenclojars_deploy_token
CloudBees CodeShipCloudBees CodeShip Credentialcodeship_credential
ContentfulContentful Personal Access Tokencontentful_personal_access_token
DatabricksDatabricks Access Tokendatabricks_access_token
DevCycleDevCycle Client API Keydevcycle_client_api_key
DevCycleDevCycle Server API Keydevcycle_server_api_key
DevCycleDevCycle Mobile API Keydevcycle_mobile_api_key
DigitalOceanDigitalOcean Personal Access Tokendigitalocean_personal_access_token
DigitalOceanDigitalOcean OAuth Tokendigitalocean_oauth_token
DigitalOceanDigitalOcean Refresh Tokendigitalocean_refresh_token
DigitalOceanDigitalOcean System Tokendigitalocean_system_token
DiscordDiscord Bot Tokendiscord_bot_token
DiscordDiscord API Token V2discord_api_token_v2
DopplerDoppler Personal Tokendoppler_personal_token
DopplerDoppler Service Tokendoppler_service_token
DopplerDoppler CLI Tokendoppler_cli_token
DopplerDoppler SCIM Tokendoppler_scim_token
DopplerDoppler Audit Tokendoppler_audit_token
DropboxDropbox Access Tokendropbox_access_token
DropboxDropbox Short Lived Access Tokendropbox_short_lived_access_token
DuffelDuffel Live Access Tokenduffel_live_access_token
DuffelDuffel Test Access Tokenduffel_test_access_token
DynatraceDynatrace Access Tokendynatrace_access_token
DynatraceDynatrace Internal Tokendynatrace_internal_token
EasyPostEasyPost Production API Keyeasypost_production_api_key
EasyPostEasyPost Test API Keyeasypost_test_api_key
eBayeBay Production Client ID (App ID) with eBay Production Client Secret (Cert ID)ebay_production_client_id
eBayeBay Sandbox Client ID (App ID) with eBay Sandbox Client Secret (Cert ID)ebay_sandbox_client_id
FastlyFastly API Tokenfastly_api_token
FigmaFigma Personal Access Tokenfigma_pat
FinicityFinicity App Keyfinicity_app_key
FlutterwaveFlutterwave Live API Secret Keyflutterwave_live_api_secret_key
FlutterwaveFlutterwave Test API Secret Keyflutterwave_test_api_secret_key JSON Web Tokenframeio_jwt Developer Tokenframeio_developer_token
FullStoryFullStory API Keyfullstory_api_key
GitHubGitHub Personal Access Tokengithub_personal_access_token
GitHubGitHub OAuth Access Tokengithub_oauth_access_token
GitHubGitHub Refresh Tokengithub_refresh_token
GitHubGitHub App Installation Access Tokengithub_app_installation_access_token
GitHubGitHub SSH Private Keygithub_ssh_private_key
GitLabGitLab Access Tokengitlab_access_token
GoCardlessGoCardless Live Access Tokengocardless_live_access_token
GoCardlessGoCardless Sandbox Access Tokengocardless_sandbox_access_token
GoogleFirebase Cloud Messaging Server Keyfirebase_cloud_messaging_server_key
GoogleGoogle API Keygoogle_api_key
GoogleGoogle Cloud Private Key IDgoogle_cloud_private_key_id
GoogleGoogle Cloud Storage Service Account Access Key ID with Google Cloud Storage Access Key Secretgoogle_cloud_storage_service_account_access_key_id
GoogleGoogle Cloud Storage User Access Key ID with Google Cloud Storage Access Key Secretgoogle_cloud_storage_user_access_key_id
GoogleGoogle OAuth Access Tokengoogle_oauth_access_token
GoogleGoogle OAuth Client ID with Google OAuth Client Secretgoogle_oauth_client_id
GoogleGoogle OAuth Refresh Tokengoogle_oauth_refresh_token
GrafanaGrafana API Keygrafana_api_key
GrafanaGrafana Cloud API Keygrafana_cloud_api_key
GrafanaGrafana Cloud API Tokengrafana_cloud_api_token
GrafanaGrafana Project API Keygrafana_project_api_key
GrafanaGrafana Project Service Account Tokengrafana_project_service_account_token
HashiCorpTerraform Cloud / Enterprise API Tokenterraform_api_token
HashiCorpHashiCorp Vault Batch Tokenhashicorp_vault_batch_token
HashiCorpHashiCorp Vault Root Service Tokenhashicorp_vault_root_service_token
HashiCorpHashiCorp Vault Service Tokenhashicorp_vault_service_token
HubspotHubspot API Keyhubspot_api_key
HubspotHubspot API Personal Access Keyhubspot_api_personal_access_key
IntercomIntercom Access Tokenintercom_access_token
IonicIonic Personal Access Tokenionic_personal_access_token
IonicIonic Refresh Tokenionic_refresh_token
JD CloudJD Cloud Access Keyjd_cloud_access_key
JFrogJFrog Platform Access Tokenjfrog_platform_access_token
JFrogJFrog Platform API Keyjfrog_platform_api_key
LinearLinear API Keylinear_api_key
LinearLinear OAuth Access Tokenlinear_oauth_access_token
LobLob Live API Keylob_live_api_key
LobLob Test API Keylob_test_api_key
LocalStackLocalStack API Keylocalstack_api_key
LogicMonitorLogicMonitor Bearer Tokenlogicmonitor_bearer_token
LogicMonitorLogicMonitor LMV1 Access Keylogicmonitor_lmv1_access_key
MailchimpMailchimp API Keymailchimp_api_key
MailgunMailgun API Keymailgun_api_key
MapboxMapbox Secret Access Tokenmapbox_secret_access_token
MessageBirdMessageBird API Keymessagebird_api_key
MetaFacebook Access Tokenfacebook_access_token
MidtransMidtrans Production Server Keymidtrans_production_server_key
MidtransMidtrans Sandbox Server Keymidtrans_sandbox_server_key
New RelicNew Relic Personal API Keynew_relic_personal_api_key
New RelicNew Relic REST API Keynew_relic_rest_api_key
New RelicNew Relic Insights Query Keynew_relic_insights_query_key
New RelicNew Relic License Keynew_relic_license_key
NotionNotion Integration Tokennotion_integration_token
NotionNotion OAuth Client Secretnotion_oauth_client_secret
npmnpm Access Tokennpm_access_token
NuGetNuGet API Keynuget_api_key
Octopus DeployOctopus Deploy API Keyoctopus_deploy_api_key
OnfidoOnfido Live API Tokenonfido_live_api_token
OnfidoOnfido Sandbox API Tokenonfido_sandbox_api_token
OpenAIOpenAI API Keyopenai_api_key
PalantirPalantir JSON Web Tokenpalantir_jwt
PersonaPersona Production API Keypersona_production_api_key
PersonaPersona Sandbox API Keypersona_sandbox_api_key
PlanetScalePlanetScale Database Passwordplanetscale_database_password
PlanetScalePlanetScale OAuth Tokenplanetscale_oauth_token
PlanetScalePlanetScale Service Tokenplanetscale_service_token
PlivoPlivo Auth ID with Plivo Auth Tokenplivo_auth_id
PostmanPostman API Keypostman_api_key
PostmanPostman Collection Keypostman_collection_key
PrefectPrefect Server API Keyprefect_server_api_key
PrefectPrefect User API Keyprefect_user_api_key
ProctorioProctorio Consumer Keyproctorio_consumer_key
ProctorioProctorio Linkage Keyproctorio_linkage_key
ProctorioProctorio Registration Keyproctorio_registration_key
ProctorioProctorio Secret Keyproctorio_secret_key
PulumiPulumi Access Tokenpulumi_access_token
PyPIPyPI API Tokenpypi_api_token
ReadMeReadMe API Access Keyreadmeio_api_access_token API Tokenredirect_pizza_api_token
RubyGemsRubyGems API Keyrubygems_api_key
SamsaraSamsara API Tokensamsara_api_token
SamsaraSamsara OAuth Access Tokensamsara_oauth_access_token
SegmentSegment Public API Tokensegment_public_api_token
SendGridSendGrid API Keysendgrid_api_key
SendinblueSendinblue API Keysendinblue_api_key
SendinblueSendinblue SMTP Keysendinblue_smtp_key
ShippoShippo Live API Tokenshippo_live_api_token
ShippoShippo Test API Tokenshippo_test_api_token
ShopifyShopify App Client Credentialsshopify_app_client_credentials
ShopifyShopify App Client Secretshopify_app_client_secret
ShopifyShopify App Shared Secretshopify_app_shared_secret
ShopifyShopify Access Tokenshopify_access_token
ShopifyShopify Custom App Access Tokenshopify_custom_app_access_token
ShopifyShopify Merchant Tokenshopify_merchant_token
ShopifyShopify Marketplace Tokenshopify_marketplace_token
ShopifyShopify Partner API Tokenshopify_partner_api_token
ShopifyShopify Private App Passwordshopify_private_app_password
SlackSlack API Tokenslack_api_token
SlackSlack Incoming Webhook URLslack_incoming_webhook_url
SlackSlack Workflow Webhook URLslack_workflow_webhook_url
SquareSquare Access Tokensquare_access_token
SquareSquare Production Application Secretsquare_production_application_secret
SquareSquare Sandbox Application Secretsquare_sandbox_application_secret
SSLMateSSLMate API Keysslmate_api_key
SSLMateSSLMate Cluster Secretsslmate_cluster_secret
StripeStripe API Keystripe_api_key
StripeStripe Live API Secret Keystripe_live_secret_key
StripeStripe Test API Secret Keystripe_test_secret_key
StripeStripe Live API Restricted Keystripe_live_restricted_key
StripeStripe Test API Restricted Keystripe_test_restricted_key
StripeStripe Webhook Signing Secretstripe_webhook_signing_secret
SupabaseSupabase Service Keysupabase_service_key
TableauTableau Personal Access Tokentableau_personal_access_token
TelegramTelegram Bot Tokentelegram_bot_token
TelnyxTelnyx API V2 Keytelnyx_api_v2_key
Tencent CloudTencent Cloud Secret IDtencent_cloud_secret_id
Tencent WeChatTencent WeChat API App IDtencent_wechat_api_app_id
TwilioTwilio Access Tokentwilio_access_token
TwilioTwilio Account String Identifiertwilio_account_sid
TwilioTwilio API Keytwilio_api_key
TypeformTypeform Personal Access Tokentypeform_personal_access_token
UniwiseWISEflow API Keywiseflow_api_key
WakaTimeWakaTime App Secretwakatime_pp_secret
WakaTimeWakaTime OAuth Access Tokenwakatime_oauth_access_token
WakaTimeWakaTime OAuth Refresh Tokenwakatime_oauth_refresh_token
WorkOSWorkOS Production API Keyworkos_production_api_key
WorkOSWorkOS Staging API Keyworkos_staging_api_key
YandexYandex.Cloud API Keyyandex_cloud_api_key
YandexYandex.Cloud IAM Cookieyandex_cloud_iam_cookie
YandexYandex.Cloud IAM Tokenyandex_cloud_iam_token
YandexYandex.Dictionary API Keyyandex_dictionary_api_key
YandexYandex.Cloud Access Secretyandex_iam_access_secret
YandexYandex.Predictor API Keyyandex_predictor_api_key
YandexYandex.Translate API Keyyandex_translate_api_key
ZuploZuplo Consumer API Keyzuplo_consumer_api_key

Further reading