Supported GitLeaks Rule IDs

This document lists all secret scanning rules (by id) currently supported in the project, with a short description for each.

Rule ID Description
1password-secret-keyUncovered a possible 1Password secret key, potentially compromising access to secrets in vaults.
1password-service-account-tokenUncovered a possible 1Password service account token, potentially compromising access to secrets in vaults.
adafruit-api-keyIdentified a potential Adafruit API Key, which could lead to unauthorized access to Adafruit services and sensitive data exposure.
adobe-client-idDetected a pattern that resembles an Adobe OAuth Web Client ID, posing a risk of compromised Adobe integrations and data breaches.
adobe-client-secretDiscovered a potential Adobe Client Secret, which, if exposed, could allow unauthorized Adobe service access and data manipulation.
age-secret-keyDiscovered a potential Age encryption tool secret key, risking data decryption and unauthorized access to sensitive information.
airtable-api-keyUncovered a possible Airtable API Key, potentially compromising database access and leading to data leakage or alteration.
algolia-api-keyIdentified an Algolia API Key, which could result in unauthorized search operations and data exposure on Algolia-managed platforms.
alibaba-access-key-idDetected an Alibaba Cloud AccessKey ID, posing a risk of unauthorized cloud resource access and potential data compromise.
alibaba-secret-keyDiscovered a potential Alibaba Cloud Secret Key, potentially allowing unauthorized operations and data access within Alibaba Cloud.
asana-client-idDiscovered a potential Asana Client ID, risking unauthorized access to Asana projects and sensitive task information.
asana-client-secretIdentified an Asana Client Secret, which could lead to compromised project management integrity and unauthorized access.
atlassian-api-tokenDetected an Atlassian API token, posing a threat to project management and collaboration tool security and data confidentiality.
authress-service-client-access-keyUncovered a possible Authress Service Client Access Key, which may compromise access control services and sensitive data.
aws-access-tokenIdentified a pattern that may indicate AWS credentials, risking unauthorized cloud resource access and data breaches on AWS platforms.
azure-ad-client-secretAzure AD Client Secret
beamer-api-tokenDetected a Beamer API token, potentially compromising content management and exposing sensitive notifications and updates.
bitbucket-client-idDiscovered a potential Bitbucket Client ID, risking unauthorized repository access and potential codebase exposure.
bitbucket-client-secretDiscovered a potential Bitbucket Client Secret, posing a risk of compromised code repositories and unauthorized access.
bittrex-access-keyIdentified a Bittrex Access Key, which could lead to unauthorized access to cryptocurrency trading accounts and financial loss.
bittrex-secret-keyDetected a Bittrex Secret Key, potentially compromising cryptocurrency transactions and financial security.
cisco-meraki-api-keyCisco Meraki is a cloud-managed IT solution that provides networking, security, and device management through an easy-to-use interface.
clickhouse-cloud-api-secret-keyIdentified a pattern that may indicate clickhouse cloud API secret key, risking unauthorized clickhouse cloud api access and data breaches on ClickHouse Cloud platforms.
clojars-api-tokenUncovered a possible Clojars API token, risking unauthorized access to Clojure libraries and potential code manipulation.
cloudflare-api-keyDetected a Cloudflare API Key, potentially compromising cloud application deployments and operational security.
cloudflare-global-api-keyDetected a Cloudflare Global API Key, potentially compromising cloud application deployments and operational security.
cloudflare-origin-ca-keyDetected a Cloudflare Origin CA Key, potentially compromising cloud application deployments and operational security.
codecov-access-tokenFound a pattern resembling a Codecov Access Token, posing a risk of unauthorized access to code coverage reports and sensitive data.
cohere-api-tokenIdentified a Cohere Token, posing a risk of unauthorized access to AI services and data manipulation.
coinbase-access-tokenDetected a Coinbase Access Token, posing a risk of unauthorized access to cryptocurrency accounts and financial transactions.
confluent-access-tokenIdentified a Confluent Access Token, which could compromise access to streaming data platforms and sensitive data flow.
confluent-secret-keyFound a Confluent Secret Key, potentially risking unauthorized operations and data access within Confluent services.
contentful-delivery-api-tokenDiscovered a Contentful delivery API token, posing a risk to content management systems and data integrity.
curl-auth-headerDiscovered a potential authorization token provided in a curl command header, which could compromise the curl accessed resource.
curl-auth-userDiscovered a potential basic authorization token provided in a curl command, which could compromise the curl accessed resource.
databricks-api-tokenUncovered a Databricks API token, which may compromise big data analytics platforms and sensitive data processing.
datadog-access-tokenDetected a Datadog Access Token, potentially risking monitoring and analytics data exposure and manipulation.
defined-networking-api-tokenIdentified a Defined Networking API token, which could lead to unauthorized network operations and data breaches.
digitalocean-access-tokenFound a DigitalOcean OAuth Access Token, risking unauthorized cloud resource access and data compromise.
digitalocean-patDiscovered a DigitalOcean Personal Access Token, posing a threat to cloud infrastructure security and data privacy.
digitalocean-refresh-tokenUncovered a DigitalOcean OAuth Refresh Token, which could allow prolonged unauthorized access and resource manipulation.
discord-api-tokenDetected a Discord API key, potentially compromising communication channels and user data privacy on Discord.
discord-client-idIdentified a Discord client ID, which may lead to unauthorized integrations and data exposure in Discord applications.
discord-client-secretDiscovered a potential Discord client secret, risking compromised Discord bot integrations and data leaks.
doppler-api-tokenDiscovered a Doppler API token, posing a risk to environment and secrets management security.
droneci-access-tokenDetected a Droneci Access Token, potentially compromising continuous integration and deployment workflows.
dropbox-api-tokenIdentified a Dropbox API secret, which could lead to unauthorized file access and data breaches in Dropbox storage.
dropbox-long-lived-api-tokenFound a Dropbox long-lived API token, risking prolonged unauthorized access to cloud storage and sensitive data.
dropbox-short-lived-api-tokenDiscovered a Dropbox short-lived API token, posing a risk of temporary but potentially harmful data access and manipulation.
duffel-api-tokenUncovered a Duffel API token, which may compromise travel platform integrations and sensitive customer data.
dynatrace-api-tokenDetected a Dynatrace API token, potentially risking application performance monitoring and data exposure.
easypost-api-tokenIdentified an EasyPost API token, which could lead to unauthorized postal and shipment service access and data exposure.
easypost-test-api-tokenDetected an EasyPost test API token, risking exposure of test environments and potentially sensitive shipment data.
etsy-access-tokenFound an Etsy Access Token, potentially compromising Etsy shop management and customer data.
facebook-access-tokenDiscovered a Facebook Access Token, posing a risk of unauthorized access to Facebook accounts and personal data exposure.
facebook-page-access-tokenDiscovered a Facebook Page Access Token, posing a risk of unauthorized access to Facebook accounts and personal data exposure.
facebook-secretDiscovered a Facebook Application secret, posing a risk of unauthorized access to Facebook accounts and personal data exposure.
fastly-api-tokenUncovered a Fastly API key, which may compromise CDN and edge cloud services, leading to content delivery and security issues.
finicity-api-tokenDetected a Finicity API token, potentially risking financial data access and unauthorized financial operations.
finicity-client-secretIdentified a Finicity Client Secret, which could lead to compromised financial service integrations and data breaches.
finnhub-access-tokenFound a Finnhub Access Token, risking unauthorized access to financial market data and analytics.
flickr-access-tokenDiscovered a Flickr Access Token, posing a risk of unauthorized photo management and potential data leakage.
flutterwave-encryption-keyUncovered a Flutterwave Encryption Key, which may compromise payment processing and sensitive financial information.
flutterwave-public-keyDetected a Finicity Public Key, potentially exposing public cryptographic operations and integrations.
flutterwave-secret-keyIdentified a Flutterwave Secret Key, risking unauthorized financial transactions and data breaches.
flyio-access-tokenUncovered a Fly.io API key
frameio-api-tokenFound a Frame.io API token, potentially compromising video collaboration and project management.
freemius-secret-keyDetected a Freemius secret key, potentially exposing sensitive information.
freshbooks-access-tokenDiscovered a Freshbooks Access Token, posing a risk to accounting software access and sensitive financial data exposure.
Robility-secret-keyDetected a Robility Secret Key, risking unauthorized access to Robility services