Skip to main content

Эта версия GitHub Enterprise Server была прекращена 2026-04-23. Исправления выпускаться не будут даже при критических проблемах безопасности. Для повышения производительности, повышения безопасности и новых функций выполните обновление до последней версии GitHub Enterprise Server. Чтобы получить справку по обновлению, обратитесь в службу поддержки GitHub Enterprise.

Поддерживаемые шаблоны сканирования секретов

Списки поддерживаемых секретов и партнеров, с которыми работает GitHub для предотвращения мошеннического использования случайно зафиксированных секретов.

Кто может использовать эту функцию?

Secret scanning доступен для следующих типов репозитория:

  • Публичные репозитории: Secret scanning запускается автоматически бесплатно.
  • Частные и внутренние репозитории, принадлежащие организации: доступны с включённым GitHub Advanced Security на GitHub Team или GitHub Enterprise Cloud.
  • Пользовательские репозитории: доступны на GitHub Enterprise Cloud с Enterprise Managed Users. Доступно на GitHub Enterprise Server, когда у предприятия включён GitHub Advanced Security .

В этой статье

About secret scanning patterns

There are two types of secret scanning alerts:

  • Secret scanning alerts: Reported to users in the Security tab of the repository, when a supported secret is detected in the repository.
  • Push protection alerts: Reported to users in the Security tab of the repository, when a contributor bypasses push protection.

For in-depth information about each alert type, see About secret scanning alerts.

For details about all the supported patterns, see the Supported secrets section below.

If you use the REST API for secret scanning, you can use the Secret type to report on secrets from specific issuers. For more information, see REST API endpoints for secret scanning.

If you believe that secret scanning should have detected a secret committed to your repository, and it has not, you first need to check that GitHub supports your secret. For more information, refer to the following sections. For more advanced troubleshooting information, see Secret scanning detection scope.

Supported secrets

The tables list the secrets supported by secret scanning for each secret type. Information in the tables may include this data:

  • Provider: Name of the token provider.
  • Secret scanning alert: Token for which leaks are reported to users on GitHub.
    • Applies to private repositories where GitHub Advanced Security and secret scanning are enabled.
    • Includes high confidence tokens, which relate to supported patterns and specified custom patterns, as well as non-provider tokens such as private keys, which often result in false positives.
  • Push protection: Token for which leaks are reported to users on GitHub. Applies to repositories with secret scanning and push protection enabled.
  • Validity check: Token for which a validity check is implemented. Currently only applies to GitHub tokens.
  • Metadata check: Token for which extended metadata is available, providing additional context about the detected secret.
  • Base64: Token for which Base64-encoded versions are supported.

Non-provider patterns

Примечание.

The detection of non-provider patterns is currently in beta and subject to change.

Precision levels are estimated based on the pattern type's typical false positive rates.

ProviderTokenDescriptionPrecision
Generichttp_basic_authentication_headerHTTP Basic Authentication credentials in request headersMedium
Generichttp_bearer_authentication_headerHTTP Bearer tokens used for API authenticationMedium
Genericmongodb_connection_stringConnection strings for MongoDB databases containing credentialsHigh
Genericmysql_connection_urlConnection strings for MySQL databases containing credentialsHigh
Genericopenssh_private_keyOpenSSH format private keys used for SSH authenticationHigh
Genericpgp_private_keyPGP (Pretty Good Privacy) private keys used for encryption and signingHigh
Genericpostgres_connection_stringConnection strings for PostgreSQL databases containing credentialsHigh
Genericrsa_private_keyRSA private keys used for cryptographic operationsHigh

Примечание.

Validity checks are not supported for non-provider patterns.

High confidence patterns

ProviderTokenSecret scanning alertPush protectionValidity checkBase64
Adafruitadafruit_io_key✓✓✗✗
Adobeadobe_client_secret✓✓✗✗
Adobeadobe_device_token✓✓✗✗
Adobeadobe_pac_token✓✓✗✗
Adobeadobe_refresh_token✓✓✗✗
Adobeadobe_service_token✓✓✗✗
Adobeadobe_short_lived_access_token✓✓✗✗
Aivenaiven_auth_token✓✓✗✗
Aivenaiven_service_password✓✓✗✗
Alibabaalibaba_cloud_access_key_id
alibaba_cloud_access_key_secret
✓✓✗✗
Amazon AWSaws_access_key_id
aws_secret_access_key
✓✓✗✗
Amazon AWSaws_secret_access_key
aws_session_token
aws_temporary_access_key_id
✓✓✗✗
Anthropicanthropic_api_key✓✓✗✗
Anthropicanthropic_session_id✓✓✗✗
Asanaasana_legacy_format_personal_access_token✓✗✗✗
Asanaasana_personal_access_token✓✓✗✗
Atlassianatlassian_api_token✓✗✗✗
Atlassianatlassian_api_token✓✓✗✗
Atlassianatlassian_jwt✓✗✗✗
Authressauthress_service_client_access_key✓✓✗✗
Azureazure_active_directory_application_secret✓✓✗✗
Azureazure_active_directory_application_secret✓✓✗✗
Azureazure_active_directory_application_secret✗✗✗✗
Azureazure_active_directory_user_credential✓✗✗✗
Azureazure_apim_direct_management_key✓✓✗✗
Azureazure_apim_gateway_key✓✓✗✗
Azureazure_apim_repository_key✓✓✗✗
Azureazure_apim_subscription_key✓✓✗✗
Azureazure_app_configuration_connection_string✓✗✗✗
Azureazure_batch_key_identifiable✓✓✗✗
Azureazure_cache_for_redis_access_key✓✓✗✗
Azureazure_communication_services_connection_string✓✗✗✗
Azureazure_container_registry_key_identifiable✓✓✗✗
Azureazure_cosmosdb_key_identifiable✓✓✗✗
Azureazure_devops_personal_access_token✓✓✗✗
Azureazure_event_hub_key_identifiable✓✓✗✗
Azureazure_function_key✓✓✗✗
Azureazure_iot_device_connection_string✓✗✗✗
Azureazure_iot_device_key✓✓✗✗
Azureazure_iot_device_provisioning_key✓✓✗✗
Azureazure_iot_hub_connection_string✓✗✗✗
Azureazure_iot_hub_key✓✓✗✗
Azureazure_iot_provisioning_connection_string✓✗✗✗
Azureazure_management_certificate✓✗✗✗
Azureazure_ml_web_service_classic_identifiable_key✓✓✗✗
Azureazure_relay_key_identifiable✓✓✗✗
Azureazure_sas_token✓✗✗✗
Azureazure_search_admin_key✓✓✗✗
Azureazure_search_query_key✓✓✗✗
Azureazure_service_bus_identifiable✓✓✗✗
Azureazure_signalr_connection_string✓✗✗✗
Azureazure_sql_connection_string✓✗✗✗
Azureazure_sql_password✓✓✗✗
Azureazure_storage_account_key✓✗✗✗
Azureazure_storage_account_key✓✓✗✗
Azureazure_web_pub_sub_connection_string✓✗✗✗
Azuremicrosoft_corporate_network_user_credential✓✗✗✗
Baidubaiducloud_api_accesskey✓✓✗✗
Beamerbeamer_api_key✓✗✗✗
Bitbucketbitbucket_server_personal_access_token✓✓✗✗
Canadian Digital Servicecds_canada_notify_api_key✓✓✗✗
Canvacanva_app_secret✓✓✗✗
Canvacanva_connect_api_secret✓✓✗✗
Canvacanva_secret✓✓✗✗
Cashfreecashfree_api_key✓✓✗✗
Checkout.comcheckout_production_secret_key✓✗✗✗
Checkout.comcheckout_production_secret_key✓✓✗✗
Checkout.comcheckout_test_secret_key✓✗✗✗
Checkout.comcheckout_test_secret_key✓✗✗✗
Chief Toolschief_tools_token✓✓✗✗
CircleCIcircleci_bot_access_token✓✓✗✗
CircleCIcircleci_personal_access_token✓✓✗✗
CircleCIcircleci_project_access_token✓✓✗✗
CircleCIcircleci_release_integration_token✓✓✗✗
Clojarsclojars_deploy_token✓✓✗✗
CloudBeescodeship_credential✗✗✗✗
Contentfulcontentful_personal_access_token✓✗✗✗
Contributed Systemscontributed_systems_credentials✗✗✗✗
crates.iocratesio_api_token✓✓✗✗
Databricksdatabricks_access_token✓✓✗✗
Datadogdatadog_api_key✗✗✗✗
Datadogdatadog_app_key✗✗✗✗
Defined Networkingdefined_networking_nebula_api_key✓✓✗✗
DevCycledevcycle_client_api_key✓✓✗✗
DevCycledevcycle_mobile_api_key✓✓✗✗
DevCycledevcycle_server_api_key✓✓✗✗
DigitalOceandigitalocean_oauth_token✓✓✗✗
DigitalOceandigitalocean_personal_access_token✓✓✗✗
DigitalOceandigitalocean_refresh_token✓✓✗✗
DigitalOceandigitalocean_system_token✓✓✗✗
Discorddiscord_bot_token✓✓✗✗
Discorddiscord_bot_token✓✓✗✗
Dockerdocker_personal_access_token✓✓✗✗
Dopplerdoppler_audit_token✓✓✗✗
Dopplerdoppler_cli_token✓✓✗✗
Dopplerdoppler_personal_token✓✓✗✗
Dopplerdoppler_scim_token✓✓✗✗
Dopplerdoppler_service_account_token✓✓✗✗
Dopplerdoppler_service_token✓✓✗✗
Dropboxdropbox_access_token✓✗✗✗
Dropboxdropbox_short_lived_access_token✓✓✗✗
Duffelduffel_live_access_token✓✓✗✗
Duffelduffel_test_access_token✓✗✗✗
Dynatracedynatrace_api_token✓✗✗✗
Dynatracedynatrace_internal_token✓✗✗✗
EasyPosteasypost_production_api_key✓✓✗✗
EasyPosteasypost_test_api_key✓✗✗✗
eBayebay_production_client_id
ebay_production_client_secret
✓✗✗✗
eBayebay_sandbox_client_id
ebay_sandbox_client_secret
✓✗✗✗
Facebookfacebook_access_token✓✗✗✗
Fastlyfastly_api_token✓✗✗✗
Fastlyfastly_api_token✓✗✗✗
Figmafigma_pat✓✓✗✗
Finicityfinicity_app_key✓✗✗✗
Firebasefirebase_cloud_messaging_server_key✓✗✗✗
Flutterwaveflutterwave_live_api_secret_key✓✓✗✗
Flutterwaveflutterwave_test_api_secret_key✓✗✗✗
Frame.ioframeio_developer_token✓✗✗✗
Frame.ioframeio_jwt✓✗✗✗
FullStoryfullstory_api_key✓✓✗✗
FullStoryfullstory_api_key✓✗✗✗
GitHubgithub_app_installation_access_token✓✓✓✗
GitHubgithub_app_installation_access_token✓✓✓✗
GitHubgithub_oauth_access_token✓✓✓✗
GitHubgithub_oauth_access_token✓✓✓✗
GitHubgithub_personal_access_token✓✗✓✗
GitHubgithub_personal_access_token✓✓✓✗
GitHubgithub_personal_access_token✓✓✓✗
GitHubgithub_refresh_token✓✓✓✗
GitHubgithub_ssh_private_key✓✓✓✗
GitHubgithub_test_token✓✗✗✗
GitHub Secret Scanningsecret_scanning_sample_token✓✓✗✗
GitLabgitlab_access_token✓✗✗✗
GoCardlessgocardless_live_access_token✓✗✗✗
GoCardlessgocardless_sandbox_access_token✓✗✗✗
Googlegoogle_api_key✓✗✗✗
Googlegoogle_cloud_private_key_id✗✗✗✗
Googlegoogle_cloud_service_account_credentials✓✓✗✗
Googlegoogle_cloud_storage_access_key_secret
google_cloud_storage_service_account_access_key_id
✓✓✗✗
Googlegoogle_cloud_storage_access_key_secret
google_cloud_storage_user_access_key_id
✓✓✗✗
Googlegoogle_oauth_access_token✓✗✗✗
Googlegoogle_oauth_client_id
google_oauth_client_secret
✓✓✗✗
Googlegoogle_oauth_refresh_token✓✗✗✗
Grafanagrafana_cloud_api_key✓✓✗✗
Grafanagrafana_cloud_api_token✓✓✗✗
Grafanagrafana_project_api_key✓✓✗✗
Grafanagrafana_project_service_account_token✓✓✗✗
HashiCorphashicorp_vault_batch_token✓✗✗✗
HashiCorphashicorp_vault_batch_token✓✓✗✗
HashiCorphashicorp_vault_root_service_token✓✓✗✗
HashiCorphashicorp_vault_service_token✓✓✗✗
HashiCorphashicorp_vault_service_token✓✗✗✗
HashiCorpterraform_api_token✓✓✗✗
Highnotehighnote_rk_live_key✓✓✗✗
Highnotehighnote_rk_test_key✓✓✗✗
Highnotehighnote_sk_live_key✓✓✗✗
Highnotehighnote_sk_test_key✓✓✗✗
HOPhop_bearer✓✓✗✗
HOPhop_pat✓✓✗✗
HOPhop_ptk✓✓✗✗
Hubspothubspot_api_key✗✗✗✗
Hubspothubspot_api_key✓✗✗✗
Hubspothubspot_api_key✓✓✗✗
Hubspothubspot_personal_access_key✓✓✗✗
Hubspothubspot_smtp_credential✗✗✗✗
IBMibm_cloud_iam_key✓✗✗✗
IBMibm_softlayer_api_key✓✗✗✗
Intercomintercom_access_token✓✓✗✗
Ionicionic_personal_access_token✓✗✗✗
Ionicionic_personal_access_token✓✓✗✗
Ionicionic_refresh_token✓✓✗✗
Ionicionic_refresh_token✓✗✗✗
JFrogjfrog_platform_access_token✓✓✗✗
JFrogjfrog_platform_api_key✓✓✗✗
JFrogjfrog_platform_reference_token✓✓✗✗
Lightspeedlightspeed_xs_pat✓✓✗✗
Linearlinear_api_key✓✓✗✗
Linearlinear_oauth_access_token✓✓✗✗
Loblob_live_api_key✓✗✗✗
Loblob_test_api_key✓✗✗✗
Localstacklocalstack_api_key✓✓✗✗
LogicMonitorlogicmonitor_bearer_token✓✓✗✗
LogicMonitorlogicmonitor_lmv1_access_key✓✓✗✗
Login with Amazonamazon_oauth_client_id
amazon_oauth_client_secret
amazon_oauth_client_secret
✓✓✗✗
Mailchimpmailchimp_api_key✓✗✗✗
Mailchimpmandrill_api_key✗✗✗✗
Mailgunmailgun_api_key✓✗✗✗
Mailgunmailgun_api_key✓✗✗✗
Mailgunmailgun_smtp_credential✗✗✗✗
Mapboxmapbox_secret_access_token✓✗✗✗
MaxMindmaxmind_license_key✓✓✗✗
Mercurymercury_non_production_api_token✓✓✗✗
Mercurymercury_production_api_token✓✓✗✗
Mergifymergify_application_key✓✓✗✗
MessageBirdmessagebird_api_key✓✗✗✗
Midtransmidtrans_production_server_key✓✓✗✗
Midtransmidtrans_sandbox_server_key✓✗✗✗
New Relicnew_relic_insights_query_key✓✓✗✗
New Relicnew_relic_license_key✓✗✗✗
New Relicnew_relic_personal_api_key✓✓✗✗
New Relicnew_relic_rest_api_key✓✓✗✗
Notionnotion_integration_token✓✗✗✗
Notionnotion_oauth_client_secret✓✗✗✗
npmnpm_access_token✓✓✗✗
npmnpm_access_token✓✗✗✗
npmnpm_access_token✗✗✗✗
NuGetnuget_api_key✓✓✗✗
Octopus Deployoctopus_deploy_api_key✓✗✗✗
Oculusoculus_access_token✓✗✗✗
OneChronosonechronos_api_key✓✓✗✗
OneChronosonechronos_eb_api_key✓✓✗✗
OneChronosonechronos_eb_encryption_key✓✓✗✗
OneChronosonechronos_oauth_token✓✓✗✗
OneChronosonechronos_refresh_token✓✓✗✗
Onfidoonfido_live_api_token✓✓✗✗
Onfidoonfido_sandbox_api_token✓✗✗✗
OpenAIopenai_api_key✓✓✗✗
OpenAIopenai_api_key✓✗✗✗
Orbitorbit_api_token✓✗✗✗
PagerDutypagerduty_oauth_secret✓✓✗✗
PagerDutypagerduty_oauth_token✓✓✗✗
Palantirpalantir_jwt✓✓✗✗
Persona Identitiespersona_production_api_key✓✓✗✗
Persona Identitiespersona_sandbox_api_key✓✓✗✗
Pinterestpinterest_access_token✓✓✗✗
Pinterestpinterest_refresh_token✓✓✗✗
PlanetScaleplanetscale_database_password✓✓✗✗
PlanetScaleplanetscale_oauth_token✓✓✗✗
PlanetScaleplanetscale_service_token✓✓✗✗
Plivoplivo_auth_id
plivo_auth_token
✓✓✗✗
Postmanpostman_api_key✓✓✗✗
Postmanpostman_collection_key✓✓✗✗
Prefectprefect_server_api_key✓✓✗✗
Prefectprefect_user_api_key✓✓✗✗
Proctorioproctorio_consumer_key✓✗✗✗
Proctorioproctorio_linkage_key✓✗✗✗
Proctorioproctorio_registration_key✓✗✗✗
Proctorioproctorio_secret_key✓✓✗✗
Proctorioproctorio_secret_key✓✗✗✗
Pulumipulumi_access_token✓✗✗✗
PyPIpypi_api_token✓✗✗✗
ReadMereadmeio_api_access_token✓✓✗✗
redirect.pizzaredirect_pizza_api_token✓✓✗✗
Replicatereplicate_api_token✗✗✗✗
Rootlyrootly_api_key✓✓✗✗
RubyGemsrubygems_api_key✓✗✗✗
Samsarasamsara_api_token✓✓✗✗
Samsarasamsara_oauth_access_token✓✓✗✗
Segmentsegment_public_api_token✓✓✗✗
SendGridsendgrid_api_key✓✓✗✗
Sendinbluesendinblue_api_key✓✓✗✗
Sendinbluesendinblue_smtp_key✓✓✗✗
Shipposhippo_live_api_token✓✓✗✗
Shipposhippo_test_api_token✓✗✗✗
Shopifyshopify_access_token✓✓✗✗
Shopifyshopify_app_client_credentials✓✗✗✗
Shopifyshopify_app_client_secret✓✗✗✗
Shopifyshopify_app_shared_secret✓✓✗✗
Shopifyshopify_custom_app_access_token✓✗✗✗
Shopifyshopify_marketplace_token✓✗✗✗
Shopifyshopify_merchant_token✓✗✗✗
Shopifyshopify_partner_api_token✓✗✗✗
Shopifyshopify_private_app_password✓✗✗✗
Slackslack_api_token✓✓✗✗
Slackslack_api_token✓✗✗✗
Slackslack_api_token✓✓✗✗
Slackslack_incoming_webhook_url✓✗✗✗
Slackslack_workflow_webhook_url✓✗✗✗
Squaresquare_access_token✓✗✗✗
Squaresquare_access_token✓✗✗✗
Squaresquare_access_token✓✗✗✗
Squaresquare_production_application_secret✓✗✗✗
Squaresquare_sandbox_application_secret✓✗✗✗
SSLMatesslmate_api_key✓✗✗✗
SSLMatesslmate_api_key✓✗✗✗
SSLMatesslmate_cluster_secret✓✗✗✗
Stripestripe_api_key✓✓✗✗
Stripestripe_legacy_api_key✓✗✗✗
Stripestripe_live_restricted_key✓✗✗✗
Stripestripe_test_restricted_key✓✗✗✗
Stripestripe_test_secret_key✓✗✗✗
Stripestripe_webhook_signing_secret✓✗✗✗
Supabasesupabase_service_key✓✗✗✗
Supabasesupabase_service_key✓✗✗✗
Tableautableau_personal_access_token✓✗✗✗
Telegramtelegram_bot_token✓✗✗✗
Telnyxtelnyx_api_v2_key✓✓✗✗
Tencenttencent_cloud_secret_id✓✓✗✗
Tencenttencent_wechat_api_app_id✓✗✗✗
Twiliotwilio_access_token✓✓✗✗
Twiliotwilio_account_sid✓✓✗✗
Twiliotwilio_api_key✓✓✗✗
Typeformtypeform_personal_access_token✓✓✗✗
Uniwisewiseflow_api_key✓✓✗✗
Unkeyunkey_root_key✓✗✗✗
VolcEnginevolcengine_access_key_id✓✓✗✗
Wakatimewakatime_api_key✓✓✗✗
Wakatimewakatime_app_secret✓✓✗✗
Wakatimewakatime_oauth_access_token✓✓✗✗
Wakatimewakatime_oauth_refresh_token✓✓✗✗
Workatoworkato_developer_api_token✓✓✗✗
Workatoworkato_developer_api_token✓✓✗✗
Workatoworkato_developer_api_token✓✓✗✗
Workatoworkato_developer_api_token✓✓✗✗
WorkOSworkos_production_api_key✓✓✗✗
WorkOSworkos_production_api_key✗✗✗✗
WorkOSworkos_staging_api_key✓✗✗✗
WorkOSworkos_staging_api_key✗✗✗✗
Yandexyandex_cloud_api_key✓✗✗✗
Yandexyandex_cloud_iam_access_secret✓✗✗✗
Yandexyandex_cloud_iam_cookie✓✗✗✗
Yandexyandex_cloud_iam_token✓✗✗✗
Yandexyandex_cloud_smartcaptcha_server_key✓✓✗✗
Yandexyandex_dictionary_api_key✓✗✗✗
Yandexyandex_passport_oauth_token✓✓✗✗
Yandexyandex_predictor_api_key✓✗✗✗
Yandexyandex_translate_api_key✓✗✗✗
Zuplozuplo_consumer_api_key✓✓✗✗

Token versions

Service providers update the patterns used to generate tokens periodically and may support more than one version of a token. Push protection only supports the most recent token versions that secret scanning can identify with confidence. This avoids push protection blocking commits unnecessarily when a result may be a false positive, which is more likely to happen with legacy tokens.

Further reading