Skip to main content

Cette version de GitHub Enterprise Server n'est plus disponible depuis le 2025-06-19. Aucune publication de correctifs n’est effectuée, même pour les problèmes de sécurité critiques. Pour de meilleures performances, une sécurité améliorée et de nouvelles fonctionnalités, effectuez une mise à niveau vers la dernière version de GitHub Enterprise. Pour obtenir de l’aide sur la mise à niveau, contactez le support GitHub Enterprise.

Modèles d’analyse de secrets pris en charge

Listes des secrets pris en charge et des partenaires avec lesquels GitHub travaille pour empêcher l'utilisation frauduleuse de secrets commités accidentellement.

Qui peut utiliser cette fonctionnalité ?

Secret scanning est disponible pour les types de référentiels suivants :

About secret scanning patterns

There are two types of secret scanning alerts:

  • Secret scanning alerts: Reported to users in the Security tab of the repository, when a supported secret is detected in the repository.
  • Push protection alerts: Reported to users in the Security tab of the repository, when a contributor bypasses push protection.

For in-depth information about each alert type, see About secret scanning alerts.

For details about all the supported patterns, see the Supported secrets section below.

If you use the REST API for secret scanning, you can use the Secret type to report on secrets from specific issuers. For more information, see REST API endpoints for secret scanning.

If you believe that secret scanning should have detected a secret committed to your repository, and it has not, you first need to check that GitHub supports your secret. For more information, refer to the following sections. For more advanced troubleshooting information, see Troubleshooting secret scanning.

Supported secrets

This table lists the secrets supported by secret scanning. You can see the types of alert that get generated for each token, as well as whether a validity check is performed on the token.

  • Provider: Name of the token provider.

  • Secret scanning alert: Token for which leaks are reported to users on GitHub.

    • Applies to private repositories where GitHub Advanced Security and secret scanning are enabled.
    • Includes high confidence tokens, which relate to supported patterns and specified custom patterns, as well as non-provider tokens such as private keys, which often result in false positives.
  • Push protection: Token for which leaks are reported to users on GitHub. Applies to repositories with secret scanning and push protection enabled.

  • Validity check: Token for which a validity check is implemented. Currently only applies to GitHub tokens.

Non-provider patterns

Remarque

The detection of non-provider patterns is currently in beta and subject to change.

ProviderToken
Generichttp_basic_authentication_header
Generichttp_bearer_authentication_header
Genericmongodb_connection_string
Genericmysql_connection_string
Genericopenssh_private_key
Genericpgp_private_key
Genericpostgres_connection_string
Genericrsa_private_key

Remarque

Push protection and validity checks are not supported for non-provider patterns.

High confidence patterns

ProviderTokenSecret scanning alertPush protectionValidity check
Adafruitadafruit_io_key✓✓✗
Adobeadobe_client_secret✓✓✗
Adobeadobe_device_token✓✓✗
Adobeadobe_pac_token✓✓✗
Adobeadobe_refresh_token✓✓✗
Adobeadobe_service_token✓✓✗
Adobeadobe_short_lived_access_token✓✓✗
Aivenaiven_auth_token✓✓✗
Aivenaiven_service_password✓✓✗
Alibabaalibaba_cloud_access_key_id
alibaba_cloud_access_key_secret
✓✓✗
Amazon AWSaws_access_key_id
aws_secret_access_key
✓✓✗
Anthropicanthropic_api_key✓✓✗
Asanaasana_personal_access_token✓✓✗
Atlassianatlassian_api_token
Token versions
✓✓✗
Atlassianatlassian_jwt✓✓✗
Authressauthress_service_client_access_key✓✓✗
Azureazure_active_directory_application_secret
Token versions
✓✓✗
Azureazure_batch_key_identifiable✓✓✗
Azureazure_cache_for_redis_access_key✓✓✗
Azureazure_container_registry_key_identifiable✓✓✗
Azureazure_cosmosdb_key_identifiable✓✓✗
Azureazure_devops_personal_access_token✓✓✗
Azureazure_function_key✓✓✗
Azureazure_management_certificate✓✗✗
Azureazure_ml_web_service_classic_identifiable_key✓✓✗
Azureazure_sas_token✓✗✗
Azureazure_search_admin_key✓✓✗
Azureazure_search_query_key✓✓✗
Azureazure_sql_connection_string✓✗✗
Azureazure_sql_password✓✓✗
Azureazure_storage_account_key
Token versions
✓✓✗
Baidubaiducloud_api_accesskey✓✓✗
Beamerbeamer_api_key✓✓✗
Bitbucketbitbucket_server_personal_access_token✓✓✗
Brevosendinblue_api_key✓✓✗
Brevosendinblue_smtp_key✓✓✗
Canadian Digital Servicecds_canada_notify_api_key✓✓✗
Canvacanva_connect_api_secret✓✓✗
Cashfreecashfree_api_key✓✓✗
Checkout.comcheckout_production_secret_key
Token versions
✓✓✗
Checkout.comcheckout_test_secret_key
Token versions
✓✓✗
Chief Toolschief_tools_token✓✓✗
CircleCIcircleci_personal_access_token✓✓✗
Clojarsclojars_deploy_token✓✓✗
CloudBeescodeship_credential✗✗✗
Contentfulcontentful_personal_access_token✓✓✗
crates.iocratesio_api_token✓✓✗
Databricksdatabricks_access_token✓✓✗
Defined Networkingdefined_networking_nebula_api_key✓✓✗
DevCycledevcycle_client_api_key✓✓✗
DevCycledevcycle_mobile_api_key✓✓✗
DevCycledevcycle_server_api_key✓✓✗
DigitalOceandigitalocean_oauth_token✓✓✗
DigitalOceandigitalocean_personal_access_token✓✓✗
DigitalOceandigitalocean_refresh_token✓✓✗
DigitalOceandigitalocean_system_token✓✓✗
Discorddiscord_bot_token
Token versions
✓✓✗
Dockerdocker_personal_access_token✓✓✗
Dopplerdoppler_audit_token✓✓✗
Dopplerdoppler_cli_token✓✓✗
Dopplerdoppler_personal_token✓✓✗
Dopplerdoppler_scim_token✓✓✗
Dopplerdoppler_service_account_token✓✓✗
Dopplerdoppler_service_token✓✓✗
Dropboxdropbox_access_token✓✗✗
Dropboxdropbox_short_lived_access_token✓✓✗
Duffelduffel_live_access_token✓✓✗
Duffelduffel_test_access_token✓✓✗
Dynatracedynatrace_internal_token✓✓✗
EasyPosteasypost_production_api_key✓✓✗
EasyPosteasypost_test_api_key✓✗✗
eBayebay_production_client_id
ebay_production_client_secret
✓✗✗
eBayebay_sandbox_client_id
ebay_sandbox_client_secret
✓✓✗
Facebookfacebook_access_token✓✗✗
Fastlyfastly_api_token
Token versions
✓✗✗
Figmafigma_pat✓✓✗
Finicityfinicity_app_key✓✗✗
Firebasefirebase_cloud_messaging_server_key✓✗✗
Flutterwaveflutterwave_live_api_secret_key✓✓✗
Flutterwaveflutterwave_test_api_secret_key✓✗✗
Frame.ioframeio_developer_token✓✗✗
Frame.ioframeio_jwt✓✓✗
FullStoryfullstory_api_key
Token versions
✓✓✗
GitHubgithub_app_installation_access_token
Token versions
✓✓✓
GitHubgithub_oauth_access_token
Token versions
✓✓✓
GitHubgithub_personal_access_token
Token versions
✓✓✓
GitHubgithub_refresh_token
Token versions
✓✓✓
GitHubgithub_ssh_private_key✓✓✓
GitLabgitlab_access_token✓✓✗
GoCardlessgocardless_live_access_token✓✗✗
GoCardlessgocardless_sandbox_access_token✓✗✗
Googlegoogle_api_key✓✗✗
Googlegoogle_cloud_service_account_credentials✓✓✗
Googlegoogle_oauth_access_token✓✓✗
Googlegoogle_oauth_client_id
google_oauth_client_secret
✓✓✗
Googlegoogle_oauth_refresh_token✓✓✗
Grafanagrafana_cloud_api_key✓✓✗
Grafanagrafana_cloud_api_token✓✓✗
Grafanagrafana_project_api_key✓✓✗
Grafanagrafana_project_service_account_token✓✓✗
HashiCorphashicorp_vault_batch_token
Token versions
✓✓✗
HashiCorphashicorp_vault_root_service_token✓✓✗
HashiCorphashicorp_vault_service_token
Token versions
✓✓✗
HashiCorpterraform_api_token✓✓✗
Highnotehighnote_rk_live_key✓✓✗
Highnotehighnote_rk_test_key✓✓✗
Highnotehighnote_sk_live_key✓✓✗
Highnotehighnote_sk_test_key✓✓✗
HOPhop_bearer✓✓✗
HOPhop_pat✓✓✗
HOPhop_ptk✓✓✗
Hubspothubspot_api_key
Token versions
✓✓✗
Intercomintercom_access_token✓✓✗
Ionicionic_personal_access_token
Token versions
✓✓✗
Ionicionic_refresh_token
Token versions
✓✓✗
JFrogjfrog_platform_access_token✓✓✗
JFrogjfrog_platform_api_key✓✓✗
JFrogjfrog_platform_reference_token✓✓✗
Lightspeedlightspeed_xs_pat✓✓✗
Linearlinear_api_key✓✓✗
Linearlinear_oauth_access_token✓✓✗
Loblob_live_api_key✓✗✗
Loblob_test_api_key✓✓✗
Localstacklocalstack_api_key✓✓✗
LogicMonitorlogicmonitor_bearer_token✓✓✗
LogicMonitorlogicmonitor_lmv1_access_key✓✓✗
Mailchimpmailchimp_api_key✓✗✗
Mailgunmailgun_api_key
Token versions
✓✓✗
Mapboxmapbox_secret_access_token✓✗✗
MaxMindmaxmind_license_key✓✓✗
Mercurymercury_non_production_api_token✓✓✗
Mercurymercury_production_api_token✓✓✗
Mergifymergify_application_key✓✓✗
MessageBirdmessagebird_api_key✓✗✗
Midtransmidtrans_production_server_key✓✓✗
Midtransmidtrans_sandbox_server_key✓✗✗
New Relicnew_relic_insights_query_key✓✓✗
New Relicnew_relic_license_key✓✗✗
New Relicnew_relic_personal_api_key✓✓✗
New Relicnew_relic_rest_api_key✓✓✗
Notionnotion_integration_token✓✗✗
Notionnotion_oauth_client_secret✓✓✗
npmnpm_access_token
Token versions
✓✓✗
NuGetnuget_api_key✓✓✗
Octopus Deployoctopus_deploy_api_key✓✗✗
OneChronosonechronos_api_key✓✓✗
OneChronosonechronos_eb_api_key✓✓✗
OneChronosonechronos_eb_encryption_key✓✓✗
OneChronosonechronos_oauth_token✓✓✗
OneChronosonechronos_refresh_token✓✓✗
Onfidoonfido_live_api_token✓✓✗
Onfidoonfido_sandbox_api_token✓✗✗
OpenAIopenai_api_key
Token versions
✓✓✗
Palantirpalantir_jwt✓✓✗
Persona Identitiespersona_production_api_key✓✓✗
Persona Identitiespersona_sandbox_api_key✓✓✗
Pinterestpinterest_access_token✓✓✗
Pinterestpinterest_refresh_token✓✓✗
PlanetScaleplanetscale_database_password✓✓✗
PlanetScaleplanetscale_oauth_token✓✓✗
PlanetScaleplanetscale_service_token✓✓✗
Plivoplivo_auth_id
plivo_auth_token
✓✓✗
Postmanpostman_api_key✓✓✗
Postmanpostman_collection_key✓✓✗
Prefectprefect_server_api_key✓✓✗
Prefectprefect_user_api_key✓✓✗
Proctorioproctorio_consumer_key✓✗✗
Proctorioproctorio_linkage_key✓✗✗
Proctorioproctorio_registration_key✓✗✗
Proctorioproctorio_secret_key
Token versions
✓✓✗
Pulumipulumi_access_token✓✓✗
PyPIpypi_api_token✓✓✗
ReadMereadmeio_api_access_token✓✓✗
redirect.pizzaredirect_pizza_api_token✓✓✗
Rootlyrootly_api_key✓✓✗
RubyGemsrubygems_api_key✓✓✗
Samsarasamsara_api_token✓✓✗
Samsarasamsara_oauth_access_token✓✓✗
Segmentsegment_public_api_token✓✓✗
SendGridsendgrid_api_key✓✓✗
Shipposhippo_live_api_token✓✓✗
Shipposhippo_test_api_token✓✗✗
Shopifyshopify_access_token✓✓✗
Shopifyshopify_app_client_credentials✓✓✗
Shopifyshopify_app_client_secret✓✗✗
Shopifyshopify_app_shared_secret✓✓✗
Shopifyshopify_custom_app_access_token✓✓✗
Shopifyshopify_marketplace_token✓✗✗
Shopifyshopify_merchant_token✓✗✗
Shopifyshopify_partner_api_token✓✓✗
Shopifyshopify_private_app_password✓✓✗
Slackslack_api_token
Token versions
✓✓✗
Slackslack_incoming_webhook_url✓✗✗
Slackslack_workflow_webhook_url✓✓✗
Squaresquare_access_token
Token versions
✓✓✗
Squaresquare_production_application_secret✓✓✗
Squaresquare_sandbox_application_secret✓✓✗
SSLMatesslmate_api_key
Token versions
✓✓✗
SSLMatesslmate_cluster_secret✓✓✗
Stripestripe_api_key✓✓✗
Stripestripe_legacy_api_key✓✗✗
Stripestripe_live_restricted_key✓✗✗
Stripestripe_test_restricted_key✓✗✗
Stripestripe_test_secret_key✓✓✗
Stripestripe_webhook_signing_secret✓✗✗
Supabasesupabase_service_key
Token versions
✓✗✗
Tableautableau_personal_access_token✓✓✗
Telegramtelegram_bot_token✓✗✗
Telnyxtelnyx_api_v2_key✓✓✗
Tencenttencent_cloud_secret_id✓✓✗
Tencenttencent_wechat_api_app_id✓✗✗
Twiliotwilio_access_token✓✓✗
Twiliotwilio_account_sid✓✓✗
Twiliotwilio_api_key✓✓✗
Typeformtypeform_personal_access_token✓✓✗
Uniwisewiseflow_api_key✓✓✗
VolcEnginevolcengine_access_key_id✓✓✗
Wakatimewakatime_app_secret✓✓✗
Wakatimewakatime_oauth_access_token✓✓✗
Wakatimewakatime_oauth_refresh_token✓✓✗
Workatoworkato_developer_api_token
Token versions
✓✓✗
WorkOSworkos_production_api_key
Token versions
✓✓✗
WorkOSworkos_staging_api_key
Token versions
✓✓✗
Yandexyandex_cloud_api_key✓✓✗
Yandexyandex_cloud_iam_cookie✓✗✗
Yandexyandex_cloud_iam_token✓✗✗
Yandexyandex_cloud_smartcaptcha_server_key✓✓✗
Yandexyandex_dictionary_api_key✓✓✗
Yandexyandex_predictor_api_key✓✗✗
Yandexyandex_translate_api_key✓✗✗
Zuplozuplo_consumer_api_key✓✓✗

Token versions

Service providers update the patterns used to generate tokens periodically and may support more than one version of a token. Push protection only supports the most recent token versions that secret scanning can identify with confidence. This avoids push protection blocking commits unnecessarily when a result may be a false positive, which is more likely to happen with legacy tokens.

Further reading