Skip to main content

This version of GitHub Enterprise Server was discontinued on 2026-04-23. No patch releases will be made, even for critical security issues. For better performance, improved security, and new features, upgrade to the latest version of GitHub Enterprise Server. For help with the upgrade, contact GitHub Enterprise support.

Supported secret scanning patterns

Lists of supported secrets and the partners that GitHub works with to prevent fraudulent use of secrets that were committed accidentally.

Who can use this feature?

Secret scanning is available for the following repository types:

  • Public repositories: Secret scanning runs automatically for free.
  • Organization-owned private and internal repositories: Available with GitHub Advanced Security enabled on GitHub Team or GitHub Enterprise Cloud.
  • User-owned repositories: Available on GitHub Enterprise Cloud with Enterprise Managed Users. Available on GitHub Enterprise Server when the enterprise has GitHub Advanced Security enabled.

About secret scanning patterns

There are two types of secret scanning alerts:

  • Secret scanning alerts: Reported to users in the Security tab of the repository, when a supported secret is detected in the repository.
  • Push protection alerts: Reported to users in the Security tab of the repository, when a contributor bypasses push protection.

For in-depth information about each alert type, see About secret scanning alerts.

For details about all the supported patterns, see the Supported secrets section below.

If you use the REST API for secret scanning, you can use the Secret type to report on secrets from specific issuers. For more information, see REST API endpoints for secret scanning.

If you believe that secret scanning should have detected a secret committed to your repository, and it has not, you first need to check that GitHub supports your secret. For more information, refer to the following sections. For more advanced troubleshooting information, see Secret scanning detection scope.

Supported secrets

The tables list the secrets supported by secret scanning for each secret type. Information in the tables may include this data:

  • Provider: Name of the token provider.
  • Secret scanning alert: Token for which leaks are reported to users on GitHub.
    • Applies to private repositories where GitHub Advanced Security and secret scanning are enabled.
    • Includes high confidence tokens, which relate to supported patterns and specified custom patterns, as well as non-provider tokens such as private keys, which often result in false positives.
  • Push protection: Token for which leaks are reported to users on GitHub. Applies to repositories with secret scanning and push protection enabled.
  • Validity check: Token for which a validity check is implemented. Currently only applies to GitHub tokens.
  • Metadata check: Token for which extended metadata is available, providing additional context about the detected secret.
  • Base64: Token for which Base64-encoded versions are supported.

Non-provider patterns

Note

The detection of non-provider patterns is currently in beta and subject to change.

Precision levels are estimated based on the pattern type's typical false positive rates.

ProviderTokenDescriptionPrecision
Generichttp_basic_authentication_headerHTTP Basic Authentication credentials in request headersMedium
Generichttp_bearer_authentication_headerHTTP Bearer tokens used for API authenticationMedium
Genericmongodb_connection_stringConnection strings for MongoDB databases containing credentialsHigh
Genericmysql_connection_urlConnection strings for MySQL databases containing credentialsHigh
Genericopenssh_private_keyOpenSSH format private keys used for SSH authenticationHigh
Genericpgp_private_keyPGP (Pretty Good Privacy) private keys used for encryption and signingHigh
Genericpostgres_connection_stringConnection strings for PostgreSQL databases containing credentialsHigh
Genericrsa_private_keyRSA private keys used for cryptographic operationsHigh

Note

Validity checks are not supported for non-provider patterns.

High confidence patterns

ProviderTokenSecret scanning alertPush protectionValidity checkBase64
Adafruitadafruit_io_key✓✓✗✗
Adobeadobe_client_secret✓✓✗✗
Adobeadobe_device_token✓✓✗✗
Adobeadobe_pac_token✓✓✗✗
Adobeadobe_refresh_token✓✓✗✗
Adobeadobe_service_token✓✓✗✗
Adobeadobe_short_lived_access_token✓✓✗✗
Aivenaiven_auth_token✓✓✗✗
Aivenaiven_service_password✓✓✗✗
Alibabaalibaba_cloud_access_key_id
alibaba_cloud_access_key_secret
✓✓✗✗
Amazon AWSaws_access_key_id
aws_secret_access_key
✓✓✗✗
Amazon AWSaws_secret_access_key
aws_session_token
aws_temporary_access_key_id
✓✓✗✗
Anthropicanthropic_api_key✓✓✗✗
Anthropicanthropic_session_id✓✓✗✗
Asanaasana_legacy_format_personal_access_token✓✗✗✗
Asanaasana_personal_access_token✓✓✗✗
Atlassianatlassian_api_token
Token versions
✓✓✗✗
Atlassianatlassian_jwt✓✗✗✗
Authressauthress_service_client_access_key✓✓✗✗
Azureazure_active_directory_application_secret
Token versions
✓✓✗✗
Azureazure_active_directory_user_credential✓✗✗✗
Azureazure_apim_direct_management_key✓✓✗✗
Azureazure_apim_gateway_key✓✓✗✗
Azureazure_apim_repository_key✓✓✗✗
Azureazure_apim_subscription_key✓✓✗✗
Azureazure_app_configuration_connection_string✓✗✗✗
Azureazure_batch_key_identifiable✓✓✗✗
Azureazure_cache_for_redis_access_key✓✓✗✗
Azureazure_communication_services_connection_string✓✗✗✗
Azureazure_container_registry_key_identifiable✓✓✗✗
Azureazure_cosmosdb_key_identifiable✓✓✗✗
Azureazure_devops_personal_access_token✓✓✗✗
Azureazure_event_hub_key_identifiable✓✓✗✗
Azureazure_function_key✓✓✗✗
Azureazure_iot_device_connection_string✓✗✗✗
Azureazure_iot_device_key✓✓✗✗
Azureazure_iot_device_provisioning_key✓✓✗✗
Azureazure_iot_hub_connection_string✓✗✗✗
Azureazure_iot_hub_key✓✓✗✗
Azureazure_iot_provisioning_connection_string✓✗✗✗
Azureazure_management_certificate✓✗✗✗
Azureazure_ml_web_service_classic_identifiable_key✓✓✗✗
Azureazure_relay_key_identifiable✓✓✗✗
Azureazure_sas_token✓✗✗✗
Azureazure_search_admin_key✓✓✗✗
Azureazure_search_query_key✓✓✗✗
Azureazure_service_bus_identifiable✓✓✗✗
Azureazure_signalr_connection_string✓✗✗✗
Azureazure_sql_connection_string✓✗✗✗
Azureazure_sql_password✓✓✗✗
Azureazure_storage_account_key
Token versions
✓✓✗✗
Azureazure_web_pub_sub_connection_string✓✗✗✗
Azuremicrosoft_corporate_network_user_credential✓✗✗✗
Baidubaiducloud_api_accesskey✓✓✗✗
Beamerbeamer_api_key✓✗✗✗
Bitbucketbitbucket_server_personal_access_token✓✓✗✗
Canadian Digital Servicecds_canada_notify_api_key✓✓✗✗
Canvacanva_app_secret✓✓✗✗
Canvacanva_connect_api_secret✓✓✗✗
Canvacanva_secret✓✓✗✗
Cashfreecashfree_api_key✓✓✗✗
Checkout.comcheckout_production_secret_key
Token versions
✓✓✗✗
Checkout.comcheckout_test_secret_key
Token versions
✓✗✗✗
Chief Toolschief_tools_token✓✓✗✗
CircleCIcircleci_bot_access_token✓✓✗✗
CircleCIcircleci_personal_access_token✓✓✗✗
CircleCIcircleci_project_access_token✓✓✗✗
CircleCIcircleci_release_integration_token✓✓✗✗
Clojarsclojars_deploy_token✓✓✗✗
CloudBeescodeship_credential✗✗✗✗
Contentfulcontentful_personal_access_token✓✗✗✗
Contributed Systemscontributed_systems_credentials✗✗✗✗
crates.iocratesio_api_token✓✓✗✗
Databricksdatabricks_access_token✓✓✗✗
Datadogdatadog_api_key✗✗✗✗
Datadogdatadog_app_key✗✗✗✗
Defined Networkingdefined_networking_nebula_api_key✓✓✗✗
DevCycledevcycle_client_api_key✓✓✗✗
DevCycledevcycle_mobile_api_key✓✓✗✗
DevCycledevcycle_server_api_key✓✓✗✗
DigitalOceandigitalocean_oauth_token✓✓✗✗
DigitalOceandigitalocean_personal_access_token✓✓✗✗
DigitalOceandigitalocean_refresh_token✓✓✗✗
DigitalOceandigitalocean_system_token✓✓✗✗
Discorddiscord_bot_token
Token versions
✓✓✗✗
Dockerdocker_personal_access_token✓✓✗✗
Dopplerdoppler_audit_token✓✓✗✗
Dopplerdoppler_cli_token✓✓✗✗
Dopplerdoppler_personal_token✓✓✗✗
Dopplerdoppler_scim_token✓✓✗✗
Dopplerdoppler_service_account_token✓✓✗✗
Dopplerdoppler_service_token✓✓✗✗
Dropboxdropbox_access_token✓✗✗✗
Dropboxdropbox_short_lived_access_token✓✓✗✗
Duffelduffel_live_access_token✓✓✗✗
Duffelduffel_test_access_token✓✗✗✗
Dynatracedynatrace_api_token✓✗✗✗
Dynatracedynatrace_internal_token✓✗✗✗
EasyPosteasypost_production_api_key✓✓✗✗
EasyPosteasypost_test_api_key✓✗✗✗
eBayebay_production_client_id
ebay_production_client_secret
✓✗✗✗
eBayebay_sandbox_client_id
ebay_sandbox_client_secret
✓✗✗✗
Facebookfacebook_access_token✓✗✗✗
Fastlyfastly_api_token
Token versions
✓✗✗✗
Figmafigma_pat✓✓✗✗
Finicityfinicity_app_key✓✗✗✗
Firebasefirebase_cloud_messaging_server_key✓✗✗✗
Flutterwaveflutterwave_live_api_secret_key✓✓✗✗
Flutterwaveflutterwave_test_api_secret_key✓✗✗✗
Frame.ioframeio_developer_token✓✗✗✗
Frame.ioframeio_jwt✓✗✗✗
FullStoryfullstory_api_key
Token versions
✓✓✗✗
GitHubgithub_app_installation_access_token
Token versions
✓✓✓✗
GitHubgithub_oauth_access_token
Token versions
✓✓✓✗
GitHubgithub_personal_access_token
Token versions
✓✓✓✗
GitHubgithub_refresh_token✓✓✓✗
GitHubgithub_ssh_private_key✓✓✓✗
GitHubgithub_test_token✓✗✗✗
GitHub Secret Scanningsecret_scanning_sample_token✓✓✗✗
GitLabgitlab_access_token✓✗✗✗
GoCardlessgocardless_live_access_token✓✗✗✗
GoCardlessgocardless_sandbox_access_token✓✗✗✗
Googlegoogle_api_key✓✗✗✗
Googlegoogle_cloud_private_key_id✗✗✗✗
Googlegoogle_cloud_service_account_credentials✓✓✗✗
Googlegoogle_cloud_storage_access_key_secret
google_cloud_storage_service_account_access_key_id
✓✓✗✗
Googlegoogle_cloud_storage_access_key_secret
google_cloud_storage_user_access_key_id
✓✓✗✗
Googlegoogle_oauth_access_token✓✗✗✗
Googlegoogle_oauth_client_id
google_oauth_client_secret
✓✓✗✗
Googlegoogle_oauth_refresh_token✓✗✗✗
Grafanagrafana_cloud_api_key✓✓✗✗
Grafanagrafana_cloud_api_token✓✓✗✗
Grafanagrafana_project_api_key✓✓✗✗
Grafanagrafana_project_service_account_token✓✓✗✗
HashiCorphashicorp_vault_batch_token
Token versions
✓✓✗✗
HashiCorphashicorp_vault_root_service_token✓✓✗✗
HashiCorphashicorp_vault_service_token
Token versions
✓✓✗✗
HashiCorpterraform_api_token✓✓✗✗
Highnotehighnote_rk_live_key✓✓✗✗
Highnotehighnote_rk_test_key✓✓✗✗
Highnotehighnote_sk_live_key✓✓✗✗
Highnotehighnote_sk_test_key✓✓✗✗
HOPhop_bearer✓✓✗✗
HOPhop_pat✓✓✗✗
HOPhop_ptk✓✓✗✗
Hubspothubspot_api_key
Token versions
✓✓✗✗
Hubspothubspot_personal_access_key✓✓✗✗
Hubspothubspot_smtp_credential✗✗✗✗
IBMibm_cloud_iam_key✓✗✗✗
IBMibm_softlayer_api_key✓✗✗✗
Intercomintercom_access_token✓✓✗✗
Ionicionic_personal_access_token
Token versions
✓✓✗✗
Ionicionic_refresh_token
Token versions
✓✓✗✗
JFrogjfrog_platform_access_token✓✓✗✗
JFrogjfrog_platform_api_key✓✓✗✗
JFrogjfrog_platform_reference_token✓✓✗✗
LaunchDarklylaunchdarkly_access_token✗✗✗✗
Lightspeedlightspeed_xs_pat✓✓✗✗
Linearlinear_api_key✓✓✗✗
Linearlinear_oauth_access_token✓✓✗✗
Loblob_live_api_key✓✗✗✗
Loblob_test_api_key✓✗✗✗
Localstacklocalstack_api_key✓✓✗✗
LogicMonitorlogicmonitor_bearer_token✓✓✗✗
LogicMonitorlogicmonitor_lmv1_access_key✓✓✗✗
Login with Amazonamazon_oauth_client_id
amazon_oauth_client_secret
amazon_oauth_client_secret
✓✓✗✗
Mailchimpmailchimp_api_key✓✗✗✗
Mailchimpmandrill_api_key✗✗✗✗
Mailgunmailgun_api_key
Token versions
✓✗✗✗
Mailgunmailgun_smtp_credential✗✗✗✗
Mapboxmapbox_secret_access_token✓✗✗✗
MaxMindmaxmind_license_key✓✓✗✗
Mercurymercury_non_production_api_token✓✓✗✗
Mercurymercury_production_api_token✓✓✗✗
Mergifymergify_application_key✓✓✗✗
MessageBirdmessagebird_api_key✓✗✗✗
Midtransmidtrans_production_server_key✓✓✗✗
Midtransmidtrans_sandbox_server_key✓✗✗✗
New Relicnew_relic_insights_query_key✓✓✗✗
New Relicnew_relic_license_key✓✗✗✗
New Relicnew_relic_personal_api_key✓✓✗✗
New Relicnew_relic_rest_api_key✓✓✗✗
Notionnotion_integration_token✓✗✗✗
Notionnotion_oauth_client_secret✓✗✗✗
npmnpm_access_token
Token versions
✓✓✗✗
NuGetnuget_api_key✓✓✗✗
Octopus Deployoctopus_deploy_api_key✓✗✗✗
Oculusoculus_access_token✓✗✗✗
OneChronosonechronos_api_key✓✓✗✗
OneChronosonechronos_eb_api_key✓✓✗✗
OneChronosonechronos_eb_encryption_key✓✓✗✗
OneChronosonechronos_oauth_token✓✓✗✗
OneChronosonechronos_refresh_token✓✓✗✗
Onfidoonfido_live_api_token✓✓✗✗
Onfidoonfido_sandbox_api_token✓✗✗✗
OpenAIopenai_api_key
Token versions
✓✓✗✗
Orbitorbit_api_token✓✗✗✗
PagerDutypagerduty_oauth_secret✓✓✗✗
PagerDutypagerduty_oauth_token✓✓✗✗
Palantirpalantir_jwt✓✓✗✗
Persona Identitiespersona_production_api_key✓✓✗✗
Persona Identitiespersona_sandbox_api_key✓✓✗✗
Pinterestpinterest_access_token✓✓✗✗
Pinterestpinterest_refresh_token✓✓✗✗
PlanetScaleplanetscale_database_password✓✓✗✗
PlanetScaleplanetscale_oauth_token✓✓✗✗
PlanetScaleplanetscale_service_token✓✓✗✗
Plivoplivo_auth_id
plivo_auth_token
✓✓✗✗
Postmanpostman_api_key✓✓✗✗
Postmanpostman_collection_key✓✓✗✗
Prefectprefect_server_api_key✓✓✗✗
Prefectprefect_user_api_key✓✓✗✗
Proctorioproctorio_consumer_key✓✗✗✗
Proctorioproctorio_linkage_key✓✗✗✗
Proctorioproctorio_registration_key✓✗✗✗
Proctorioproctorio_secret_key
Token versions
✓✓✗✗
Pulumipulumi_access_token✓✗✗✗
PyPIpypi_api_token✓✗✗✗
ReadMereadmeio_api_access_token✓✓✗✗
redirect.pizzaredirect_pizza_api_token✓✓✗✗
Replicatereplicate_api_token✗✗✗✗
Rootlyrootly_api_key✓✓✗✗
RubyGemsrubygems_api_key✓✗✗✗
Samsarasamsara_api_token✓✓✗✗
Samsarasamsara_oauth_access_token✓✓✗✗
Segmentsegment_public_api_token✓✓✗✗
SendGridsendgrid_api_key✓✓✗✗
Sendinbluesendinblue_api_key✓✓✗✗
Sendinbluesendinblue_smtp_key✓✓✗✗
Shipposhippo_live_api_token✓✓✗✗
Shipposhippo_test_api_token✓✗✗✗
Shopifyshopify_access_token✓✓✗✗
Shopifyshopify_app_client_credentials✓✗✗✗
Shopifyshopify_app_client_secret✓✗✗✗
Shopifyshopify_app_shared_secret✓✓✗✗
Shopifyshopify_custom_app_access_token✓✗✗✗
Shopifyshopify_marketplace_token✓✗✗✗
Shopifyshopify_merchant_token✓✗✗✗
Shopifyshopify_partner_api_token✓✗✗✗
Shopifyshopify_private_app_password✓✗✗✗
Slackslack_api_token
Token versions
✓✓✗✗
Slackslack_incoming_webhook_url✓✗✗✗
Slackslack_workflow_webhook_url✓✗✗✗
Squaresquare_access_token
Token versions
✓✗✗✗
Squaresquare_production_application_secret✓✗✗✗
Squaresquare_sandbox_application_secret✓✗✗✗
SSLMatesslmate_api_key
Token versions
✓✗✗✗
SSLMatesslmate_cluster_secret✓✗✗✗
Stripestripe_api_key✓✓✗✗
Stripestripe_legacy_api_key✓✗✗✗
Stripestripe_live_restricted_key✓✗✗✗
Stripestripe_test_restricted_key✓✗✗✗
Stripestripe_test_secret_key✓✗✗✗
Stripestripe_webhook_signing_secret✓✗✗✗
Supabasesupabase_service_key
Token versions
✓✗✗✗
Tableautableau_personal_access_token✓✗✗✗
Telegramtelegram_bot_token✓✗✗✗
Telnyxtelnyx_api_v2_key✓✓✗✗
Tencenttencent_cloud_secret_id✓✓✗✗
Tencenttencent_wechat_api_app_id✓✗✗✗
Twiliotwilio_access_token✓✓✗✗
Twiliotwilio_account_sid✓✓✗✗
Twiliotwilio_api_key✓✓✗✗
Typeformtypeform_personal_access_token✓✓✗✗
Uniwisewiseflow_api_key✓✓✗✗
Unkeyunkey_root_key✓✗✗✗
VolcEnginevolcengine_access_key_id✓✓✗✗
Wakatimewakatime_api_key✓✓✗✗
Wakatimewakatime_app_secret✓✓✗✗
Wakatimewakatime_oauth_access_token✓✓✗✗
Wakatimewakatime_oauth_refresh_token✓✓✗✗
Workatoworkato_developer_api_token
Token versions
✓✓✗✗
WorkOSworkos_production_api_key
Token versions
✓✓✗✗
WorkOSworkos_staging_api_key
Token versions
✓✗✗✗
Yandexyandex_cloud_api_key✓✗✗✗
Yandexyandex_cloud_iam_access_secret✓✗✗✗
Yandexyandex_cloud_iam_cookie✓✗✗✗
Yandexyandex_cloud_iam_token✓✗✗✗
Yandexyandex_cloud_smartcaptcha_server_key✓✓✗✗
Yandexyandex_dictionary_api_key✓✗✗✗
Yandexyandex_passport_oauth_token✓✓✗✗
Yandexyandex_predictor_api_key✓✗✗✗
Yandexyandex_translate_api_key✓✗✗✗
Zuplozuplo_consumer_api_key✓✓✗✗

Token versions

Service providers update the patterns used to generate tokens periodically and may support more than one version of a token. Push protection only supports the most recent token versions that secret scanning can identify with confidence. This avoids push protection blocking commits unnecessarily when a result may be a false positive, which is more likely to happen with legacy tokens.

Further reading