Detected secrets

  • Tier: Free, Premium, Ultimate
  • Offering: GitLab.com, GitLab Self-Managed, GitLab Dedicated

This table lists the secrets detected by:

  • Pipeline secret detection
  • Client-side secret detection
  • Secret push protection

Secret detection rules are updated in the default ruleset. Detected secrets with patterns that have been removed or updated remain open so you can triage them.

DescriptionIDPipeline secret detectionClient-side secret detectionSecret push protection
Adafruit IO KeyAdafruitIOKeycheck-circle Yesdotted-circle Nocheck-circle Yes
Adobe Client ID (OAuth Web)Adobe Client ID (Oauth Web)check-circle Yesdotted-circle Nodotted-circle No
Adobe client secretAdobe Client Secretcheck-circle Yesdotted-circle Nocheck-circle Yes
Age secret keyAge secret keycheck-circle Yesdotted-circle Nodotted-circle No
Aiven Service PasswordAivenServicePasswordcheck-circle Yesdotted-circle Nocheck-circle Yes
Alibaba AccessKey IDAlibaba AccessKey IDcheck-circle Yesdotted-circle Nodotted-circle No
Alibaba Secret KeyAlibaba Secret Keycheck-circle Yesdotted-circle Nodotted-circle No
Anthropic API keyanthropic_keycheck-circle Yescheck-circle Yescheck-circle Yes
Artifactory API KeyArtifactoryApiKeycheck-circle Yesdotted-circle Nocheck-circle Yes
Artifactory Identity TokenArtifactoryIdentityTokencheck-circle Yesdotted-circle Nocheck-circle Yes
Asana client IDAsana Client IDcheck-circle Yesdotted-circle Nodotted-circle No
Asana client secretAsana Client Secretcheck-circle Yesdotted-circle Nodotted-circle No
Asana Personal Access Token V1AsanaPersonalAccessTokenV1check-circle Yesdotted-circle Nocheck-circle Yes
Asana Personal Access Token V2AsanaPersonalAccessTokenV2check-circle Yesdotted-circle Nocheck-circle Yes
Atlassian API KeyAtlassianApiKeycheck-circle Yesdotted-circle Nocheck-circle Yes
Atlassian API tokenAtlassian API tokencheck-circle Yesdotted-circle Nodotted-circle No
Atlassian User API TokenAtlassianUserApiTokencheck-circle Yesdotted-circle Nocheck-circle Yes
AWS access tokenAWScheck-circle Yesdotted-circle Nocheck-circle Yes
Azure Entra Client SecretAzureEntraClientSecretcheck-circle Yesdotted-circle Nocheck-circle Yes
Beamer API tokenBeamer API tokencheck-circle Yesdotted-circle Nodotted-circle No
Bitbucket client IDBitbucket client IDcheck-circle Yesdotted-circle Nodotted-circle No
Bitbucket client secretBitbucket client secretcheck-circle Yesdotted-circle Nodotted-circle No
Brevo API tokenSendinblue API tokencheck-circle Yesdotted-circle Nocheck-circle Yes
Brevo SMTP tokenSendinblue SMTP tokencheck-circle Yesdotted-circle Nocheck-circle Yes
CircleCI access tokenCircleCI access tokenscheck-circle Yesdotted-circle Nodotted-circle No
CircleCI Personal Access TokenCircleCIPersonalAccessTokencheck-circle Yesdotted-circle Nocheck-circle Yes
Clojars deploy tokenClojars API tokencheck-circle Yesdotted-circle Nodotted-circle No
Contentful delivery API tokenContentful delivery API tokencheck-circle Yesdotted-circle Nodotted-circle No
Contentful personal access tokenContentfulPersonalAccessTokencheck-circle Yesdotted-circle Nocheck-circle Yes
Contentful preview API tokenContentful preview API tokencheck-circle Yesdotted-circle Nodotted-circle No
Databricks API tokenDatabricks API tokencheck-circle Yesdotted-circle Nodotted-circle No
DigitalOcean OAuth access tokendigitalocean-access-tokencheck-circle Yesdotted-circle Nodotted-circle No
DigitalOcean personal access tokendigitalocean-patcheck-circle Yesdotted-circle Nodotted-circle No
DigitalOcean refresh tokendigitalocean-refresh-tokencheck-circle Yesdotted-circle Nodotted-circle No
Discord API keyDiscord API keycheck-circle Yesdotted-circle Nodotted-circle No
Discord client IDDiscord client IDcheck-circle Yesdotted-circle Nodotted-circle No
Discord client secretDiscord client secretcheck-circle Yesdotted-circle Nodotted-circle No
Docker Personal Access TokenDockerPersonalAccessTokencheck-circle Yesdotted-circle Nocheck-circle Yes
Doppler API tokenDoppler API tokencheck-circle Yesdotted-circle Nocheck-circle Yes
Doppler Service tokenDoppler Service tokencheck-circle Yesdotted-circle Nocheck-circle Yes
Dropbox API secret/keyDropbox API secret/keycheck-circle Yesdotted-circle Nodotted-circle No
Dropbox long lived API tokenDropbox long lived API tokencheck-circle Yesdotted-circle Nodotted-circle No
Dropbox short lived API tokenDropbox short lived API tokencheck-circle Yesdotted-circle Nocheck-circle Yes
Duffel API tokenDuffel API tokencheck-circle Yesdotted-circle Nodotted-circle No
Dynatrace Platform TokenDynatracePlatformTokencheck-circle Yesdotted-circle Nodotted-circle No
EasyPost production API keyEasyPost API tokencheck-circle Yesdotted-circle Nodotted-circle No
EasyPost test API keyEasyPost test API tokencheck-circle Yesdotted-circle Nodotted-circle No
Facebook tokenFacebook tokencheck-circle Yesdotted-circle Nodotted-circle No
Fastly API user or automation tokenFastly API tokencheck-circle Yesdotted-circle Nodotted-circle No
Figma Personal Access TokenFigmaPersonalAccessTokencheck-circle Yesdotted-circle Nocheck-circle Yes
Finicity API tokenFinicity API tokencheck-circle Yesdotted-circle Nodotted-circle No
Finicity client secretFinicity client secretcheck-circle Yesdotted-circle Nodotted-circle No
Flutterwave test encrypted keyFlutterwave encrypted keycheck-circle Yesdotted-circle Nodotted-circle No
Flutterwave test public keyFlutterwave public keycheck-circle Yesdotted-circle Nodotted-circle No
Flutterwave test secret keyFlutterwave secret keycheck-circle Yesdotted-circle Nodotted-circle No
Frame.io API tokenFrame.io API tokencheck-circle Yesdotted-circle Nodotted-circle No
GCP API keyGCP API keycheck-circle Yesdotted-circle Nodotted-circle No
GCP OAuth client secretGCP OAuth client secretcheck-circle Yesdotted-circle Nocheck-circle Yes
GitHub app tokenGithub App Tokencheck-circle Yesdotted-circle Nocheck-circle Yes
GitHub App Installation TokenGithubAppInstallationTokencheck-circle Yesdotted-circle Nocheck-circle Yes
GitHub Fine Grained Personal Access TokenGithubFineGrainedPersonalAccessTokencheck-circle Yesdotted-circle Nocheck-circle Yes
GitHub OAuth Access TokenGithub OAuth Access Tokencheck-circle Yesdotted-circle Nocheck-circle Yes
GitHub personal access token (classic)Github Personal Access Tokencheck-circle Yesdotted-circle Nocheck-circle Yes
GitHub refresh tokenGithub Refresh Tokencheck-circle Yesdotted-circle Nocheck-circle Yes
GitLab CI/CD job tokengitlab_ci_build_tokencheck-circle Yescheck-circle Yesdotted-circle No
GitLab deploy tokengitlab_deploy_tokencheck-circle Yescheck-circle Yesdotted-circle No
GitLab Feature Flags Client TokenNonedotted-circle Nocheck-circle Yesdotted-circle No
GitLab feed tokengitlab_feed_tokencheck-circle Yescheck-circle Yesdotted-circle No
GitLab feed token v2gitlab_feed_token_v2check-circle Yescheck-circle Yescheck-circle Yes
GitLab incoming email tokengitlab_incoming_email_tokencheck-circle Yescheck-circle Yescheck-circle Yes
GitLab Kubernetes agent tokengitlab_kubernetes_agent_tokencheck-circle Yescheck-circle Yescheck-circle Yes
GitLab OAuth application secretgitlab_oauth_app_secretcheck-circle Yescheck-circle Yescheck-circle Yes
GitLab personal access tokengitlab_personal_access_tokencheck-circle Yescheck-circle Yescheck-circle Yes
GitLab Personal Access Token (routable)gitlab_personal_access_token_routablecheck-circle Yescheck-circle Yescheck-circle Yes
GitLab pipeline trigger tokengitlab_pipeline_trigger_tokencheck-circle Yescheck-circle Yescheck-circle Yes
GitLab runner authentication tokengitlab_runner_auth_tokencheck-circle Yescheck-circle Yescheck-circle Yes
GitLab runner registration tokengitlab_runner_registration_tokencheck-circle Yesdotted-circle Nocheck-circle Yes
GitLab SCIM OAuth tokengitlab_scim_oauth_tokencheck-circle Yescheck-circle Yesdotted-circle No
GoCardless API tokenGoCardless API tokencheck-circle Yesdotted-circle Nodotted-circle No
Google (GCP) service accountGoogle (GCP) Service-accountcheck-circle Yesdotted-circle Nocheck-circle Yes
Grafana API tokenGrafana API tokencheck-circle Yesdotted-circle Nocheck-circle Yes
HashiCorp Terraform API tokenHashicorp Terraform user/org API tokencheck-circle Yesdotted-circle Nocheck-circle Yes
HashiCorp Vault batch tokenHashicorp Vault batch tokencheck-circle Yesdotted-circle Nocheck-circle Yes
Heroku API key or application authorization tokenHeroku API Keycheck-circle Yesdotted-circle Nodotted-circle No
Highnote Live Secret KeyHighnoteLiveSecretKeycheck-circle Yesdotted-circle Nocheck-circle Yes
Highnote Test Secret KeyHighnoteTestSecretKeycheck-circle Yesdotted-circle Nocheck-circle Yes
HubSpot private app API tokenHubspot API tokencheck-circle Yesdotted-circle Nocheck-circle Yes
Hugging Face User Access TokenHuggingFaceUserAccessTokencheck-circle Yesdotted-circle Nocheck-circle Yes
Instagram access tokenInstagram access tokencheck-circle Yesdotted-circle Nodotted-circle No
Intercom API tokenIntercom API tokencheck-circle Yesdotted-circle Nodotted-circle No
Intercom client secret or client IDIntercom client secret/IDcheck-circle Yesdotted-circle Nodotted-circle No
Ionic personal access tokenIonic API tokencheck-circle Yesdotted-circle Nodotted-circle No
Linear API tokenLinear API tokencheck-circle Yesdotted-circle Nocheck-circle Yes
Linear client secret or ID (OAuth 2.0)Linear client secret/IDcheck-circle Yesdotted-circle Nodotted-circle No
LinkedIn client IDLinkedin Client IDcheck-circle Yesdotted-circle Nodotted-circle No
LinkedIn client secretLinkedin Client secretcheck-circle Yesdotted-circle Nodotted-circle No
Lob API keyLob API Keycheck-circle Yesdotted-circle Nodotted-circle No
Lob publishable API keyLob Publishable API Keycheck-circle Yesdotted-circle Nodotted-circle No
Mailchimp API keyMailchimp API keycheck-circle Yesdotted-circle Nocheck-circle Yes
Mailgun private API tokenMailgun private API tokencheck-circle Yesdotted-circle Nocheck-circle Yes
Mailgun public verification keyMailgun public validation keycheck-circle Yesdotted-circle Nodotted-circle No
Mailgun webhook signing keyMailgun webhook signing keycheck-circle Yesdotted-circle Nocheck-circle Yes
Mapbox API tokenMapbox API tokencheck-circle Yesdotted-circle Nodotted-circle No
MaxMind License KeyMaxMind License Keycheck-circle Yesdotted-circle Nocheck-circle Yes
MessageBird access keymessagebird-api-tokencheck-circle Yesdotted-circle Nodotted-circle No
MessageBird API client IDMessageBird API client IDcheck-circle Yesdotted-circle Nodotted-circle No
Meta access tokenMeta access tokencheck-circle Yesdotted-circle Nodotted-circle No
New Relic ingest browser API tokenNew Relic ingest browser API tokencheck-circle Yesdotted-circle Nodotted-circle No
New Relic ingest browser API token v2New Relic ingest browser API token v2check-circle Yesdotted-circle Nocheck-circle Yes
New Relic REST API KeyNew Relic REST API Keycheck-circle Yesdotted-circle Nocheck-circle Yes
New Relic user API IDNew Relic user API IDcheck-circle Yesdotted-circle Nocheck-circle Yes
New Relic user API keyNew Relic user API Keycheck-circle Yesdotted-circle Nocheck-circle Yes
npm access tokennpm access tokencheck-circle Yesdotted-circle Nocheck-circle Yes
Oculus access tokenOculus access tokencheck-circle Yesdotted-circle Nodotted-circle No
Onfido Live API TokenOnfido Live API Tokencheck-circle Yesdotted-circle Nocheck-circle Yes
OpenAI API keyopen ai tokencheck-circle Yesdotted-circle Nodotted-circle No
Password in URLPassword in URLcheck-circle Yesdotted-circle Nodotted-circle No
PGP private keyPGP private keycheck-circle Yesdotted-circle Nodotted-circle No
PKCS8 private keyPKCS8 private keycheck-circle Yesdotted-circle Nodotted-circle No
PlanetScale API tokenPlanetscale API tokencheck-circle Yesdotted-circle Nocheck-circle Yes
PlanetScale App SecretPlanetscaleAppSecretcheck-circle Yesdotted-circle Nocheck-circle Yes
PlanetScale OAuth SecretPlanetscaleOAuthSecretcheck-circle Yesdotted-circle Nocheck-circle Yes
PlanetScale passwordPlanetscale passwordcheck-circle Yesdotted-circle Nocheck-circle Yes
PostHog Personal API keyPostHogPersonalAPIkeycheck-circle Yesdotted-circle Nocheck-circle Yes
PostHog Project API keyPostHogProjectAPIkeycheck-circle Yesdotted-circle Nocheck-circle Yes
Postman API tokenPostman API tokencheck-circle Yesdotted-circle Nodotted-circle No
Pulumi API tokenPulumi API tokencheck-circle Yesdotted-circle Nodotted-circle No
PyPi upload tokenPyPI upload tokencheck-circle Yesdotted-circle Nocheck-circle Yes
RSA private keyRSA private keycheck-circle Yesdotted-circle Nodotted-circle No
RubyGems API tokenRubygem API tokencheck-circle Yesdotted-circle Nocheck-circle Yes
Segment public API tokenSegment Public API tokencheck-circle Yesdotted-circle Nocheck-circle Yes
SendGrid API tokenSendgrid API tokencheck-circle Yesdotted-circle Nocheck-circle Yes
Shippo API tokenShippo API tokencheck-circle Yesdotted-circle Nocheck-circle Yes
Shippo Test API tokenShippo Test API tokencheck-circle Yesdotted-circle Nodotted-circle No
Shopify custom app access tokenShopify custom app access tokencheck-circle Yesdotted-circle Nocheck-circle Yes
Shopify personal access tokenShopify access tokencheck-circle Yesdotted-circle Nocheck-circle Yes
Shopify private app access tokenShopify private app access tokencheck-circle Yesdotted-circle Nocheck-circle Yes
Shopify shared secretShopify shared secretcheck-circle Yesdotted-circle Nocheck-circle Yes
Slack app level tokenSlackAppLevelTokencheck-circle Yesdotted-circle Nocheck-circle Yes
Slack bot user OAuth tokenSlack tokencheck-circle Yesdotted-circle Nocheck-circle Yes
Slack webhookSlack Webhookcheck-circle Yesdotted-circle Nodotted-circle No
SonarQube Global Analysis TokenSonarQubeGlobalAnalysisTokencheck-circle Yesdotted-circle Nocheck-circle Yes
SonarQube Project Analysis TokenSonarQubeProjectAnalysisTokencheck-circle Yesdotted-circle Nocheck-circle Yes
SonarQube User TokenSonarQubeUserTokencheck-circle Yesdotted-circle Nocheck-circle Yes
SSH (DSA) private keySSH (DSA) private keycheck-circle Yesdotted-circle Nodotted-circle No
SSH (EC) private keySSH (EC) private keycheck-circle Yesdotted-circle Nodotted-circle No
SSH private keySSH private keycheck-circle Yesdotted-circle Nodotted-circle No
Stripe live restricted keyStripeLiveRestrictedKeycheck-circle Yesdotted-circle Nocheck-circle Yes
Stripe live secret keyStripeLiveSecretKeycheck-circle Yesdotted-circle Nocheck-circle Yes
Stripe Live Short Secret KeyStripeLiveShortSecretKeycheck-circle Yesdotted-circle Nocheck-circle Yes
Stripe publishable live keyStripeLivePublishableKeycheck-circle Yesdotted-circle Nodotted-circle No
Stripe publishable test keyStripeTestPublishableKeycheck-circle Yesdotted-circle Nodotted-circle No
Stripe restricted test keyStripeTestRestrictedKeycheck-circle Yesdotted-circle Nodotted-circle No
Stripe secret test keyStripeTestSecretKeycheck-circle Yesdotted-circle Nodotted-circle No
Stripe Test Short Secret KeyStripeTestShortSecretKeycheck-circle Yesdotted-circle Nocheck-circle Yes
Tailscale keyTailscale keycheck-circle Yesdotted-circle Nodotted-circle No
Tencent Cloud Secret IDTencentCloudSecretIDcheck-circle Yesdotted-circle Nocheck-circle Yes
Twilio Account SIDTwilio Account SIDcheck-circle Yesdotted-circle Nocheck-circle Yes
Twilio API keyTwilio API Keycheck-circle Yesdotted-circle Nocheck-circle Yes
Twitch OAuth client secretTwitch API tokencheck-circle Yesdotted-circle Nodotted-circle No
Typeform personal access tokenTypeform API tokencheck-circle Yesdotted-circle Nodotted-circle No
Volcengine Access Key IDVolcengineAccessKeyIDcheck-circle Yesdotted-circle Nocheck-circle Yes
WakaTime API KeyWakaTimeAPIKeycheck-circle Yesdotted-circle Nocheck-circle Yes
X tokenTwitter tokencheck-circle Yesdotted-circle Nodotted-circle No
Yandex.Cloud AWS API compatible access secretYandex.Cloud AWS API compatible Access Secretcheck-circle Yesdotted-circle Nodotted-circle No
Yandex.Cloud API KeyYandex.Cloud API Keycheck-circle Yesdotted-circle Nodotted-circle No
Yandex.Cloud IAM cookie v1-1Yandex.Cloud IAM Cookie v1 - 1check-circle Yesdotted-circle Nodotted-circle No
Yandex.Cloud IAM cookie v1-3Yandex.Cloud IAM Cookie v1 - 3check-circle Yesdotted-circle Nodotted-circle No