Secret Revocation¶
Finding an active credential is not containment. Deleting it from the current branch does not invalidate copies in Git history, logs, forks, caches, or an attacker's hands.
Kingfisher lets defenders revoke supported leaked credentials directly from the CLI. For self-revocable credentials and other provider flows that can safely identify the exact key, this removes a common incident-response dependency: locating the employee who created or leaked the credential. The responder can contain the risk even when ownership is unclear, the credential predates the current team, or the original owner has left the company.
Revocation is provider- and credential-specific, not a universal promise. Some APIs require extra captured values or permissions, and some credential formats cannot safely identify the exact key to disable. Kingfisher exposes a revoke action only when it has a bounded provider workflow. Always review the target and operational impact before running it; revocation can interrupt workloads that still depend on the credential.
Kingfisher supports direct revocation for selected built-in imported detectors and through a rule-level revocation: block in the Kingfisher rule format. The current open-source catalog includes 34 revocation-enabled rules across 15 provider families.
Kingfisher keeps reviewed operational revocation actions in crates/kingfisher-rules/data/imported-rules-capabilities.yml. This file contains no candidate detector regexes; it may add narrow operational filters and capability metadata. Every entry is joined to the pinned imported-detector catalog by upstream ID during bundle generation. Betterleaks 2.x supports revoke expressions, but Kingfisher's importer currently uses these overlay actions instead of executing those expressions.
Current built-in provider families include:
- AWS access keys and GCP service-account keys
- GitHub PAT, fine-grained PAT, OAuth, and refresh credentials
- GitLab PAT formats
- Buildkite, Cloudflare, crates.io, DigitalOcean, Doppler, Heroku, and npm credentials
- Hugging Face credentials and selected Slack, Twitch, and Vercel token formats
The capability file is the authoritative exact-ID list. Kingfisher intentionally omits actions when an upstream detector combines credential types with different revocation APIs, when required context cannot be bound safely, or when a provider lookup cannot identify the exact credential. That conservative boundary is important: a remediation shortcut should never guess which key to disable.
Examples:
kingfisher revoke --rule github-pat "ghp_xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx"
kingfisher revoke --rule aws-access-token \
--var AKID=AKIAIOSFODNN7EXAMPLE \
"wJalrXUtnFEMI/K7MDENG/bPxRfiCYEXAMPLEKEY"
Kingfisher custom rules may define these revocation types:
Httpfor a single provider API requestHttpMultiStepfor lookup-then-delete workflowsAWSfor IAM access-key revocationGCPfor service-account key revocation
Invoke a Kingfisher custom revocation rule with:
See USAGE.md for the command and RULES.md for the Kingfisher custom-rule schema.