Detected secrets

  • Tier: Free, Premium, Ultimate
  • Offering: GitLab.com, GitLab Self-Managed, GitLab Dedicated

This table lists the secrets detected by:

  • Pipeline secret detection
  • Client-side secret detection
  • Secret push protection

Secret detection rules are updated in the default ruleset. Detected secrets with patterns that have been removed or updated remain open so you can triage them.

Description ID Pipeline secret detection Client-side secret detection Secret push protection
Adafruit IO Key AdafruitIOKey check-sm No check-sm
Adobe Client ID (OAuth Web) Adobe Client ID (Oauth Web) check-sm No No
Adobe client secret Adobe Client Secret check-sm No check-sm
Age secret key Age secret key check-sm No No
Aiven Service Password AivenServicePassword check-sm No check-sm
Alibaba AccessKey ID Alibaba AccessKey ID check-sm No No
Alibaba Secret Key Alibaba Secret Key check-sm No No
Amazon OAuth Client ID AmazonOAuthClientID check-sm No check-sm
Anthropic API key anthropic_key check-sm check-sm check-sm
Artifactory API Key ArtifactoryApiKey check-sm No check-sm
Artifactory Identity Token ArtifactoryIdentityToken check-sm No check-sm
Asana client ID Asana Client ID check-sm No No
Asana client secret Asana Client Secret check-sm No No
Asana Personal Access Token V1 AsanaPersonalAccessTokenV1 check-sm No check-sm
Asana Personal Access Token V2 AsanaPersonalAccessTokenV2 check-sm No check-sm
Atlassian API Key AtlassianApiKey check-sm No check-sm
Atlassian API token Atlassian API token check-sm No No
Atlassian User API Token AtlassianUserApiToken check-sm No check-sm
Auth0 Client Secret Auth0ClientSecret check-sm No No
AWS Access Key ID AWS check-sm No check-sm
AWS Access Secret Key AWSSecretAccessKey check-sm No No
AWS Session Token AWSSessionToken check-sm No check-sm
AWS Cognito Identity Pool ID AWSCognitoIdentityPoolID check-sm No No
AWS Bedrock Key AWSBedrockKey check-sm No No
AWS Bedrock Short-lived Key AWSBedrockShortLivedKey check-sm No check-sm
Azure API Management Gateway Key AzureAPIManagementGatewayKey check-sm No check-sm
Azure API Management Direct Key AzureAPIManagementDirectKey check-sm No No
Azure App Config AzureAppConfigConnectionString check-sm No check-sm
Azure Communication Services AzureCommServicesConnectionString check-sm No check-sm
Azure Cosmos DB Credentials AzureCosmosDBCredentials check-sm No No
Azure Entra Client Secret AzureEntraClientSecret check-sm No check-sm
Azure Entra Client ID Token AzureEntraIDToken check-sm No check-sm
Azure EventGrid Access Key AzureEventGridAccessKey check-sm No No
Azure Functions API Key AzureFunctionsAPIKey check-sm No check-sm
Azure Logic App SAS AzureLogicAppSAS check-sm No check-sm
Azure OpenAI API Key AzureOpenAIAPIKey check-sm No No
Azure Personal Access Token AzurePersonalAccessToken check-sm No No
Azure SignalR Access Key AzureSignalRAccessKey check-sm No check-sm
Beamer API token Beamer API token check-sm No No
Bitbucket client ID Bitbucket client ID check-sm No No
Bitbucket client secret Bitbucket client secret check-sm No No
Brevo API token Sendinblue API token check-sm No check-sm
Brevo SMTP token Sendinblue SMTP token check-sm No check-sm
Canada Digital Service Notify API Key CDSCanadaNotifyAPIKey check-sm No check-sm
CircleCI access token CircleCI access tokens check-sm No No
CircleCI Personal Access Token CircleCIPersonalAccessToken check-sm No check-sm
Clojars deploy token Clojars API token check-sm No No
Contentful delivery API token Contentful delivery API token check-sm No No
Contentful personal access token ContentfulPersonalAccessToken check-sm No check-sm
Contentful preview API token Contentful preview API token check-sm No No
Databricks API token Databricks API token check-sm No No
DataDog API Key DataDogAPIKey check-sm No No
DigitalOcean OAuth access token digitalocean-access-token check-sm No No
DigitalOcean personal access token digitalocean-pat check-sm No No
DigitalOcean refresh token digitalocean-refresh-token check-sm No No
Discord API key Discord API key check-sm No No
Discord client ID Discord client ID check-sm No No
Discord client secret Discord client secret check-sm No No
Docker Personal Access Token DockerPersonalAccessToken check-sm No check-sm
Doppler API token Doppler API token check-sm No check-sm
Doppler Service token Doppler Service token check-sm No check-sm
Dropbox API secret/key Dropbox API secret/key check-sm No No
Dropbox App Access Token DropboxAppAccessToken check-sm No check-sm
Dropbox long lived API token Dropbox long lived API token check-sm No No
Dropbox short lived API token Dropbox short lived API token check-sm No check-sm
Duffel API token Duffel API token check-sm No No
Dynatrace Platform Token DynatracePlatformToken check-sm No No
EasyPost production API key EasyPost API token check-sm No No
EasyPost test API key EasyPost test API token check-sm No No
Facebook token Facebook token check-sm No No
Fastly API user or automation token Fastly API token check-sm No No
Figma Personal Access Token FigmaPersonalAccessToken check-sm No check-sm
Finicity API token Finicity API token check-sm No No
Finicity client secret Finicity client secret check-sm No No
Flutterwave Prod Encrypted Key FlutterwaveProdEncryptedKey check-sm No check-sm
Flutterwave test encrypted key Flutterwave encrypted key check-sm No No
Flutterwave Prod Public Key FlutterwaveProdPublicKey check-sm No check-sm
Flutterwave test public key Flutterwave public key check-sm No No
Flutterwave Prod Secret Key FlutterwaveProdSecretKey check-sm No check-sm
Flutterwave test secret key Flutterwave secret key check-sm No No
Frame.io API token Frame.io API token check-sm No No
GCP API key GCP API key check-sm No No
GCP OAuth client secret GCP OAuth client secret check-sm No check-sm
GCP Vertex Express Mode Key GCPVertexExpressModeKey check-sm No check-sm
GitHub app token Github App Token check-sm No check-sm
GitHub App Installation Token GithubAppInstallationToken check-sm No check-sm
GitHub Fine Grained Personal Access Token GithubFineGrainedPersonalAccessToken check-sm No check-sm
GitHub OAuth Access Token Github OAuth Access Token check-sm No check-sm
GitHub personal access token (classic) Github Personal Access Token check-sm No check-sm
GitHub refresh token Github Refresh Token check-sm No check-sm
GitLab CI/CD job token gitlab_ci_build_token check-sm check-sm No
GitLab deploy token gitlab_deploy_token check-sm check-sm No
GitLab Feature Flags Client Token None No check-sm No
GitLab feed token gitlab_feed_token check-sm check-sm No
GitLab feed token v2 gitlab_feed_token_v2 check-sm check-sm check-sm
GitLab incoming email token gitlab_incoming_email_token check-sm check-sm check-sm
GitLab Kubernetes agent token gitlab_kubernetes_agent_token check-sm check-sm check-sm
GitLab OAuth application secret gitlab_oauth_app_secret check-sm check-sm check-sm
GitLab personal access token gitlab_personal_access_token check-sm check-sm check-sm
GitLab Personal Access Token (routable) gitlab_personal_access_token_routable check-sm check-sm check-sm
GitLab pipeline trigger token gitlab_pipeline_trigger_token check-sm check-sm check-sm
GitLab runner authentication token gitlab_runner_auth_token check-sm check-sm check-sm
GitLab runner registration token gitlab_runner_registration_token check-sm No check-sm
GitLab SCIM OAuth token gitlab_scim_oauth_token check-sm check-sm No
GoCardless API token GoCardless API token check-sm No No
Google API key GCP API key check-sm No No
Google (GCP) service account Google (GCP) Service-account check-sm No check-sm
Grafana Service Account Token GrafanaServiceAccountToken check-sm No check-sm
Grafana Cloud Access Policy Token GrafanaCloudAccessPolicyToken check-sm No check-sm
HashiCorp Terraform API token Hashicorp Terraform user/org API token check-sm No check-sm
HashiCorp Vault batch token Hashicorp Vault batch token check-sm No check-sm
HashiCorp Vault Service Token HashicorpVaultServiceToken check-sm No check-sm
Heroku API key or application authorization token Heroku API Key check-sm No check-sm
Highnote Live Secret Key HighnoteLiveSecretKey check-sm No check-sm
Highnote Test Secret Key HighnoteTestSecretKey check-sm No check-sm
HubSpot private app API token Hubspot API token check-sm No check-sm
Hugging Face User Access Token HuggingFaceUserAccessToken check-sm No check-sm
Instagram access token Instagram access token check-sm No No
Intercom API token Intercom API token check-sm No No
Intercom App Access Token IntercomAppAccessToken check-sm No check-sm
Intercom client secret or client ID Intercom client secret/ID check-sm No No
Ionic personal access token Ionic API token check-sm No No
Kubernetes Service Account Token KubernetesServiceAccToken check-sm No check-sm
LangChain API Key LangChainAPIKey check-sm No check-sm
Linear API token Linear API token check-sm No check-sm
Linear client secret or ID (OAuth 2.0) Linear client secret/ID check-sm No No
LinkedIn client ID Linkedin Client ID check-sm No No
LinkedIn client secret Linkedin Client secret check-sm No No
Lob API key Lob API Key check-sm No No
Lob publishable API key Lob Publishable API Key check-sm No No
Mailchimp API key Mailchimp API key check-sm No check-sm
Mailgun private API token Mailgun private API token check-sm No check-sm
Mailgun public verification key Mailgun public validation key check-sm No No
Mailgun webhook signing key Mailgun webhook signing key check-sm No check-sm
Mapbox API token Mapbox API token check-sm No No
Mapbox Secret API Token MapboxSecretApiToken check-sm No No
MaxMind License Key MaxMind License Key check-sm No check-sm
MessageBird access key messagebird-api-token check-sm No No
MessageBird API client ID MessageBird API client ID check-sm No No
Meta access token Meta access token check-sm No No
New Relic ingest browser API token New Relic ingest browser API token check-sm No No
New Relic ingest browser API token v2 New Relic ingest browser API token v2 check-sm No check-sm
New Relic REST API Key New Relic REST API Key check-sm No check-sm
New Relic user API ID New Relic user API ID check-sm No check-sm
New Relic user API key New Relic user API Key check-sm No check-sm
npm access token npm access token check-sm No check-sm
Oculus access token Oculus access token check-sm No No
Okta API Token OktaAPIToken check-sm No check-sm
Okta Client Secret OktaClientSecret check-sm No No
Onfido Live API Token Onfido Live API Token check-sm No check-sm
OpenAI API key open ai token check-sm No No
OpenAI Project Key OpenAiProjectKey check-sm No check-sm
OpenAI Service Account Key OpenAiServiceAccountKey check-sm No check-sm
Password in URL Password in URL check-sm No No
PGP private key PGP private key check-sm No No
PKCS8 private key PKCS8 private key check-sm No No
PlanetScale API token Planetscale API token check-sm No check-sm
PlanetScale App Secret PlanetscaleAppSecret check-sm No check-sm
PlanetScale OAuth Secret PlanetscaleOAuthSecret check-sm No check-sm
PlanetScale password Planetscale password check-sm No check-sm
PostHog Personal API key PostHogPersonalAPIkey check-sm No check-sm
PostHog Project API key PostHogProjectAPIkey check-sm No check-sm
Postman API token Postman API token check-sm No No
Postman Collection Access Key PostmanCollectionAccessKey check-sm No check-sm
Pulumi API token Pulumi API token check-sm No No
PyPi upload token PyPI upload token check-sm No check-sm
RSA private key RSA private key check-sm No No
RubyGems API token Rubygem API token check-sm No check-sm
Segment public API token Segment Public API token check-sm No check-sm
SendGrid API token Sendgrid API token check-sm No check-sm
Shippo API token Shippo API token check-sm No check-sm
Shippo Test API token Shippo Test API token check-sm No No
Shopify Partner API Token ShopifyPartnerAPIToken check-sm No check-sm
Shopify personal access token Shopify access token check-sm No check-sm
Shopify private app access token Shopify private app access token check-sm No check-sm
Shopify Custom App Access Token Shopify custom app access token check-sm No check-sm
Shopify shared secret Shopify shared secret check-sm No check-sm
Slack App Configuration Token SlackAppConfigurationToken check-sm No check-sm
Slack App Configuration Refresh Token SlackAppConfigurationRefreshToken check-sm No check-sm
Slack app level token SlackAppLevelToken check-sm No check-sm
Slack bot user OAuth token Slack token check-sm No check-sm
Slack webhook Slack Webhook check-sm No No
SonarQube Global Analysis Token SonarQubeGlobalAnalysisToken check-sm No check-sm
SonarQube Project Analysis Token SonarQubeProjectAnalysisToken check-sm No check-sm
SonarQube User Token SonarQubeUserToken check-sm No check-sm
Splunk Authentication Token SplunkAuthToken check-sm No check-sm
Splunk HTTP Event Collector (HEC) Token SplunkHECToken check-sm No No
SSH (DSA) private key SSH (DSA) private key check-sm No No
SSH (EC) private key SSH (EC) private key check-sm No No
SSH private key SSH private key check-sm No No
Stripe live restricted key StripeLiveRestrictedKey check-sm No check-sm
Stripe live secret key StripeLiveSecretKey check-sm No check-sm
Stripe Live Short Secret Key StripeLiveShortSecretKey check-sm No check-sm
Stripe publishable live key StripeLivePublishableKey check-sm No No
Stripe publishable test key StripeTestPublishableKey check-sm No No
Stripe restricted test key StripeTestRestrictedKey check-sm No No
Stripe secret test key StripeTestSecretKey check-sm No No
Stripe Test Short Secret Key StripeTestShortSecretKey check-sm No check-sm
Tailscale OAuth Client Secret TailscaleOauthClientSecret check-sm No check-sm
Tailscale API Access Token TailscaleApiAccessToken check-sm No check-sm
Tailscale Personal Auth Key TailscalePersonalAuthKey check-sm No check-sm
Tencent Cloud Secret ID TencentCloudSecretID check-sm No check-sm
Twilio Account SID Twilio Account SID check-sm No check-sm
Twilio API key Twilio API Key check-sm No check-sm
Twitch OAuth client secret Twitch API token check-sm No No
Typeform personal access token Typeform API token check-sm No No
Volcengine Access Key ID VolcengineAccessKeyID check-sm No check-sm
WakaTime API Key WakaTimeAPIKey check-sm No check-sm
X token Twitter token check-sm No No
Yandex.Cloud AWS API compatible access secret Yandex.Cloud AWS API compatible Access Secret check-sm No No
Yandex.Cloud API Key Yandex.Cloud API Key check-sm No No
Yandex.Cloud IAM cookie v1-1 Yandex.Cloud IAM Cookie v1 - 1 check-sm No No
Yandex.Cloud IAM cookie v1-3 Yandex.Cloud IAM Cookie v1 - 3 check-sm No No