Improvement

August 5, 20256 Minute Read

Secret Protection expands default pattern support and adds additional validators – August 2025

GitHub continually updates the default pattern set for secret scanning with new patterns and upgrades to existing patterns, helping ensure your repositories have comprehensive detection for different secret types.

The following new patterns were added over the past two months. Secret scanning automatically detects any secrets matching these patterns in your repositories. See the full list of supported secrets in the documentation.

ProviderTokenPartnerUserPush protection
1Password1password_service_account_tokenx
Akamaiakamai_api_credentialsx
Amazon AWSaws_api_keyxx
Apifyapify_api_tokenxxx
Apifyapify_actor_run_api_tokenxxx
Apifyapify_actor_run_proxy_passwordxxx
Apifyapify_integration_api_tokenxxx
Apifyapify_proxy_passwordxxx
Apifyapify_ui_tokenxxx
Apifyapify_webhook_dispatch_api_tokenxxx
Azureazure_app_configuration_keyxxx
Azureazure_communication_services_keyxxx
Azureazure_event_grid_key_identifiablexxx
Azureazure_maps_keyxxx
Azureazure_ml_inference_identifiable_keyxxx
Azureazure_ml_internal_service_principal_identifiable_keyx
Azureazure_web_app_bot_keyxxx
Azureazure_ai_services_keyxxx
Azureazure_anomaly_detector_ee_keyxxx
Azureazure_anomaly_detector_keyxxx
Azureazure_cognitive_services_keyxxx
Azureazure_computer_vision_keyxxx
Azureazure_content_moderator_keyxxx
Azureazure_content_safety_keyxxx
Azureazure_custom_vision_prediction_keyxxx
Azureazure_custom_vision_training_keyxxx
Azureazure_dummy_keyxxx
Azureazure_face_keyxxx
Azureazure_fluid_relay_keyxxx
Azureazure_form_recognizer_keyxxx
Azureazure_health_decision_support_keyxxx
Azureazure_health_insights_keyxxx
Azureazure_immersive_reader_keyxxx
Azureazure_internal_all_in_one_keyxxx
Azureazure_knowledge_keyxxx
Azureazure_luis_authoring_keyxxx
Azureazure_luis_keyxxx
Azureazure_metrics_advisor_keyxxx
Azureazure_mixed_reality_keyxxx
Azureazure_personalizer_keyxxx
Azureazure_qna_maker_keyxxx
Azureazure_qna_maker_v2_keyxxx
Azureazure_signalr_keyxxx
Azureazure_speech_services_keyxxx
Azureazure_speech_translation_keyxxx
Azureazure_text_analytics_keyxxx
Azureazure_text_translation_keyxxx
Azureazure_video_intelligence_keyxxx
Buildkitebuildkite_agent_access_tokenxx
Buildkitebuildkite_agent_job_tokenxx
Buildkitebuildkite_agent_registration_tokenxx
Buildkitebuildkite_cluster_queue_tokenxx
Buildkitebuildkite_cluster_tokenxx
Buildkitebuildkite_packages_registry_tokenxx
Buildkitebuildkite_packages_temporary_tokenxx
Buildkitebuildkite_portal_secretxx
Buildkitebuildkite_portal_tokenxx
Contentfulcontentful_web_tokenxxx
Elasticelastic_cloud_api_keyx
Langchainlangchain_api_personal_keyx
Langchainlangchain_api_server_keyx
LaunchDarklylaunchdarkly_access_tokenxx
Notionnotion_api_tokenxxx
Perplexityperplexity_api_keyx
Polarpolar_customer_session_tokenxxx
Polarpolar_user_session_tokenxxx
Snowflakesnowflake_programmatic_access_tokenxx
Tencenttencent_cloud_intl_access_tokenxx
Val Townval_town_api_tokenxx

The following existing patterns have been updated. Existing alerts are not affected by pattern updates.

ProviderTokenUpdate
Alibabaalibaba_cloud_access_key_idUpdated detector for increased precision
Alibabaalibaba_cloud_access_key_secretUpdated detector for increased precision
Anthropicanthropic_api_keyAdded to validity checks
Anthropicanthropic_admin_api_keyAdded to validity checks
Azureazure_devops_personal_access_tokenUpdated detector for new pattern format
Bitrisebitrise_personal_access_tokenAdded to validity checks
Contentfulcontentful_personal_access_tokenAdded to validity checks
DigitalOceandigitalocean_oauth_tokenAdded to validity checks
DigitalOceandigitalocean_personal_access_tokenAdded to validity checks
Dropboxdropbox_access_tokenAdded to validity checks
Duffelduffel_live_access_tokenAdded to validity checks
Duffelduffel_test_access_tokenAdded to validity checks
Generichttp_bearer_authentication_headerUpdated detector for increased precision
GitLabgitlab_access_tokenAdded to validity checks
Groqgroq_api_keyAdded to push protection
HashiCorpterraform_api_tokenAdded to validity checks
Herokuheroku_platform_api_oauth2_tokenAdded to push protection
OpenAIopenai_api_keyUpdated detector for increased recall
Polarpolar_access_tokenUpdated detector for new pattern format, added to push protection
Polarpolar_authorization_codeUpdated detector for new pattern format, added to push protection
Polarpolar_client_registration_tokenUpdated detector for new pattern format, added to push protection
Polarpolar_client_secretUpdated detector for new pattern format, added to push protection
Polarpolar_personal_access_tokenUpdated detector for new pattern format, added to push protection
Polarpolar_refresh_tokenUpdated detector for new pattern format, added to push protection
ReadMereadmeio_api_access_tokenAdded to validity checks
Salesforcesalesforce_oauth2_consumer_keyAdded to push protection
Salesforcesalesforce_oauth2_consumer_secretAdded to push protection
Tailscaletailscale_api_keyAdded to validity checks
Workatoworkato_developer_api_token1Added to validity checks
xAIxai_api_keyAdded to push protection

Learn more about securing your repositories with secret scanning.


  1. Includes support for regional variants: JP (Japan), SG (Singapore), EU (Europe), and US (United States) versions of the Workato Developer API Token. 

Subscribe to our developer newsletter

Discover tips, technical guides, and best practices in our biweekly newsletter just for devs.

By submitting, I agree to let GitHub and its affiliates use my information for personalized communications, targeted advertising, and campaign effectiveness. See the GitHub Privacy Statement for more details.

Secret Protection expands default pattern support and adds additional validators – August 2025 - GitHub Changelog