See the whole story
behind a finding.
Bring your reports together. Filter findings, identify active credentials, and explore blast radius when your Kingfisher report includes access-map data.
OPEN SOURCE SECURITY · BUILT BY MONGODB
Find exposed credentials. Validate what’s live. Revoke supported secrets — from the CLI, Rust, or Python. All open source.
Credential revocation, free and open source. Among the open-source tools in our comparison, Kingfisher and Betterleaks 2.0 include built-in revocation for supported credentials, with no enterprise subscription required.
See the comparisonYOUR INVESTIGATION STARTS HERE
Explore what Kingfisher detects, then turn your scan results into a focused response.
Bring your reports together. Filter findings, identify active credentials, and explore blast radius when your Kingfisher report includes access-map data.
Browse the built-in catalog from Betterleaks and Veles. Search by provider and compare confidence, live validation, and direct revocation support.
github-patGitHubaws-access-tokenAWSmongodb-connection-stringMongoDBFROM DISCOVERY TO RESPONSE
Find credentials in files, Git history, cloud storage, containers, and collaboration platforms.
Explore integrations →Check credentials against provider APIs. Map identities, permissions, and accessible resources with blast-radius analysis.
Explore access mapping →Investigate findings visually and revoke supported credentials through provider-specific CLI workflows.
See revocation support →EMBED THE SCANNER
Add kingfisher-scanner = "1.2.0" and anyhow = "1" to your Cargo dependencies. Load the bundled rules once, then reuse the scanner to inspect bytes or files in process. Enable the validation feature for live credential validation and rule-driven revocation with kingfisher_scanner::Revoker.
use std::sync::Arc;
use kingfisher_scanner::{get_builtin_rules, RulesDatabase, Scanner};
fn main() -> anyhow::Result<()> {
let rules = get_builtin_rules(None)?;
let database = Arc::new(RulesDatabase::from_rule_collection(rules)?);
let scanner = Scanner::new(database);
let findings = scanner.scan_bytes(b"application config")?;
println!("{} findings", findings.len());
Ok(())
} Setup, options, and runnable examples EMBED THE SAME RUST ENGINE
Install kingfisher-secret-scanner and import kingfisher_sdk. Scan text, bytes, or files in process, then validate findings or explicitly revoke supported credentials with Validator and Revoker. No CLI subprocess is needed.
# Install the native SDK
uv add kingfisher-secret-scanner
# Scan in your Python application
from kingfisher_sdk import Scanner
scanner = Scanner()
findings = scanner.scan("application config")
print(f"{len(findings)} findings") Setup, validation, and revocation START WITH A SCAN
Install Kingfisher and bring secret detection into your local development or CI workflow.
All installation options →# Install Kingfisher
brew install kingfisher
# Scan your current directory
kingfisher scan . --view-reportFollow the quick start