Improvement

July 22, 20252 Minute Read

Secret scanning adds validity checks for over 40 secret detectors

Secret scanning is adding validity check support for 45 additional token types across over 30 providers.

What’s changing?

In addition to previously announced token types, you will now see validity checks for the following secret types:

ProviderPatternValidity
Block Protocolblock_protocol_api_key
Brevosendinblue_api_key
Canadian Digital Servicescds_canada_notify_api_key
Checkout.comcheckout_production_secret_key
Checkout.comcheckout_test_secret_key
CircleCIcircleci_personal_access_token
DataBentodatabento_api_key
Dopplerdoppler_audit_token
Dopplerdoppler_cli_token
Dopplerdoppler_scim_token
Dopplerdoppler_service_token
Fastlyfastly_api_token
Figmafigma_pat
FlutterWaveflutterwave_live_api_secret_key
FlutterWaveflutterwave_test_api_secret_key
Frame.ioframeio_developer_token
Frame.ioframeio_jwt
GoCardlessgocardless_live_access_token
GoCardlessgocardless_sandbox_access_token
Herokuheroku_platform_api_oauth2_token
Highnotehighnote_sk_live_key
Highnotehighnote_sk_test_key
Intercomintercom_access_token
Lichesslichess_oauth_access_token
Lichesslichess_personal_access_token
Loblob_live_api_key
Loblob_test_api_key
MapBoxmapbox_secret_access_token
MaxMindmaxmind_license_key
Mercurymercury_non_production_api_token
Mercurymercury_production_api_token
OpenRouteropenrouter_api_key
Persona Identitiespersona_production_api_key
Persona Identitiespersona_sandbox_api_key
Planning Centerplanning_center_oauth_access_token
Pulumipulumi_access_token
redirect.pizzaredirect_pizza_api_token
Replicatereplicate_api_token
Rootlyrootly_api_key
RubyGemsrubygems_api_key
Scalrscalr_api_token
SendGridsendgrid_api_key
Sindrisindri_api_key
Unkeyunkey_root_key
xAIxai_api_key
Zuplozuplo_consumer_api_key

What are validity checks?

Validity checks indicate if the leaked credentials are active and could still be exploited. If you’ve previously enabled validation checks for a given repository, GitHub will now automatically verify validity for alerts on supported token types. View the full list of supported secret types in our product documentation.

Subscribe to our developer newsletter

Discover tips, technical guides, and best practices in our biweekly newsletter just for devs.

By submitting, I agree to let GitHub and its affiliates use my information for personalized communications, targeted advertising, and campaign effectiveness. See the GitHub Privacy Statement for more details.

Secret scanning adds validity checks for over 40 secret detectors - GitHub Changelog