Skip to content

OPEN SOURCE SECURITY · BUILT BY MONGODB

Find the secret.
Understand the risk.

Find exposed credentials. Validate what’s live. Revoke supported secrets — from the CLI, Rust, or Python. All open source.

Rust library →   ·   Python SDK →

Credential revocation, free and open source. Among the open-source tools in our comparison, Kingfisher and Betterleaks 2.0 include built-in revocation for supported credentials, with no enterprise subscription required.

See the comparison
◈   kingfisherILLUSTRATIVE REPORT
Exposure overviewScan complete
12Findings
3Active credentials
4Providers
DETECTED CREDENTIALVALIDATION
GitHubPersonal access token● Active
AWSAccess key● Active
MongoDBConnection string○ Not attempted
Prioritize findings. Explore their impact.
ONE CONNECTED WORKFLOW
  1. Detect
  2. Validate
  3. Map access
  4. Triage
  5. Revoke
See how it works

YOUR INVESTIGATION STARTS HERE

Less noise.
More clarity.

Explore what Kingfisher detects, then turn your scan results into a focused response.

INVESTIGATE & TRIAGE

See the whole story
behind a finding.

Bring your reports together. Filter findings, identify active credentials, and explore blast radius when your Kingfisher report includes access-map data.

KingfisherSARIFGitleaksTruffleHog
Viewer guide & import support
EXPLORE DETECTION COVERAGE

Know exactly
what you can find.

Browse the built-in catalog from Betterleaks and Veles. Search by provider and compare confidence, live validation, and direct revocation support.

github-patGitHub
aws-access-tokenAWS
mongodb-connection-stringMongoDB
Build your own custom rules

FROM DISCOVERY TO RESPONSE

Go beyond the match.

01 / DISCOVER

Scan across your estate.

Find credentials in files, Git history, cloud storage, containers, and collaboration platforms.

Explore integrations →
02 / UNDERSTAND

Verify the impact.

Check credentials against provider APIs. Map identities, permissions, and accessible resources with blast-radius analysis.

Explore access mapping →
03 / RESPOND

Move toward containment.

Investigate findings visually and revoke supported credentials through provider-specific CLI workflows.

See revocation support →

EMBED THE SCANNER

Use Kingfisher
from Rust.

Add kingfisher-scanner = "1.2.0" and anyhow = "1" to your Cargo dependencies. Load the bundled rules once, then reuse the scanner to inspect bytes or files in process. Enable the validation feature for live credential validation and rule-driven revocation with kingfisher_scanner::Revoker.

Rust library guide →

Validation example · Revocation example

RUST QUICK STARTCRATES.IO
use std::sync::Arc;
use kingfisher_scanner::{get_builtin_rules, RulesDatabase, Scanner};

fn main() -> anyhow::Result<()> {
    let rules = get_builtin_rules(None)?;
    let database = Arc::new(RulesDatabase::from_rule_collection(rules)?);
    let scanner = Scanner::new(database);
    let findings = scanner.scan_bytes(b"application config")?;
    println!("{} findings", findings.len());
    Ok(())
}
Setup, options, and runnable examples

EMBED THE SAME RUST ENGINE

Use Kingfisher
from Python.

Install kingfisher-secret-scanner and import kingfisher_sdk. Scan text, bytes, or files in process, then validate findings or explicitly revoke supported credentials with Validator and Revoker. No CLI subprocess is needed.

Python SDK guide →

Runnable Python examples

PYTHON QUICK STARTPYPI · PYTHON 3.10+
# Install the native SDK
uv add kingfisher-secret-scanner

# Scan in your Python application
from kingfisher_sdk import Scanner

scanner = Scanner()
findings = scanner.scan("application config")
print(f"{len(findings)} findings")
Setup, validation, and revocation

START WITH A SCAN

Your next step
takes one command.

Install Kingfisher and bring secret detection into your local development or CI workflow.

All installation options →
TERMINALHOMEBREW
# Install Kingfisher
brew install kingfisher

# Scan your current directory
kingfisher scan . --view-report
Follow the quick start
Kingfisher   /   Built by MongoDBExplore the source on GitHub ↗