Skip to main content

Esta versión de GitHub Enterprise Server se discontinuó el 2026-04-23. No se realizarán lanzamientos de patch, ni siquiera para problemas de seguridad críticos. Para obtener rendimiento mejorado, seguridad mejorada y nuevas características, actualice a la versión más reciente de GitHub Enterprise Server. Para obtener ayuda con la actualización, póngase en contacto con el soporte técnico de GitHub Enterprise.

Patrones de análisis de secretos admitidos

Listas de los secretos admitidos y los asociados con los que trabaja GitHub para evitar el uso fraudulento de secretos que se confirmaron por accidente.

¿Quién puede utilizar esta característica?

Secret scanning está disponible para los tipos de repositorio siguientes:

  • Repositorios públicos: Secret scanning se ejecuta automáticamente y sin coste.
  • Repositorios privados e internos de la organización: disponibles con GitHub Advanced Security habilitados en GitHub Team o GitHub Enterprise Cloud.
  • Repositorios propiedad del usuario: disponibles en GitHub Enterprise Cloud con Enterprise Managed Users. Disponible en GitHub Enterprise Server cuando la empresa tiene GitHub Advanced Security habilitado.

About secret scanning patterns

There are two types of secret scanning alerts:

  • Secret scanning alerts: Reported to users in the Security tab of the repository, when a supported secret is detected in the repository.
  • Push protection alerts: Reported to users in the Security tab of the repository, when a contributor bypasses push protection.

For in-depth information about each alert type, see About secret scanning alerts.

For details about all the supported patterns, see the Supported secrets section below.

If you use the REST API for secret scanning, you can use the Secret type to report on secrets from specific issuers. For more information, see REST API endpoints for secret scanning.

If you believe that secret scanning should have detected a secret committed to your repository, and it has not, you first need to check that GitHub supports your secret. For more information, refer to the following sections. For more advanced troubleshooting information, see Secret scanning detection scope.

Supported secrets

The tables list the secrets supported by secret scanning for each secret type. Information in the tables may include this data:

  • Provider: Name of the token provider.
  • Secret scanning alert: Token for which leaks are reported to users on GitHub.
    • Applies to private repositories where GitHub Advanced Security and secret scanning are enabled.
    • Includes high confidence tokens, which relate to supported patterns and specified custom patterns, as well as non-provider tokens such as private keys, which often result in false positives.
  • Push protection: Token for which leaks are reported to users on GitHub. Applies to repositories with secret scanning and push protection enabled.
  • Validity check: Token for which a validity check is implemented. Currently only applies to GitHub tokens.
  • Metadata check: Token for which extended metadata is available, providing additional context about the detected secret.
  • Base64: Token for which Base64-encoded versions are supported.

Non-provider patterns

Nota:

The detection of non-provider patterns is currently in beta and subject to change.

Precision levels are estimated based on the pattern type's typical false positive rates.

ProviderTokenDescriptionPrecision
Generichttp_basic_authentication_headerHTTP Basic Authentication credentials in request headersMedium
Generichttp_bearer_authentication_headerHTTP Bearer tokens used for API authenticationMedium
Genericmongodb_connection_stringConnection strings for MongoDB databases containing credentialsHigh
Genericmysql_connection_urlConnection strings for MySQL databases containing credentialsHigh
Genericopenssh_private_keyOpenSSH format private keys used for SSH authenticationHigh
Genericpgp_private_keyPGP (Pretty Good Privacy) private keys used for encryption and signingHigh
Genericpostgres_connection_stringConnection strings for PostgreSQL databases containing credentialsHigh
Genericrsa_private_keyRSA private keys used for cryptographic operationsHigh

Nota:

Validity checks are not supported for non-provider patterns.

High confidence patterns

ProviderTokenSecret scanning alertPush protectionValidity checkBase64
Adafruitadafruit_io_key✓✓✗✗
Adobeadobe_client_secret✓✓✗✗
Adobeadobe_device_token✓✓✗✗
Adobeadobe_pac_token✓✓✗✗
Adobeadobe_refresh_token✓✓✗✗
Adobeadobe_service_token✓✓✗✗
Adobeadobe_short_lived_access_token✓✓✗✗
Aivenaiven_auth_token✓✓✗✗
Aivenaiven_service_password✓✓✗✗
Alibabaalibaba_cloud_access_key_id
alibaba_cloud_access_key_secret
✓✓✗✗
Amazon AWSaws_access_key_id
aws_secret_access_key
✓✓✗✗
Amazon AWSaws_secret_access_key
aws_session_token
aws_temporary_access_key_id
✓✓✗✗
Anthropicanthropic_api_key✓✓✗✗
Anthropicanthropic_session_id✓✓✗✗
Asanaasana_legacy_format_personal_access_token✓✗✗✗
Asanaasana_personal_access_token✓✓✗✗
Atlassianatlassian_api_token✓✗✗✗
Atlassianatlassian_api_token✓✓✗✗
Atlassianatlassian_jwt✓✗✗✗
Authressauthress_service_client_access_key✓✓✗✗
Azureazure_active_directory_application_secret✓✓✗✗
Azureazure_active_directory_application_secret✓✓✗✗
Azureazure_active_directory_application_secret✗✗✗✗
Azureazure_active_directory_user_credential✓✗✗✗
Azureazure_apim_direct_management_key✓✓✗✗
Azureazure_apim_gateway_key✓✓✗✗
Azureazure_apim_repository_key✓✓✗✗
Azureazure_apim_subscription_key✓✓✗✗
Azureazure_app_configuration_connection_string✓✗✗✗
Azureazure_batch_key_identifiable✓✓✗✗
Azureazure_cache_for_redis_access_key✓✓✗✗
Azureazure_communication_services_connection_string✓✗✗✗
Azureazure_container_registry_key_identifiable✓✓✗✗
Azureazure_cosmosdb_key_identifiable✓✓✗✗
Azureazure_devops_personal_access_token✓✓✗✗
Azureazure_event_hub_key_identifiable✓✓✗✗
Azureazure_function_key✓✓✗✗
Azureazure_iot_device_connection_string✓✗✗✗
Azureazure_iot_device_key✓✓✗✗
Azureazure_iot_device_provisioning_key✓✓✗✗
Azureazure_iot_hub_connection_string✓✗✗✗
Azureazure_iot_hub_key✓✓✗✗
Azureazure_iot_provisioning_connection_string✓✗✗✗
Azureazure_management_certificate✓✗✗✗
Azureazure_ml_web_service_classic_identifiable_key✓✓✗✗
Azureazure_relay_key_identifiable✓✓✗✗
Azureazure_sas_token✓✗✗✗
Azureazure_search_admin_key✓✓✗✗
Azureazure_search_query_key✓✓✗✗
Azureazure_service_bus_identifiable✓✓✗✗
Azureazure_signalr_connection_string✓✗✗✗
Azureazure_sql_connection_string✓✗✗✗
Azureazure_sql_password✓✓✗✗
Azureazure_storage_account_key✓✗✗✗
Azureazure_storage_account_key✓✓✗✗
Azureazure_web_pub_sub_connection_string✓✗✗✗
Azuremicrosoft_corporate_network_user_credential✓✗✗✗
Baidubaiducloud_api_accesskey✓✓✗✗
Beamerbeamer_api_key✓✗✗✗
Bitbucketbitbucket_server_personal_access_token✓✓✗✗
Canadian Digital Servicecds_canada_notify_api_key✓✓✗✗
Canvacanva_app_secret✓✓✗✗
Canvacanva_connect_api_secret✓✓✗✗
Canvacanva_secret✓✓✗✗
Cashfreecashfree_api_key✓✓✗✗
Checkout.comcheckout_production_secret_key✓✗✗✗
Checkout.comcheckout_production_secret_key✓✓✗✗
Checkout.comcheckout_test_secret_key✓✗✗✗
Checkout.comcheckout_test_secret_key✓✗✗✗
Chief Toolschief_tools_token✓✓✗✗
CircleCIcircleci_bot_access_token✓✓✗✗
CircleCIcircleci_personal_access_token✓✓✗✗
CircleCIcircleci_project_access_token✓✓✗✗
CircleCIcircleci_release_integration_token✓✓✗✗
Clojarsclojars_deploy_token✓✓✗✗
CloudBeescodeship_credential✗✗✗✗
Contentfulcontentful_personal_access_token✓✗✗✗
Contributed Systemscontributed_systems_credentials✗✗✗✗
crates.iocratesio_api_token✓✓✗✗
Databricksdatabricks_access_token✓✓✗✗
Datadogdatadog_api_key✗✗✗✗
Datadogdatadog_app_key✗✗✗✗
Defined Networkingdefined_networking_nebula_api_key✓✓✗✗
DevCycledevcycle_client_api_key✓✓✗✗
DevCycledevcycle_mobile_api_key✓✓✗✗
DevCycledevcycle_server_api_key✓✓✗✗
DigitalOceandigitalocean_oauth_token✓✓✗✗
DigitalOceandigitalocean_personal_access_token✓✓✗✗
DigitalOceandigitalocean_refresh_token✓✓✗✗
DigitalOceandigitalocean_system_token✓✓✗✗
Discorddiscord_bot_token✓✓✗✗
Discorddiscord_bot_token✓✓✗✗
Dockerdocker_personal_access_token✓✓✗✗
Dopplerdoppler_audit_token✓✓✗✗
Dopplerdoppler_cli_token✓✓✗✗
Dopplerdoppler_personal_token✓✓✗✗
Dopplerdoppler_scim_token✓✓✗✗
Dopplerdoppler_service_account_token✓✓✗✗
Dopplerdoppler_service_token✓✓✗✗
Dropboxdropbox_access_token✓✗✗✗
Dropboxdropbox_short_lived_access_token✓✓✗✗
Duffelduffel_live_access_token✓✓✗✗
Duffelduffel_test_access_token✓✗✗✗
Dynatracedynatrace_api_token✓✗✗✗
Dynatracedynatrace_internal_token✓✗✗✗
EasyPosteasypost_production_api_key✓✓✗✗
EasyPosteasypost_test_api_key✓✗✗✗
eBayebay_production_client_id
ebay_production_client_secret
✓✗✗✗
eBayebay_sandbox_client_id
ebay_sandbox_client_secret
✓✗✗✗
Facebookfacebook_access_token✓✗✗✗
Fastlyfastly_api_token✓✗✗✗
Fastlyfastly_api_token✓✗✗✗
Figmafigma_pat✓✓✗✗
Finicityfinicity_app_key✓✗✗✗
Firebasefirebase_cloud_messaging_server_key✓✗✗✗
Flutterwaveflutterwave_live_api_secret_key✓✓✗✗
Flutterwaveflutterwave_test_api_secret_key✓✗✗✗
Frame.ioframeio_developer_token✓✗✗✗
Frame.ioframeio_jwt✓✗✗✗
FullStoryfullstory_api_key✓✓✗✗
FullStoryfullstory_api_key✓✗✗✗
GitHubgithub_app_installation_access_token✓✓✓✗
GitHubgithub_app_installation_access_token✓✓✓✗
GitHubgithub_oauth_access_token✓✓✓✗
GitHubgithub_oauth_access_token✓✓✓✗
GitHubgithub_personal_access_token✓✗✓✗
GitHubgithub_personal_access_token✓✓✓✗
GitHubgithub_personal_access_token✓✓✓✗
GitHubgithub_refresh_token✓✓✓✗
GitHubgithub_ssh_private_key✓✓✓✗
GitHubgithub_test_token✓✗✗✗
GitHub Secret Scanningsecret_scanning_sample_token✓✓✗✗
GitLabgitlab_access_token✓✗✗✗
GoCardlessgocardless_live_access_token✓✗✗✗
GoCardlessgocardless_sandbox_access_token✓✗✗✗
Googlegoogle_api_key✓✗✗✗
Googlegoogle_cloud_private_key_id✗✗✗✗
Googlegoogle_cloud_service_account_credentials✓✓✗✗
Googlegoogle_cloud_storage_access_key_secret
google_cloud_storage_service_account_access_key_id
✓✓✗✗
Googlegoogle_cloud_storage_access_key_secret
google_cloud_storage_user_access_key_id
✓✓✗✗
Googlegoogle_oauth_access_token✓✗✗✗
Googlegoogle_oauth_client_id
google_oauth_client_secret
✓✓✗✗
Googlegoogle_oauth_refresh_token✓✗✗✗
Grafanagrafana_cloud_api_key✓✓✗✗
Grafanagrafana_cloud_api_token✓✓✗✗
Grafanagrafana_project_api_key✓✓✗✗
Grafanagrafana_project_service_account_token✓✓✗✗
HashiCorphashicorp_vault_batch_token✓✗✗✗
HashiCorphashicorp_vault_batch_token✓✓✗✗
HashiCorphashicorp_vault_root_service_token✓✓✗✗
HashiCorphashicorp_vault_service_token✓✓✗✗
HashiCorphashicorp_vault_service_token✓✗✗✗
HashiCorpterraform_api_token✓✓✗✗
Highnotehighnote_rk_live_key✓✓✗✗
Highnotehighnote_rk_test_key✓✓✗✗
Highnotehighnote_sk_live_key✓✓✗✗
Highnotehighnote_sk_test_key✓✓✗✗
HOPhop_bearer✓✓✗✗
HOPhop_pat✓✓✗✗
HOPhop_ptk✓✓✗✗
Hubspothubspot_api_key✗✗✗✗
Hubspothubspot_api_key✓✗✗✗
Hubspothubspot_api_key✓✓✗✗
Hubspothubspot_personal_access_key✓✓✗✗
Hubspothubspot_smtp_credential✗✗✗✗
IBMibm_cloud_iam_key✓✗✗✗
IBMibm_softlayer_api_key✓✗✗✗
Intercomintercom_access_token✓✓✗✗
Ionicionic_personal_access_token✓✗✗✗
Ionicionic_personal_access_token✓✓✗✗
Ionicionic_refresh_token✓✓✗✗
Ionicionic_refresh_token✓✗✗✗
JFrogjfrog_platform_access_token✓✓✗✗
JFrogjfrog_platform_api_key✓✓✗✗
JFrogjfrog_platform_reference_token✓✓✗✗
Lightspeedlightspeed_xs_pat✓✓✗✗
Linearlinear_api_key✓✓✗✗
Linearlinear_oauth_access_token✓✓✗✗
Loblob_live_api_key✓✗✗✗
Loblob_test_api_key✓✗✗✗
Localstacklocalstack_api_key✓✓✗✗
LogicMonitorlogicmonitor_bearer_token✓✓✗✗
LogicMonitorlogicmonitor_lmv1_access_key✓✓✗✗
Login with Amazonamazon_oauth_client_id
amazon_oauth_client_secret
amazon_oauth_client_secret
✓✓✗✗
Mailchimpmailchimp_api_key✓✗✗✗
Mailchimpmandrill_api_key✗✗✗✗
Mailgunmailgun_api_key✓✗✗✗
Mailgunmailgun_api_key✓✗✗✗
Mailgunmailgun_smtp_credential✗✗✗✗
Mapboxmapbox_secret_access_token✓✗✗✗
MaxMindmaxmind_license_key✓✓✗✗
Mercurymercury_non_production_api_token✓✓✗✗
Mercurymercury_production_api_token✓✓✗✗
Mergifymergify_application_key✓✓✗✗
MessageBirdmessagebird_api_key✓✗✗✗
Midtransmidtrans_production_server_key✓✓✗✗
Midtransmidtrans_sandbox_server_key✓✗✗✗
New Relicnew_relic_insights_query_key✓✓✗✗
New Relicnew_relic_license_key✓✗✗✗
New Relicnew_relic_personal_api_key✓✓✗✗
New Relicnew_relic_rest_api_key✓✓✗✗
Notionnotion_integration_token✓✗✗✗
Notionnotion_oauth_client_secret✓✗✗✗
npmnpm_access_token✓✓✗✗
npmnpm_access_token✓✗✗✗
npmnpm_access_token✗✗✗✗
NuGetnuget_api_key✓✓✗✗
Octopus Deployoctopus_deploy_api_key✓✗✗✗
Oculusoculus_access_token✓✗✗✗
OneChronosonechronos_api_key✓✓✗✗
OneChronosonechronos_eb_api_key✓✓✗✗
OneChronosonechronos_eb_encryption_key✓✓✗✗
OneChronosonechronos_oauth_token✓✓✗✗
OneChronosonechronos_refresh_token✓✓✗✗
Onfidoonfido_live_api_token✓✓✗✗
Onfidoonfido_sandbox_api_token✓✗✗✗
OpenAIopenai_api_key✓✓✗✗
OpenAIopenai_api_key✓✗✗✗
Orbitorbit_api_token✓✗✗✗
PagerDutypagerduty_oauth_secret✓✓✗✗
PagerDutypagerduty_oauth_token✓✓✗✗
Palantirpalantir_jwt✓✓✗✗
Persona Identitiespersona_production_api_key✓✓✗✗
Persona Identitiespersona_sandbox_api_key✓✓✗✗
Pinterestpinterest_access_token✓✓✗✗
Pinterestpinterest_refresh_token✓✓✗✗
PlanetScaleplanetscale_database_password✓✓✗✗
PlanetScaleplanetscale_oauth_token✓✓✗✗
PlanetScaleplanetscale_service_token✓✓✗✗
Plivoplivo_auth_id
plivo_auth_token
✓✓✗✗
Postmanpostman_api_key✓✓✗✗
Postmanpostman_collection_key✓✓✗✗
Prefectprefect_server_api_key✓✓✗✗
Prefectprefect_user_api_key✓✓✗✗
Proctorioproctorio_consumer_key✓✗✗✗
Proctorioproctorio_linkage_key✓✗✗✗
Proctorioproctorio_registration_key✓✗✗✗
Proctorioproctorio_secret_key✓✓✗✗
Proctorioproctorio_secret_key✓✗✗✗
Pulumipulumi_access_token✓✗✗✗
PyPIpypi_api_token✓✗✗✗
ReadMereadmeio_api_access_token✓✓✗✗
redirect.pizzaredirect_pizza_api_token✓✓✗✗
Replicatereplicate_api_token✗✗✗✗
Rootlyrootly_api_key✓✓✗✗
RubyGemsrubygems_api_key✓✗✗✗
Samsarasamsara_api_token✓✓✗✗
Samsarasamsara_oauth_access_token✓✓✗✗
Segmentsegment_public_api_token✓✓✗✗
SendGridsendgrid_api_key✓✓✗✗
Sendinbluesendinblue_api_key✓✓✗✗
Sendinbluesendinblue_smtp_key✓✓✗✗
Shipposhippo_live_api_token✓✓✗✗
Shipposhippo_test_api_token✓✗✗✗
Shopifyshopify_access_token✓✓✗✗
Shopifyshopify_app_client_credentials✓✗✗✗
Shopifyshopify_app_client_secret✓✗✗✗
Shopifyshopify_app_shared_secret✓✓✗✗
Shopifyshopify_custom_app_access_token✓✗✗✗
Shopifyshopify_marketplace_token✓✗✗✗
Shopifyshopify_merchant_token✓✗✗✗
Shopifyshopify_partner_api_token✓✗✗✗
Shopifyshopify_private_app_password✓✗✗✗
Slackslack_api_token✓✓✗✗
Slackslack_api_token✓✗✗✗
Slackslack_api_token✓✓✗✗
Slackslack_incoming_webhook_url✓✗✗✗
Slackslack_workflow_webhook_url✓✗✗✗
Squaresquare_access_token✓✗✗✗
Squaresquare_access_token✓✗✗✗
Squaresquare_access_token✓✗✗✗
Squaresquare_production_application_secret✓✗✗✗
Squaresquare_sandbox_application_secret✓✗✗✗
SSLMatesslmate_api_key✓✗✗✗
SSLMatesslmate_api_key✓✗✗✗
SSLMatesslmate_cluster_secret✓✗✗✗
Stripestripe_api_key✓✓✗✗
Stripestripe_legacy_api_key✓✗✗✗
Stripestripe_live_restricted_key✓✗✗✗
Stripestripe_test_restricted_key✓✗✗✗
Stripestripe_test_secret_key✓✗✗✗
Stripestripe_webhook_signing_secret✓✗✗✗
Supabasesupabase_service_key✓✗✗✗
Supabasesupabase_service_key✓✗✗✗
Tableautableau_personal_access_token✓✗✗✗
Telegramtelegram_bot_token✓✗✗✗
Telnyxtelnyx_api_v2_key✓✓✗✗
Tencenttencent_cloud_secret_id✓✓✗✗
Tencenttencent_wechat_api_app_id✓✗✗✗
Twiliotwilio_access_token✓✓✗✗
Twiliotwilio_account_sid✓✓✗✗
Twiliotwilio_api_key✓✓✗✗
Typeformtypeform_personal_access_token✓✓✗✗
Uniwisewiseflow_api_key✓✓✗✗
Unkeyunkey_root_key✓✗✗✗
VolcEnginevolcengine_access_key_id✓✓✗✗
Wakatimewakatime_api_key✓✓✗✗
Wakatimewakatime_app_secret✓✓✗✗
Wakatimewakatime_oauth_access_token✓✓✗✗
Wakatimewakatime_oauth_refresh_token✓✓✗✗
Workatoworkato_developer_api_token✓✓✗✗
Workatoworkato_developer_api_token✓✓✗✗
Workatoworkato_developer_api_token✓✓✗✗
Workatoworkato_developer_api_token✓✓✗✗
WorkOSworkos_production_api_key✓✓✗✗
WorkOSworkos_production_api_key✗✗✗✗
WorkOSworkos_staging_api_key✓✗✗✗
WorkOSworkos_staging_api_key✗✗✗✗
Yandexyandex_cloud_api_key✓✗✗✗
Yandexyandex_cloud_iam_access_secret✓✗✗✗
Yandexyandex_cloud_iam_cookie✓✗✗✗
Yandexyandex_cloud_iam_token✓✗✗✗
Yandexyandex_cloud_smartcaptcha_server_key✓✓✗✗
Yandexyandex_dictionary_api_key✓✗✗✗
Yandexyandex_passport_oauth_token✓✓✗✗
Yandexyandex_predictor_api_key✓✗✗✗
Yandexyandex_translate_api_key✓✗✗✗
Zuplozuplo_consumer_api_key✓✓✗✗

Token versions

Service providers update the patterns used to generate tokens periodically and may support more than one version of a token. Push protection only supports the most recent token versions that secret scanning can identify with confidence. This avoids push protection blocking commits unnecessarily when a result may be a false positive, which is more likely to happen with legacy tokens.

Further reading