Improvement

October 7, 20253 Minute Read

Secret Protection expands default pattern support – September 2025

GitHub continually updates the default pattern set for secret scanning with new patterns and upgrades to existing patterns, helping ensure your repositories have comprehensive detection for different secret types.

The following new patterns were added over the past two months. Secret scanning automatically detects any secrets matching these patterns in your repositories. See the full list of supported secrets.

ProviderTokenPartnerUserPush protection
Aikidoaikido_api_client_secretxx
Aikidoaikido_ci_scanning_tokenxx
Airtableairtable_api_keyx
Azureazure_quantum_keyxxx
Coherecohere_api_keyx
DeepSeekdeepseek_api_keyx
Googlegoogle_gemini_api_keyx
GuardSquareguardsquare_appsweep_api_keyxxx
GuardSquareguardsquare_cli_access_tokenxxx
GuardSquareguardsquare_maven_tokenxx
hCaptchahcaptcha_siteverify_secretxx
Mistralmistral_ai_api_keyx
Openweatheropenweather_api_keyx
Salesforcesalesforce_access_tokenxx
Temporaltemporal_cloud_api_keyxx
Tencenttencent_wechat_pay_tokenx
Weights & Biaseswandb_api_keyx
ZenHubzenhub_personal_api_keyxx

The following existing patterns have been added to push protection.

ProviderToken
1Password1password_service_account_token
Airtableairtable_personal_access_token
Azureazure_communication_services_connection_string
Azureazure_iot_device_connection_string
Azureazure_iot_hub_connection_string
Azureazure_iot_provisioning_connection_string
Azureazure_management_certificate
Azureazure_sas_token
Azureazure_signalr_connection_string
Buildkitebuildkite_agent_access_token
Buildkitebuildkite_agent_job_token
Buildkitebuildkite_agent_registration_token
Buildkitebuildkite_cluster_queue_token
Buildkitebuildkite_cluster_token
Buildkitebuildkite_packages_registry_token
Buildkitebuildkite_packages_temporary_token
Buildkitebuildkite_portal_secret
Buildkitebuildkite_portal_token
Dropboxdropbox_access_token
Facebookfacebook_access_token
Frameioframeio_developer_token
Hugging Facehf_org_api_key
Langchainlangchain_api_personal_key
LinkedInlinkedin_client_secret
Mailchimpmailchimp_api_key
Messagebirdmessagebird_api_key
Notionnotion_integration_token
Oculusoculus_access_token
Pangeapangea_token
Rampramp_client_id
Rampramp_client_secret
Salesforcesalesforce_refresh_token
Shipposhippo_test_api_token
Shopifyshopify_merchant_token
Slackslack_incoming_webhook_url
Snowflakesnowflake_programmatic_access_token
SourceGraphsourcegraph_dotcom_user_gateway
SourceGraphsourcegraph_license_key_token
Stripestripe_live_restricted_key
Stripestripe_test_restricted_key
Valval_town_api_token
Yandexyandex_cloud_iam_cookie
Yandexyandex_cloud_iam_token
Yandexyandex_predictor_api_key
Yandexyandex_translate_api_key

Learn more about securing your repositories with secret scanning.

Subscribe to our developer newsletter

Discover tips, technical guides, and best practices in our biweekly newsletter just for devs.

By submitting, I agree to let GitHub and its affiliates use my information for personalized communications, targeted advertising, and campaign effectiveness. See the GitHub Privacy Statement for more details.

Secret Protection expands default pattern support – September 2025 - GitHub Changelog