Skip to content

Built-in Rules

Kingfisher embeds 483 rules from the Betterleaks and Veles sources. Of these, 244 include validation and 34 support direct revocation. The catalog includes 46 hidden component/helper rules used to assemble composite credentials.

Yes means the operation is embedded in the current build. None means the rule detects findings but does not provide that operation.

Search

Filter by catalog, rule name, rule ID, confidence, validation, or revocation support.

Catalog Rule Name Rule ID Confidence Validation Revocation
Betterleaks Uncovered a possible 1Password secret key, potentially compromising access to secrets in vaults. betterleaks.1password-secret-key High None None
Betterleaks Uncovered a possible 1Password service account token, potentially compromising access to secrets in vaults. betterleaks.1password-service-account-token High Yes None
Betterleaks AbuseIPDB API key, which may allow access to IP reputation data and abuse-reporting APIs. betterleaks.abuseipdb-api-key.1 High Yes None
Betterleaks Identified a potential Adafruit API Key, which could lead to unauthorized access to Adafruit services and sensitive data exposure. betterleaks.adafruit-api-key High None None
Betterleaks Detected a pattern that resembles an Adobe OAuth Web Client ID, posing a risk of compromised Adobe integrations and data breaches. betterleaks.adobe-client-id High None None
Betterleaks Discovered a potential Adobe Client Secret, which, if exposed, could allow unauthorized Adobe service access and data manipulation. betterleaks.adobe-client-secret High None None
Betterleaks Discovered a potential Age encryption tool secret key, risking data decryption and unauthorized access to sensitive information. betterleaks.age-secret-key High None None
Betterleaks Detected an Aikido CI token, which may allow unauthorized CI scan integration activity in Aikido. betterleaks.aikido-ci-token High None None
Betterleaks Detected an Aikido client ID, used as a component of the aikido-client-secret composite rule. (helper) betterleaks.aikido-client-id High None None
Betterleaks Detected an Aikido client secret, which may allow unauthorized access to Aikido APIs when paired with a client ID. betterleaks.aikido-client-secret High None None
Betterleaks Uncovered a possible Airtable API Key, potentially compromising database access and leading to data leakage or alteration. betterleaks.airtable-api-key High None None
Betterleaks Detected an Airtable OAuth token, which may allow unauthorized access to Airtable resources granted to an OAuth integration. betterleaks.airtable-oauth-token High Yes None
Betterleaks Uncovered a possible Airtable Personal AccessToken, potentially compromising database access and leading to data leakage or alteration. betterleaks.airtable-personnal-access-token High Yes None
Betterleaks Detected an Aiven authentication token, which may expose Aiven projects and services. betterleaks.aiven-auth-token High Yes None
Betterleaks Identified an Algolia API Key, which could result in unauthorized search operations and data exposure on Algolia-managed platforms. betterleaks.algolia-api-key High Yes None
Betterleaks Detected an Algolia application ID, used as a component of the algolia-api-key composite rule. (helper) betterleaks.algolia-application-id High None None
Betterleaks Detected an Alibaba Cloud AccessKey ID, posing a risk of unauthorized cloud resource access and potential data compromise. (helper) betterleaks.alibaba-access-key-id High None None
Betterleaks Discovered a potential Alibaba Cloud Secret Key, potentially allowing unauthorized operations and data access within Alibaba Cloud. betterleaks.alibaba-secret-key High Yes None
Betterleaks Detected an Alibaba Cloud STS AccessKey ID, used as a component of the alibaba-sts-access-key-secret composite rule. (helper) betterleaks.alibaba-sts-access-key-id High None None
Betterleaks Detected an Alibaba Cloud STS AccessKey secret, which may allow temporary Alibaba Cloud API access when paired with an STS AccessKey ID and security token. betterleaks.alibaba-sts-access-key-secret High Yes None
Betterleaks Detected an Alibaba Cloud STS security token, used as a component of the alibaba-sts-access-key-secret composite rule. (helper) betterleaks.alibaba-sts-security-token High None None
Betterleaks Detected an Amplitude secret key, which may allow unauthorized event ingestion or access to Amplitude API functionality. betterleaks.amplitude-secret-key Medium Yes None
Betterleaks Detected an Anthropic Admin API Key, risking unauthorized access to administrative functions and sensitive AI model configurations. betterleaks.anthropic-admin-api-key High Yes None
Betterleaks Identified an Anthropic API Key, which may compromise AI assistant integrations and expose sensitive data to unauthorized access. betterleaks.anthropic-api-key High Yes None
Betterleaks Detected an Apify API token, which may expose actors, tasks, and stored data. betterleaks.apify-api-token High Yes None
Betterleaks Apollo.io API key, which may allow access to sales intelligence and engagement data. betterleaks.apollo-api-key.1 Medium Yes None
Betterleaks Detected an Artifactory api key, posing a risk unauthorized access to the central repository. betterleaks.artifactory-api-key High Yes None
Betterleaks Detected a JFrog Artifactory host, used as a component of Artifactory token validation. (helper) betterleaks.artifactory-jfrog-url High None None
Betterleaks Detected an Artifactory reference token, posing a risk of impersonation and unauthorized access to the central repository. betterleaks.artifactory-reference-token High Yes None
Betterleaks Detected an Asaas API token, which may expose payment and customer data. betterleaks.asaas-api-token High Yes None
Betterleaks Discovered a potential Asana Client ID, risking unauthorized access to Asana projects and sensitive task information. betterleaks.asana-client-id High None None
Betterleaks Identified an Asana Client Secret, which could lead to compromised project management integrity and unauthorized access. betterleaks.asana-client-secret High None None
Betterleaks Detected an AssemblyAI API Key, which may expose speech-to-text services and associated audio data to unauthorized access. betterleaks.assemblyai-api-key Medium None None
Betterleaks Detected an Atlassian API token, posing a threat to project management and collaboration tool security and data confidentiality. betterleaks.atlassian-api-token High None None
Betterleaks Auth0 client ID, used as a component of the Auth0 client-secret composite rule. (helper) betterleaks.auth0-client-id.1 Medium None None
Betterleaks Auth0 client secret, which may allow an application to impersonate its OAuth client. betterleaks.auth0-client-secret.1 High Yes None
Betterleaks Auth0 tenant domain, used as a component of the Auth0 client-secret composite rule. (helper) betterleaks.auth0-domain.1 High None None
Betterleaks Uncovered a possible Authress Service Client Access Key, which may compromise access control services and sensitive data. betterleaks.authress-service-client-access-key High Yes None
Betterleaks Identified an AWS access key ID paired with a secret access key, which together can provide full access to AWS services. betterleaks.aws-access-token High Yes Yes
Betterleaks Identified a pattern that may indicate long-lived Amazon Bedrock API keys, risking unauthorized Amazon Bedrock usage betterleaks.aws-amazon-bedrock-api-key-long-lived High None None
Betterleaks Identified a pattern that may indicate short-lived Amazon Bedrock API keys, risking unauthorized Amazon Bedrock usage betterleaks.aws-amazon-bedrock-api-key-short-lived High None None
Betterleaks Identified an AWS secret access key, used as a component of the aws-access-token composite rule. (helper) betterleaks.aws-secret-access-key Medium None None
Betterleaks Azure AD Client Secret betterleaks.azure-ad-client-secret High Yes None
Betterleaks Detected an Azure App Configuration connection string. betterleaks.azure-app-configuration-connection-string High Yes None
Betterleaks Detected an Azure client ID, used as a component of Azure service principal validation. (helper) betterleaks.azure-client-id Medium None None
Betterleaks Detected an Azure Service Bus or Event Hub shared access connection string. betterleaks.azure-servicebus-connection-string High Yes None
Betterleaks Detected an Azure Storage account key. betterleaks.azure-storage-account-key High Yes None
Betterleaks Detected an Azure Storage account name, used as a component of Azure Storage key validation. (helper) betterleaks.azure-storage-account-name Medium None None
Betterleaks Detected an Azure tenant ID, used as a component of Azure service principal validation. (helper) betterleaks.azure-tenant-id Medium None None
Betterleaks Detected a Beamer API token, potentially compromising content management and exposing sensitive notifications and updates. betterleaks.beamer-api-token Medium None None
Betterleaks Discovered a potential Bitbucket Client ID, risking unauthorized repository access and potential codebase exposure. betterleaks.bitbucket-client-id High None None
Betterleaks Discovered a potential Bitbucket Client Secret, posing a risk of compromised code repositories and unauthorized access. betterleaks.bitbucket-client-secret High None None
Betterleaks Detected a Bitly access token, which may allow unauthorized access to Bitly account and link management APIs. betterleaks.bitly-access-token High Yes None
Betterleaks Detected a Bitrise personal or workspace access token, which may expose CI/CD applications and builds. betterleaks.bitrise-access-token High Yes None
Betterleaks Identified a Bittrex Access Key, which could lead to unauthorized access to cryptocurrency trading accounts and financial loss. betterleaks.bittrex-access-key High None None
Betterleaks Detected a Bittrex Secret Key, potentially compromising cryptocurrency transactions and financial security. betterleaks.bittrex-secret-key High None None
Betterleaks Detected a Box API access token, which may expose Box files and account data. betterleaks.box-api-access-token Medium Yes None
Betterleaks Detected a Brave Search API key, which may allow unauthorized use of Brave Search API quota. betterleaks.brave-search-api-key High Yes None
Betterleaks BrowserStack access key, which may allow access to automated browser and device testing when paired with its username. betterleaks.browserstack-access-key.1 High Yes None
Betterleaks BrowserStack username, used as a component of the BrowserStack access-key composite rule. (helper) betterleaks.browserstack-username.1 Medium None None
Betterleaks Detected a Buildkite agent, package, or portal token, which may expose CI/CD workloads or packages. betterleaks.buildkite-service-token High None None
Betterleaks Detected a Buildkite user access token, which may expose pipelines, builds, and organization data. betterleaks.buildkite-user-access-token High Yes Yes
Betterleaks Detected a GC Notify API key, which may allow unauthorized notification access. betterleaks.canadian-digital-service-notify-api-key High Yes None
Betterleaks Detected a Canva Connect API client ID, used as a component of the canva-client-secret composite rule. (helper) betterleaks.canva-client-id High None None
Betterleaks Detected a Canva Connect API client secret, which may allow unauthorized OAuth client authentication when paired with a client ID. betterleaks.canva-client-secret High Yes None
Betterleaks Cartesia API key, which grants server-side access to Cartesia voice APIs. betterleaks.cartesia-api-key.1 High Yes None
Betterleaks Identified a Cerebras AI API Key, which may expose AI inference services to unauthorized access. betterleaks.cerebras-api-key High Yes None
Betterleaks Checkout.com secret key. betterleaks.checkout-secret-key Medium Yes None
Betterleaks CircleCI personal access token. betterleaks.circleci-personal-token High Yes None
Betterleaks CircleCI project token. betterleaks.circleci-project-token High Yes None
Betterleaks Cisco Meraki is a cloud-managed IT solution that provides networking, security, and device management through an easy-to-use interface. betterleaks.cisco-meraki-api-key High Yes None
Betterleaks Detected a Civo Cloud API key, which may expose Kubernetes clusters and compute resources to unauthorized access. betterleaks.civo-api-key High Yes None
Betterleaks Detected a Clerk secret key, which may allow unauthorized access to Clerk backend APIs. betterleaks.clerk-secret-key Medium Yes None
Betterleaks Identified a pattern that may indicate clickhouse cloud API secret key, risking unauthorized clickhouse cloud api access and data breaches on ClickHouse Cloud platforms. betterleaks.clickhouse-cloud-api-secret-key High Yes None
Betterleaks Detected a ClickHouse Cloud key ID, used as a component of the clickhouse-cloud-api-secret-key composite rule. (helper) betterleaks.clickhouse-cloud-key-id High None None
Betterleaks Detected a ClickUp personal API token, which may allow unauthorized access to ClickUp workspaces and user data. betterleaks.clickup-personal-api-token High Yes None
Betterleaks Uncovered a possible Clojars API token, risking unauthorized access to Clojure libraries and potential code manipulation. betterleaks.clojars-api-token High None None
Betterleaks Detected a Cloudflare API Key, potentially compromising cloud application deployments and operational security. betterleaks.cloudflare-api-key High None None
Betterleaks Detected a Cloudflare Global API Key, potentially compromising cloud application deployments and operational security. betterleaks.cloudflare-global-api-key High None None
Betterleaks Detected a Cloudflare Origin CA Key, potentially compromising cloud application deployments and operational security. betterleaks.cloudflare-origin-ca-key High None None
Betterleaks Detected a Cloudinary API key, used as a component of the cloudinary-api-secret composite rule. (helper) betterleaks.cloudinary-api-key High None None
Betterleaks Detected a Cloudinary API secret, which may allow unauthorized access to Cloudinary media and account APIs when paired with a cloud name and API key. betterleaks.cloudinary-api-secret High Yes None
Betterleaks Detected a Cloudinary cloud name, used as a component of the cloudinary-api-secret composite rule. (helper) betterleaks.cloudinary-cloud-name High None None
Betterleaks Detected a Cloudsmith API key, which may expose package repositories and artifact management operations to unauthorized access. betterleaks.cloudsmith-api-key High Yes None
Betterleaks Detected a CockroachDB Cloud service account API key, which may allow unauthorized access to CockroachDB Cloud resources. betterleaks.cockroachlabs-cloud-api-key High Yes None
Betterleaks Found a pattern resembling a Codecov Access Token, posing a risk of unauthorized access to code coverage reports and sensitive data. betterleaks.codecov-access-token High Yes None
Betterleaks Identified a Cohere Token, posing a risk of unauthorized access to AI services and data manipulation. betterleaks.cohere-api-token Medium Yes None
Betterleaks Detected a Coinbase Access Token, posing a risk of unauthorized access to cryptocurrency accounts and financial transactions. betterleaks.coinbase-access-token Medium None None
Betterleaks Detected a ConfigCat SDK key, which may allow access to feature flag configuration data. betterleaks.configcat-sdk-key High Yes None
Betterleaks Detected an extended ConfigCat SDK key, which may allow access to feature flag configuration data. betterleaks.configcat-sdk-key-extended High Yes None
Betterleaks Identified a Confluent Access Token, which could compromise access to streaming data platforms and sensitive data flow. betterleaks.confluent-access-token High None None
Betterleaks Found a Confluent Secret Key, potentially risking unauthorized operations and data access within Confluent services. betterleaks.confluent-secret-key High None None
Betterleaks Discovered a Contentful delivery API token, posing a risk to content management systems and data integrity. betterleaks.contentful-delivery-api-token Medium None None
Betterleaks Detected a Couchbase Capella API key secret, which may allow unauthorized access to Couchbase Capella management APIs. betterleaks.couchbase-capella-api-key High Yes None
Betterleaks Detected a Coveralls personal API token, which may expose repository coverage data. betterleaks.coveralls-personal-api-token Medium None None
Betterleaks crates.io API key. betterleaks.crates-io-api-key High Yes Yes
Betterleaks Discovered a potential authorization token provided in a curl command header, which could compromise the curl accessed resource. betterleaks.curl-auth-header High None None
Betterleaks Discovered a potential basic authorization token provided in a curl command, which could compromise the curl accessed resource. betterleaks.curl-auth-user High None None
Betterleaks Detected a Cursor Integrations API Key, which may expose AI-assisted development services to unauthorized access. betterleaks.cursor-api-key Medium Yes None
Betterleaks Databento API key. betterleaks.databento-api-key High Yes None
Betterleaks Uncovered a Databricks API token, which may compromise big data analytics platforms and sensitive data processing. betterleaks.databricks-api-token High None None
Betterleaks Detected a Datadog API key, potentially risking monitoring and analytics data exposure and manipulation. betterleaks.datadog-api-key High Yes None
Betterleaks Detected a Datadog application key, which may expose Datadog account and monitoring data when paired with an API key. betterleaks.datadog-application-key High None None
Betterleaks Detected a Data.gov API key, which may expose usage of Data.gov-backed APIs. betterleaks.datagov-api-key High Yes None
Betterleaks DataStax Astra application token. betterleaks.datastax-astra-application-token High Yes None
Betterleaks Detected a Deepgram API Key, which may expose speech recognition services and audio data to unauthorized access. betterleaks.deepgram-api-key High None None
Betterleaks Detected a DeepSeek API Key, which may expose AI model access and associated usage to unauthorized parties. betterleaks.deepseek-api-key High Yes None
Betterleaks Identified a Defined Networking API token, which could lead to unauthorized network operations and data breaches. betterleaks.defined-networking-api-token High None None
Betterleaks Detected a Deno account token, which may expose Deno Deploy account access. betterleaks.deno-account-token High Yes None
Betterleaks DevCycle client SDK key. betterleaks.devcycle-client-sdk-key High Yes None
Betterleaks DevCycle mobile SDK key. betterleaks.devcycle-mobile-sdk-key High Yes None
Betterleaks DevCycle server SDK key. betterleaks.devcycle-server-sdk-key High Yes None
Betterleaks Detected a Cognition Devin personal API key, which may expose Devin sessions and user data. betterleaks.devin-personal-api-key High Yes None
Betterleaks Detected a Cognition Devin service API key, which may expose Devin sessions and organization access. betterleaks.devin-service-api-key High Yes None
Betterleaks Detected a Cognition Devin service user token, which may expose Devin service user access. betterleaks.devin-service-user-token High Yes None
Betterleaks Found a DigitalOcean OAuth Access Token, risking unauthorized cloud resource access and data compromise. betterleaks.digitalocean-access-token High None Yes
Betterleaks Discovered a DigitalOcean Personal Access Token, posing a threat to cloud infrastructure security and data privacy. betterleaks.digitalocean-pat High None None
Betterleaks Uncovered a DigitalOcean OAuth Refresh Token, which could allow prolonged unauthorized access and resource manipulation. betterleaks.digitalocean-refresh-token High None None
Betterleaks Detected a Discord API key, potentially compromising communication channels and user data privacy on Discord. betterleaks.discord-api-token Medium None None
Betterleaks Identified a Discord client ID, which may lead to unauthorized integrations and data exposure in Discord applications. betterleaks.discord-client-id Medium None None
Betterleaks Discovered a potential Discord client secret, risking compromised Discord bot integrations and data leaks. betterleaks.discord-client-secret Medium None None
Betterleaks Detected a Disqus API key, which may expose Disqus thread and account data. betterleaks.disqus-api-key High Yes None
Betterleaks Docker Swarm join token. betterleaks.docker-swarm-join-token High None None
Betterleaks Docker Swarm unlock key. betterleaks.docker-swarm-unlock-key High None None
Betterleaks Detected a Docker Hub organization access token, which may expose organization repositories. betterleaks.dockerhub-organization-access-token High None None
Betterleaks Detected a Docker Hub personal access token, which may expose Docker Hub account access. betterleaks.dockerhub-personal-access-token High None None
Betterleaks Discovered a Doppler API token, posing a risk to environment and secrets management security. betterleaks.doppler-api-token High None Yes
Betterleaks Detected a Droneci Access Token, potentially compromising continuous integration and deployment workflows. betterleaks.droneci-access-token High None None
Betterleaks Identified a Dropbox API secret, which could lead to unauthorized file access and data breaches in Dropbox storage. betterleaks.dropbox-api-token Medium None None
Betterleaks Found a Dropbox long-lived API token, risking prolonged unauthorized access to cloud storage and sensitive data. betterleaks.dropbox-long-lived-api-token High None None
Betterleaks Discovered a Dropbox short-lived API token, posing a risk of temporary but potentially harmful data access and manipulation. betterleaks.dropbox-short-lived-api-token High None None
Betterleaks Uncovered a Duffel API token, which may compromise travel platform integrations and sensitive customer data. betterleaks.duffel-api-token High None None
Betterleaks Detected a Dynatrace API token, potentially risking application performance monitoring and data exposure. betterleaks.dynatrace-api-token High None None
Betterleaks Identified an EasyPost API token, which could lead to unauthorized postal and shipment service access and data exposure. betterleaks.easypost-api-token High None None
Betterleaks Detected an EasyPost test API token, risking exposure of test environments and potentially sensitive shipment data. betterleaks.easypost-test-api-token High None None
Betterleaks eBay client ID, used as a component of the eBay client-secret composite rule. (helper) betterleaks.ebay-client-id High None None
Betterleaks eBay client secret. betterleaks.ebay-client-secret High Yes None
Betterleaks Identified an Elastic Cloud Serverless API key, which may expose Elasticsearch and Kibana resources to unauthorized access. betterleaks.elastic-cloud-api-key High Yes None
Betterleaks Detected an ElevenLabs API Key, which may expose AI voice synthesis services to unauthorized access. betterleaks.elevenlabs-api-key High None None
Betterleaks Detected an Endor Labs API Key, which may compromise supply chain security scanning and software composition analysis. betterleaks.endorlabs-api-key High None None
Betterleaks Detected an Endor Labs API Secret, which together with an API key grants full access to Endor Labs supply chain security services. betterleaks.endorlabs-api-secret High None None
Betterleaks Found an Etsy Open API key, potentially compromising Etsy app access and shop integrations. betterleaks.etsy-open-api-key High Yes None
Betterleaks Identified an Exoscale API key paired with a secret, which together grant programmatic access to Exoscale cloud resources. betterleaks.exoscale-api-key High Yes None
Betterleaks Identified an Exoscale API secret, used as a component of the exoscale-api-key composite rule. (helper) betterleaks.exoscale-api-secret High None None
Betterleaks Discovered a Facebook Access Token, posing a risk of unauthorized access to Facebook accounts and personal data exposure. betterleaks.facebook-access-token High None None
Betterleaks Discovered a Facebook Page Access Token, posing a risk of unauthorized access to Facebook accounts and personal data exposure. betterleaks.facebook-page-access-token High None None
Betterleaks Discovered a Facebook Application secret, posing a risk of unauthorized access to Facebook accounts and personal data exposure. betterleaks.facebook-secret High None None
Betterleaks Fal.ai API key, which may allow access to model execution, billing, and platform APIs. betterleaks.fal-api-key.1 High Yes None
Betterleaks Uncovered a Fastly API key, which may compromise CDN and edge cloud services, leading to content delivery and security issues. betterleaks.fastly-api-token High Yes None
Betterleaks Uncovered a Figma Personal Access Token in a header, which may compromise design assets and team collaboration. betterleaks.figma-personal-access-header-token High Yes None
Betterleaks Uncovered a Figma Personal Access Token, which may compromise design assets and team collaboration. betterleaks.figma-personal-access-token High Yes None
Betterleaks Detected a Finicity API token, potentially risking financial data access and unauthorized financial operations. betterleaks.finicity-api-token High None None
Betterleaks Identified a Finicity Client Secret, which could lead to compromised financial service integrations and data breaches. betterleaks.finicity-client-secret High None None
Betterleaks Found a Finnhub Access Token, risking unauthorized access to financial market data and analytics. betterleaks.finnhub-access-token High None None
Betterleaks Discovered a Flickr Access Token, posing a risk of unauthorized photo management and potential data leakage. betterleaks.flickr-access-token High None None
Betterleaks Uncovered a Flutterwave Encryption Key, which may compromise payment processing and sensitive financial information. betterleaks.flutterwave-encryption-key High None None
Betterleaks Detected a Flutterwave Public Key, potentially exposing public cryptographic operations and integrations. betterleaks.flutterwave-public-key High None None
Betterleaks Identified a Flutterwave Secret Key, risking unauthorized financial transactions and data breaches. betterleaks.flutterwave-secret-key High None None
Betterleaks Uncovered a Fly.io API key betterleaks.flyio-access-token High Yes None
Betterleaks Found a Frame.io API token, potentially compromising video collaboration and project management. betterleaks.frameio-api-token High Yes None
Betterleaks Detected a Freemius secret key, potentially exposing sensitive information. betterleaks.freemius-secret-key Medium None None
Betterleaks Discovered a Freshbooks Access Token, posing a risk to accounting software access and sensitive financial data exposure. betterleaks.freshbooks-access-token High Yes None
Betterleaks FullStory API key. betterleaks.fullstory-api-key Medium Yes None
Betterleaks Uncovered a GCP API key, which could lead to unauthorized access to Google Cloud services and data breaches. betterleaks.gcp-api-key High Yes None
Betterleaks Google (GCP) Application Default Credentials betterleaks.gcp-application-default-credentials High Yes None
Betterleaks Detected a Google Gemini API key, which may expose Gemini model access and usage to unauthorized parties. betterleaks.gcp-gemini-api High Yes None
Betterleaks Google (GCP) Service-account betterleaks.gcp-service-account High Yes Yes
Betterleaks Detected a password embedded in a service connection URI, which may expose direct access to the referenced service. betterleaks.generic-credential-uri Medium Yes None
Betterleaks Detected a Gitea Access Token, which may expose self-hosted Git repositories and associated code to unauthorized access. betterleaks.gitea-access-token High None None
Betterleaks Identified a GitHub App Token, which may compromise GitHub application integrations and source code security. betterleaks.github-app-token High Yes None
Betterleaks Found a GitHub Fine-Grained Personal Access Token, risking unauthorized repository access and code manipulation. betterleaks.github-fine-grained-pat High Yes Yes
Betterleaks Discovered a GitHub OAuth Access Token, posing a risk of compromised GitHub account integrations and data leaks. betterleaks.github-oauth High Yes Yes
Betterleaks Uncovered a GitHub Personal Access Token, potentially leading to unauthorized repository access and sensitive content exposure. betterleaks.github-pat High Yes Yes
Betterleaks Detected a GitHub Refresh Token, which could allow prolonged unauthorized access to GitHub services. betterleaks.github-refresh-token High Yes Yes
Betterleaks Identified a GitLab CI/CD Job Token, potential access to projects and some APIs on behalf of a user while the CI job is running. betterleaks.gitlab-cicd-job-token High Yes None
Betterleaks Identified a GitLab Deploy Token, risking access to repositories, packages and containers with write access. betterleaks.gitlab-deploy-token High Yes None
Betterleaks Identified a GitLab feature flag client token, risks exposing user lists and features flags used by an application. betterleaks.gitlab-feature-flag-client-token High None None
Betterleaks Identified a GitLab feed token, risking exposure of user data. betterleaks.gitlab-feed-token High None None
Betterleaks Identified a GitLab incoming mail token embedded in an email address, risking manipulation of data sent by mail. betterleaks.gitlab-incoming-mail-address-token High None None
Betterleaks Identified a GitLab incoming mail token, risking manipulation of data sent by mail. betterleaks.gitlab-incoming-mail-token High None None
Betterleaks Identified a GitLab Kubernetes Agent token, risking access to repos and registry of projects connected via agent. betterleaks.gitlab-kubernetes-agent-token High None None
Betterleaks Identified a GitLab OIDC Application Secret, risking access to apps using GitLab as authentication provider. betterleaks.gitlab-oauth-app-secret High None None
Betterleaks Identified a GitLab Personal Access Token, risking unauthorized access to GitLab repositories and codebase exposure. betterleaks.gitlab-pat High Yes Yes
Betterleaks Identified a GitLab Personal Access Token (routable), risking unauthorized access to GitLab repositories and codebase exposure. betterleaks.gitlab-pat-routable High Yes Yes
Betterleaks Identified a GitLab Personal Access Token (routable, versioned), risking unauthorized access to GitLab repositories and codebase exposure. betterleaks.gitlab-pat-routable-versioned High Yes Yes
Betterleaks Found a GitLab Pipeline Trigger Token, potentially compromising continuous integration workflows and project security. betterleaks.gitlab-ptt High Yes None
Betterleaks Discovered a GitLab Runner Registration Token, posing a risk to CI/CD pipeline integrity and unauthorized access. betterleaks.gitlab-rrt High Yes None
Betterleaks Discovered a GitLab Runner Authentication Token, posing a risk to CI/CD pipeline integrity and unauthorized access. betterleaks.gitlab-runner-authentication-token High Yes None
Betterleaks Discovered a GitLab Runner Authentication Token (Routable), posing a risk to CI/CD pipeline integrity and unauthorized access. betterleaks.gitlab-runner-authentication-token-routable High Yes None
Betterleaks Discovered a GitLab SCIM Token, posing a risk to unauthorized access for a organization or instance. betterleaks.gitlab-scim-token High None None
Betterleaks Discovered a GitLab Session Cookie, posing a risk to unauthorized access to a user account. betterleaks.gitlab-session-cookie High None None
Betterleaks Uncovered a Gitter Access Token, which may lead to unauthorized access to chat and communication services. betterleaks.gitter-access-token High None None
Betterleaks Detected a GoCardless API token, potentially risking unauthorized direct debit payment operations and financial data exposure. betterleaks.gocardless-api-token High Yes None
Betterleaks Identified a Grafana API key, which could compromise monitoring dashboards and sensitive data analytics. betterleaks.grafana-api-key High None None
Betterleaks Found a Grafana cloud API token, risking unauthorized access to cloud-based monitoring services and data exposure. betterleaks.grafana-cloud-api-token High Yes None
Betterleaks Discovered a Grafana service account token, posing a risk of compromised monitoring services and data integrity. betterleaks.grafana-service-account-token High None None
Betterleaks Detected a Greptile API Key, which may expose AI-powered code search and analysis services to unauthorized access. betterleaks.greptile-api-key High None None
Betterleaks Identified a Groq API Key, which may expose high-speed AI inference services to unauthorized access. betterleaks.groq-api-key High Yes None
Betterleaks Detected a Gumroad access token, which may expose Gumroad account and product data. betterleaks.gumroad-access-token High Yes None
Betterleaks Identified a Harness Access Token (PAT or SAT), risking unauthorized access to a Harness account. betterleaks.harness-api-key High Yes None
Betterleaks Uncovered a HashiCorp Terraform user/org API token, which may lead to unauthorized infrastructure management and security breaches. betterleaks.hashicorp-tf-api-token High None None
Betterleaks Identified a HashiCorp Terraform password field, risking unauthorized infrastructure configuration and security breaches. betterleaks.hashicorp-tf-password Medium None None
Betterleaks Detected a Heroku API Key, potentially compromising cloud application deployments and operational security. betterleaks.heroku-api-key High None Yes
Betterleaks Detected a Heroku API Key, potentially compromising cloud application deployments and operational security. betterleaks.heroku-api-key-v2 High None Yes
Betterleaks Highnote secret API key for the live environment. betterleaks.highnote-secret-live-key High Yes None
Betterleaks Detected a Honeycomb API key, which may expose Honeycomb telemetry and environment data. betterleaks.honeycomb-api-key Medium Yes None
Betterleaks Found a HubSpot API Token, posing a risk to CRM data integrity and unauthorized marketing operations. betterleaks.hubspot-api-key High None None
Betterleaks Discovered a Hugging Face Access token, which could lead to unauthorized access to AI models and sensitive data. betterleaks.huggingface-access-token High Yes Yes
Betterleaks Uncovered a Hugging Face Organization API token, potentially compromising AI organization accounts and associated data. betterleaks.huggingface-organization-api-token High Yes Yes
Betterleaks Hunter API key, which may allow access to account and email intelligence data. betterleaks.hunter-api-key.1 Medium Yes None
Betterleaks Detected an IBM Cloud user API key, which may expose IBM Cloud account resources. betterleaks.ibm-cloud-user-api-key High Yes None
Betterleaks Detected an InfluxDB API token, which may allow unauthorized access to time-series data and InfluxDB organization resources. betterleaks.influxdb-api-token High Yes None
Betterleaks Detected an Infomaniak API token, which may expose hosting, mail, and cloud services to unauthorized access. betterleaks.infomaniak-api-token High Yes None
Betterleaks Detected an Infracost API Token, risking unauthorized access to cloud cost estimation tools and financial data. betterleaks.infracost-api-token High None None
Betterleaks Instantly API key, which may allow access to campaigns, accounts, leads, and analytics. betterleaks.instantly-api-key.1 Medium Yes None
Betterleaks Identified an Intercom API Token, which could compromise customer communication channels and data privacy. betterleaks.intercom-api-key Medium None None
Betterleaks Found a Intra42 client secret, which could lead to unauthorized access to the 42School API and sensitive data. betterleaks.intra42-client-secret High None None
Betterleaks Ionic personal access token. betterleaks.ionic-personal-access-token High Yes None
Betterleaks Detected a JumpCloud API key, which may expose JumpCloud directory data. betterleaks.jumpcloud-api-key High Yes None
Betterleaks Uncovered a JSON Web Token, which may lead to unauthorized access to web applications and sensitive user data. betterleaks.jwt High Yes None
Betterleaks Detected a Base64-encoded JSON Web Token, posing a risk of exposing encoded authentication and data exchange information. betterleaks.jwt-base64 High None None
Betterleaks Detected a Kagi API key, which may expose Kagi API usage. betterleaks.kagi-api-key High Yes None
Betterleaks Detected a Kimi API key, which may expose Moonshot AI model access and usage to unauthorized parties. betterleaks.kimi-api-key High Yes None
Betterleaks Detected a Klaviyo API key, which may expose Klaviyo account and marketing data. betterleaks.klaviyo-api-key High Yes None
Betterleaks Identified a Kraken Access Token, potentially compromising cryptocurrency trading accounts and financial security. betterleaks.kraken-access-token Medium None None
Betterleaks Possible Kubernetes Secret detected, posing a risk of leaking credentials/tokens from your deployments betterleaks.kubernetes-secret-yaml High None None
Betterleaks Found a Kucoin Access Token, risking unauthorized access to cryptocurrency exchange services and transactions. betterleaks.kucoin-access-token High None None
Betterleaks Discovered a Kucoin Secret Key, which could lead to compromised cryptocurrency operations and financial data breaches. betterleaks.kucoin-secret-key High None None
Betterleaks LangSmith personal access token. betterleaks.langchain-langsmith-personal-access-token High Yes None
Betterleaks LangSmith service API key. betterleaks.langchain-langsmith-service-key High Yes None
Betterleaks Langfuse public key, used as a component of the Langfuse secret-key composite rule. (helper) betterleaks.langfuse-public-key.1 High None None
Betterleaks Langfuse secret key, which authenticates project API access when paired with its public key. betterleaks.langfuse-secret-key.1 High Yes None
Betterleaks Lark application ID, used as a component of the Lark application-secret rule. (helper) betterleaks.lark-app-id High None None
Betterleaks Lark application secret. betterleaks.lark-app-secret High Yes None
Betterleaks Uncovered a Launchdarkly Access Token, potentially compromising feature flag management and application functionality. betterleaks.launchdarkly-access-token High None None
Betterleaks Lichess personal access token. betterleaks.lichess-personal-access-token High Yes None
Betterleaks Detected a LightOn Paradigm API key, which may expose enterprise LLM services to unauthorized access. betterleaks.lighton-paradigm-api-key Medium Yes None
Betterleaks Detected a Linear API Token, posing a risk to project management tools and sensitive task data. betterleaks.linear-api-key High Yes None
Betterleaks Identified a Linear Client Secret, which may compromise secure integrations and sensitive project management data. betterleaks.linear-client-secret Medium None None
Betterleaks Found a LinkedIn Client ID, risking unauthorized access to LinkedIn integrations and professional data exposure. betterleaks.linkedin-client-id Medium None None
Betterleaks Discovered a LinkedIn Client secret, potentially compromising LinkedIn application integrations and user data. betterleaks.linkedin-client-secret Medium None None
Betterleaks LlamaCloud API key, which may allow access to managed parsing, ingestion, and retrieval projects. betterleaks.llama-cloud-api-key.1 High Yes None
Betterleaks Uncovered a Lob API Key, which could lead to unauthorized access to mailing and address verification services. betterleaks.lob-api-key Medium None None
Betterleaks Detected a Lob Publishable API Key, posing a risk of exposing mail and print service integrations. betterleaks.lob-pub-api-key Medium None None
Betterleaks Found a Looker Client ID, risking unauthorized access to a Looker account and exposing sensitive data. betterleaks.looker-client-id Medium None None
Betterleaks Found a Looker Client Secret, risking unauthorized access to a Looker account and exposing sensitive data. betterleaks.looker-client-secret Medium None None
Betterleaks Identified a Mailchimp API key, potentially compromising email marketing campaigns and subscriber data. betterleaks.mailchimp-api-key High Yes None
Betterleaks MailerSend API token. betterleaks.mailersend-api-token High Yes None
Betterleaks Found a Mailgun private API token, risking unauthorized email service operations and data breaches. betterleaks.mailgun-private-api-token High Yes None
Betterleaks Discovered a Mailgun public validation key, which could expose email verification processes and associated data. betterleaks.mailgun-pub-key High None None
Betterleaks Uncovered a Mailgun webhook signing key, potentially compromising email automation and data integrity. betterleaks.mailgun-signing-key High None None
Betterleaks Detected a MapBox API token, posing a risk to geospatial services and sensitive location data exposure. betterleaks.mapbox-api-token High None None
Betterleaks Identified a Mattermost Access Token, which may compromise team communication channels and data privacy. betterleaks.mattermost-access-token Medium None None
Betterleaks Discovered a potential MaxMind license key. betterleaks.maxmind-license-key High None None
Betterleaks Mem0 API key, which may allow access to stored application memories. betterleaks.mem0-api-key.1 High Yes None
Betterleaks Mercury production API token. betterleaks.mercury-production-api-token High Yes None
Betterleaks Mergify application API key. betterleaks.mergify-application-key High Yes None
Betterleaks Found a MessageBird API token, risking unauthorized access to communication platforms and message data. betterleaks.messagebird-api-token High None None
Betterleaks Discovered a MessageBird client ID, potentially compromising API integrations and sensitive communication data. betterleaks.messagebird-client-id High None None
Betterleaks Uncovered a Microsoft Teams Webhook, which could lead to unauthorized access to team collaboration tools and data leaks. betterleaks.microsoft-teams-webhook High None None
Betterleaks Midtrans production server or client key. betterleaks.midtrans-production-server-client-key High Yes None
Betterleaks Detected a MiniMax API key, which may expose AI model, speech, image, video, or file services to unauthorized access. betterleaks.minimax-api-key High Yes None
Betterleaks Detected a Miro OAuth access token, which may allow unauthorized access to Miro users, teams, boards, and content. betterleaks.miro-access-token High Yes None
Betterleaks Detected a Miro OAuth client ID, used as a component of the miro-client-secret composite rule. (helper) betterleaks.miro-client-id Medium None None
Betterleaks Detected a Miro OAuth client secret, which may allow unauthorized OAuth client authentication when paired with a client ID. betterleaks.miro-client-secret High Yes None
Betterleaks Detected a Mistral AI API Key, which may expose AI language model services to unauthorized access. betterleaks.mistral-api-key Medium Yes None
Betterleaks monday.com API token, which may grant the same workspace access as its associated user or application. betterleaks.monday-api-token.1 High Yes None
Betterleaks Found a MongoDB Atlas service account client ID. (helper) betterleaks.mongodb-atlas-service-account-id High None None
Betterleaks Detected a MongoDB Atlas service account client secret, which could allow unauthorized Atlas administration API access when paired with a service account client ID. betterleaks.mongodb-atlas-service-account-secret High Yes None
Betterleaks Detected a MongoDB connection string with embedded credentials, potentially exposing direct database access and sensitive application data. betterleaks.mongodb-connection-string High Yes None
Betterleaks Mux access-token ID, used as a component of the Mux access-token-secret composite rule. (helper) betterleaks.mux-access-token-id.1 Medium None None
Betterleaks Mux access-token secret, which may grant access to video, data, or system APIs when paired with its token ID. betterleaks.mux-access-token-secret.1 High Yes None
Betterleaks Neon API key. betterleaks.neon-api-key High Yes None
Betterleaks Detected a Netlify Access Token, potentially compromising web hosting services and site management. betterleaks.netlify-access-token High None None
Betterleaks Identified a New Relic ingest browser API token, risking unauthorized access to application performance data and analytics. betterleaks.new-relic-browser-api-token High None None
Betterleaks Discovered a New Relic insight insert key, compromising data injection into the platform. betterleaks.new-relic-insert-key High None None
Betterleaks Found a New Relic user API ID, posing a risk to application monitoring services and data integrity. betterleaks.new-relic-user-api-id High None None
Betterleaks Discovered a New Relic user API Key, which could lead to compromised application insights and performance monitoring. betterleaks.new-relic-user-api-key High None None
Betterleaks ngrok API key or agent authtoken, which may allow tunnel access or account administration. betterleaks.ngrok-api-key.1 High Yes None
Betterleaks Notion API token betterleaks.notion-api-token High None None
Betterleaks Uncovered an npm access token, potentially compromising package management and code repository access. betterleaks.npm-access-token High None None
Betterleaks Identified a password within a Nuget config file, potentially compromising package management access. betterleaks.nuget-config-password High None None
Betterleaks Detected an NVIDIA NIM API Key, which may expose AI inference and GPU cloud services to unauthorized access. betterleaks.nvidia-api-key High None None
Betterleaks Nylas API key, which may allow application-level access to connected email, calendar, and contact data. betterleaks.nylas-api-key.1 High Yes None
Betterleaks Detected a Nytimes Access Token, risking unauthorized access to New York Times APIs and content services. betterleaks.nytimes-access-token High None None
Betterleaks Discovered a potential Octopus Deploy API key, risking application deployments and operational security. betterleaks.octopus-deploy-api-key Medium None None
Betterleaks Identified an Okta Access Token, which may compromise identity management services and user authentication data. betterleaks.okta-access-token High None None
Betterleaks Detected an Ollama API Key, which may expose local and hosted AI model serving to unauthorized access. betterleaks.ollama-api-key High None None
Betterleaks OneSignal rich authentication token. betterleaks.onesignal-rich-authentication-token High Yes None
Betterleaks Onfido live API token. betterleaks.onfido-live-api-token-ca High Yes None
Betterleaks Onfido live API token. betterleaks.onfido-live-api-token-eu High Yes None
Betterleaks Onfido live API token. betterleaks.onfido-live-api-token-us High Yes None
Betterleaks Found an OpenAI API Key, posing a risk of unauthorized access to AI services and data manipulation. betterleaks.openai-api-key High Yes None
Betterleaks Detected an OpenRouter API Key, which may expose access to multiple AI models through the OpenRouter gateway. betterleaks.openrouter-api-key High None None
Betterleaks Found an OpenShift user token, potentially compromising an OpenShift/Kubernetes cluster. betterleaks.openshift-user-token High None None
Betterleaks OpenWeather API key. betterleaks.openweather-api-key Medium Yes None
Betterleaks Opsgenie API key, which may allow access to alerts, incidents, and account configuration. betterleaks.opsgenie-api-key.1 High Yes None
Betterleaks OVHcloud Application Key - component of authenticated OVH API requests. (helper) betterleaks.ovh-application-key Medium None None
Betterleaks OVHcloud Application Secret - component of authenticated OVH API requests, which could allow unauthorized access to OVHcloud infrastructure when combined with Application and Consumer keys. betterleaks.ovh-application-secret High Yes None
Betterleaks OVHcloud Consumer Key - component of authenticated OVH API requests. (helper) betterleaks.ovh-consumer-key Medium None None
Betterleaks Paddle live API key. betterleaks.paddle-live-api-key High Yes None
Betterleaks PagerDuty authorization token, which may allow access to PagerDuty account and incident data. betterleaks.pagerduty-authorization-token.1 High Yes None
Betterleaks PayPal OAuth client ID, used as a component of the PayPal client-secret composite rule. (helper) betterleaks.paypal-client-id.1 Medium None None
Betterleaks PayPal OAuth client secret, which may allow access to PayPal REST APIs when paired with its client ID. betterleaks.paypal-client-secret.1 High Yes None
Betterleaks Detected a Perplexity API key, which could lead to unauthorized access to Perplexity AI services and data exposure. betterleaks.perplexity-api-key High Yes None
Betterleaks Persona production API key. betterleaks.persona-production-api-key High Yes None
Betterleaks Pinecone API key version 1 (UUID format). betterleaks.pinecone-api-key.1 Medium Yes None
Betterleaks Pinecone API key version 2 (pcsk format). betterleaks.pinecone-api-key.2 High Yes None
Betterleaks Pinterest access token. betterleaks.pinterest-access-token High Yes None
Betterleaks Discovered a Plaid API Token, potentially compromising financial data aggregation and banking services. betterleaks.plaid-api-token High None None
Betterleaks Uncovered a Plaid Client ID, which could lead to unauthorized financial service integrations and data breaches. betterleaks.plaid-client-id Medium None None
Betterleaks Detected a Plaid Secret key, risking unauthorized access to financial accounts and sensitive transaction data. betterleaks.plaid-secret-key Medium None None
Betterleaks Identified a PlanetScale API token, potentially compromising database management and operations. betterleaks.planetscale-api-token High Yes None
Betterleaks Found a PlanetScale service token ID. (helper) betterleaks.planetscale-id High None None
Betterleaks Found a PlanetScale OAuth token, posing a risk to database access control and sensitive data integrity. betterleaks.planetscale-oauth-token High None None
Betterleaks Discovered a PlanetScale password, which could lead to unauthorized database operations and data breaches. betterleaks.planetscale-password High None None
Betterleaks Plivo Auth ID, used as a component of the Plivo Auth Token composite rule. (helper) betterleaks.plivo-auth-id High None None
Betterleaks Plivo Auth Token. betterleaks.plivo-auth-token High Yes None
Betterleaks Polar OAuth access token. betterleaks.polar-oauth-access-token High Yes None
Betterleaks Polar organization access token. betterleaks.polar-organization-access-token High Yes None
Betterleaks Polar personal access token. betterleaks.polar-personal-access-token High Yes None
Betterleaks Found a Polymarket wallet address, used as a component of authenticated Polymarket API requests. (helper) betterleaks.polymarket-address Medium None None
Betterleaks Identified a Polymarket API key, potentially compromising access to the Polymarket trading platform. betterleaks.polymarket-api-key High Yes None
Betterleaks Discovered a Polymarket API secret, which could be used to sign authenticated requests to the Polymarket L2 API. (helper) betterleaks.polymarket-api-secret Medium None None
Betterleaks Found a Polymarket API passphrase, used as a component of authenticated Polymarket API requests. (helper) betterleaks.polymarket-passphrase Medium None None
Betterleaks Discovered a Polymarket private key, which could allow unauthorized trading and fund transfers. betterleaks.polymarket-private-key Medium Yes None
Betterleaks Detected a PostHog Personal API Key, which may expose administrative access to PostHog analytics projects. betterleaks.posthog-personal-api-key High Yes None
Betterleaks Detected a PostHog Project API Key, a public write-only token used to send events to a PostHog project. betterleaks.posthog-project-api-key High None None
Betterleaks Uncovered a Postman API token, potentially compromising API testing and development workflows. betterleaks.postman-api-token High None None
Betterleaks Postmark server or account API token, which may allow access to email delivery and account configuration. betterleaks.postmark-api-token.1 High Yes None
Betterleaks Detected a Prefect API token, risking unauthorized access to workflow management and automation services. betterleaks.prefect-api-token High None None
Betterleaks Identified a Private Key, which may compromise cryptographic security and sensitive data encryption. betterleaks.private-key High Yes None
Betterleaks Identified a PrivateAI Token, posing a risk of unauthorized access to AI services and data manipulation. betterleaks.privateai-api-token Medium None None
Betterleaks Proof production full-access API key. betterleaks.proof-full-access-api-key High Yes None
Betterleaks Found a Pulumi API token, posing a risk to infrastructure as code services and cloud resource management. betterleaks.pulumi-api-token High None None
Betterleaks Discovered a PyPI upload token, potentially compromising Python package distribution and repository integrity. betterleaks.pypi-upload-token High None None
Betterleaks Rainforest Pay production API key. betterleaks.rainforest-pay-production-api-key Medium Yes None
Betterleaks Ramp client ID, used as a component of the Ramp client-secret composite rule. (helper) betterleaks.ramp-client-id High None None
Betterleaks Ramp OAuth client secret. betterleaks.ramp-client-secret High Yes None
Betterleaks Uncovered a RapidAPI Access Token, which could lead to unauthorized access to various APIs and data services. betterleaks.rapidapi-access-token High None None
Betterleaks Razorpay key ID, used as a component of the Razorpay key-secret composite rule. (helper) betterleaks.razorpay-key-id.1 High None None
Betterleaks Razorpay key secret, which may authorize payment APIs when paired with its key ID. betterleaks.razorpay-key-secret.1 High Yes None
Betterleaks Detected a Readme API token, risking unauthorized documentation management and content exposure. betterleaks.readme-api-token High None None
Betterleaks redirect.pizza API token. betterleaks.redirect-pizza-api-token.1 High Yes None
Betterleaks Detected a Render API key, which may expose hosted services and account resources to unauthorized access. betterleaks.render-api-key High Yes None
Betterleaks Detected a Replicate API Token, which may expose AI model hosting and inference services to unauthorized access. betterleaks.replicate-api-token High Yes None
Betterleaks Resend API key, which may allow sending email or managing account resources. betterleaks.resend-api-key.1 High Yes None
Betterleaks Retell AI API key, which may allow access to agents, calls, and account configuration. betterleaks.retell-api-key.1 High Yes None
Betterleaks Rootly API key. betterleaks.rootly-api-key.1 High Yes None
Betterleaks Identified a Rubygem API token, potentially compromising Ruby library distribution and package management. betterleaks.rubygems-api-token High None None
Betterleaks RunPod API key. betterleaks.runpod-api-key.1 High Yes None
Betterleaks Salesforce access token. betterleaks.salesforce-access-token.1 High Yes None
Betterleaks Salesforce instance host, used as a component of the Salesforce access-token rule. (helper) betterleaks.salesforce-instance-url.1 High None None
Betterleaks Samsara API token. betterleaks.samsara-api-token.1 High Yes None
Betterleaks Identified a standalone Scaleway Secret Key. This can be used to authenticate API requests. betterleaks.scaleway-secret-key High Yes None
Betterleaks Found a Scalingo API token, posing a risk to cloud platform services and application deployment security. betterleaks.scalingo-api-token High None None
Betterleaks Scalr API access token. betterleaks.scalr-api-access-token.1 High Yes None
Betterleaks Segment workspace bearer token for the Public API. betterleaks.segment-public-api-token.1 High Yes None
Betterleaks Discovered a Sendbird Access ID, which could compromise chat and messaging platform integrations. betterleaks.sendbird-access-id High None None
Betterleaks Uncovered a Sendbird Access Token, potentially risking unauthorized access to communication services and user data. betterleaks.sendbird-access-token High None None
Betterleaks Detected a SendGrid API token, posing a risk of unauthorized email service operations and data exposure. betterleaks.sendgrid-api-token High None None
Betterleaks Identified a Brevo (formerly Sendinblue) API token, which may compromise email marketing services and subscriber data privacy. betterleaks.sendinblue-api-token High Yes None
Betterleaks Found a Sentry.io Access Token (old format), risking unauthorized access to error tracking services and sensitive application data. betterleaks.sentry-access-token Medium None None
Betterleaks Found a Sentry.io Organization Token, risking unauthorized access to error tracking services and sensitive application data. betterleaks.sentry-org-token High None None
Betterleaks Found a Sentry.io User Token, risking unauthorized access to error tracking services and sensitive application data. betterleaks.sentry-user-token High None None
Betterleaks Found a Settlemint Application Access Token. betterleaks.settlemint-application-access-token High None None
Betterleaks Found a Settlemint Personal Access Token. betterleaks.settlemint-personal-access-token High None None
Betterleaks Found a Settlemint Service Access Token. betterleaks.settlemint-service-access-token High None None
Betterleaks Discovered a Shippo API token, potentially compromising shipping services and customer order data. betterleaks.shippo-api-token High None None
Betterleaks Uncovered a Shopify access token, which could lead to unauthorized e-commerce platform access and data breaches. betterleaks.shopify-access-token High None None
Betterleaks Detected a Shopify custom access token, potentially compromising custom app integrations and e-commerce data security. betterleaks.shopify-custom-access-token High None None
Betterleaks Identified a Shopify private app access token, risking unauthorized access to private app data and store operations. betterleaks.shopify-private-app-access-token High None None
Betterleaks Found a Shopify shared secret, posing a risk to application authentication and e-commerce platform security. betterleaks.shopify-shared-secret High None None
Betterleaks Discovered a Sidekiq Secret, which could lead to compromised background job processing and application data breaches. betterleaks.sidekiq-secret High None None
Betterleaks Uncovered a Sidekiq Sensitive URL, potentially exposing internal job queues and sensitive operation details. betterleaks.sidekiq-sensitive-url High None None
Betterleaks Detected a Slack App-level token, risking unauthorized access to Slack applications and workspace data. betterleaks.slack-app-token High None Yes
Betterleaks Identified a Slack Bot token, which may compromise bot integrations and communication channel security. betterleaks.slack-bot-token High None Yes
Betterleaks Found a Slack Configuration access token, posing a risk to workspace configuration and sensitive data access. betterleaks.slack-config-access-token High None None
Betterleaks Discovered a Slack Configuration refresh token, potentially allowing prolonged unauthorized access to configuration settings. betterleaks.slack-config-refresh-token High None None
Betterleaks Uncovered a Slack Legacy bot token, which could lead to compromised legacy bot operations and data exposure. betterleaks.slack-legacy-bot-token High None Yes
Betterleaks Detected a Slack Legacy token, risking unauthorized access to older Slack integrations and user data. betterleaks.slack-legacy-token High None Yes
Betterleaks Identified a Slack Legacy Workspace token, potentially compromising access to workspace data and legacy features. betterleaks.slack-legacy-workspace-token High None Yes
Betterleaks Detected a Slack session cookie (xoxd-), which authenticates browser and desktop sessions across all of a user's workspaces. betterleaks.slack-session-cookie High None None
Betterleaks Detected a Slack client session token (xoxc-), which provides full user-level API access when paired with a session cookie. betterleaks.slack-session-token High None None
Betterleaks Found a Slack User token, posing a risk of unauthorized user impersonation and data access within Slack workspaces. betterleaks.slack-user-token High None Yes
Betterleaks Discovered a Slack Webhook, which could lead to unauthorized message posting and data leakage in Slack channels. betterleaks.slack-webhook-url High None None
Betterleaks Snowflake account host, used as a component of the programmatic access-token rule. (helper) betterleaks.snowflake-account-host.1 High None None
Betterleaks Snowflake programmatic access token. betterleaks.snowflake-programmatic-access-token.1 High Yes None
Betterleaks Uncovered a Snyk API token, potentially compromising software vulnerability scanning and code security. betterleaks.snyk-api-token High None None
Betterleaks Uncovered a Sonar API token, potentially compromising software vulnerability scanning and code security. betterleaks.sonar-api-token High None None
Betterleaks Sourcegraph is a code search and navigation engine. betterleaks.sourcegraph-access-token High Yes None
Betterleaks Detected a Square Access Token, risking unauthorized payment processing and financial transaction exposure. betterleaks.square-access-token High None None
Betterleaks Identified a Squarespace Access Token, which may compromise website management and content control on Squarespace. betterleaks.squarespace-access-token Medium None None
Betterleaks SSLMate API key. betterleaks.sslmate-api-key.1 High Yes None
Betterleaks Detected a Stability AI API Key, which may expose AI image generation services to unauthorized access. betterleaks.stability-ai-api-key Medium None None
Betterleaks Found a Stripe Access Token, posing a risk to payment processing services and sensitive financial data. betterleaks.stripe-access-token High Yes None
Betterleaks Discovered a SumoLogic Access ID, potentially compromising log management services and data analytics integrity. betterleaks.sumologic-access-id Medium None None
Betterleaks Uncovered a SumoLogic Access Token, which could lead to unauthorized access to log data and analytics insights. betterleaks.sumologic-access-token Medium None None
Betterleaks Detected a Supabase Management Token, which may allow unauthorized access to Supabase organizations and projects. betterleaks.supabase-management-token High Yes None
Betterleaks Detected a Supabase Project API Key, which may expose project data through Supabase APIs when paired with a project URL. betterleaks.supabase-project-api-key High Yes None
Betterleaks Detected a Supabase project URL, used as a component of the supabase-project-api-key composite rule. (helper) betterleaks.supabase-project-url High None None
Betterleaks Tableau personal access-token name, used as a component of the token rule. (helper) betterleaks.tableau-personal-access-token-name.1 High None None
Betterleaks Tableau personal access token. betterleaks.tableau-personal-access-token.1 High Yes None
Betterleaks Tableau Online server host, used as a component of the personal access-token rule. (helper) betterleaks.tableau-server-host.1 High None None
Betterleaks Tailscale API access token. betterleaks.tailscale-api-key.1 High Yes None
Betterleaks Detected a Telegram Bot API Token, risking unauthorized bot operations and message interception on Telegram. betterleaks.telegram-bot-api-token High None None
Betterleaks Telnyx API v2 key. betterleaks.telnyx-api-v2-key.1 High Yes None
Betterleaks Temporal Cloud API key. betterleaks.temporal-cloud-api-key.1 High Yes None
Betterleaks Thunderstore API token. betterleaks.thunderstore-api-token.1 High Yes None
Betterleaks Detected a Together.ai API Key, which may expose access to open-source AI models and inference services. betterleaks.togetherai-api-key High Yes None
Betterleaks Identified a Travis CI Access Token, potentially compromising continuous integration services and codebase security. betterleaks.travisci-access-token Medium None None
Betterleaks Found a Twilio API Key, posing a risk to communication services and sensitive customer interaction data. betterleaks.twilio-api-key High None None
Betterleaks Discovered a Twitch API token, which could compromise streaming services and account integrations. betterleaks.twitch-api-token Medium None Yes
Betterleaks Uncovered a Twitter Access Secret, potentially risking unauthorized Twitter integrations and data breaches. betterleaks.twitter-access-secret High None None
Betterleaks Detected a Twitter Access Token, posing a risk of unauthorized account operations and social media data exposure. betterleaks.twitter-access-token High None None
Betterleaks Identified a Twitter API Key, which may compromise Twitter application integrations and user data security. betterleaks.twitter-api-key High None None
Betterleaks Found a Twitter API Secret, risking the security of Twitter app integrations and sensitive data access. betterleaks.twitter-api-secret High None None
Betterleaks Discovered a Twitter Bearer Token, potentially compromising API access and data retrieval from Twitter. betterleaks.twitter-bearer-token High None None
Betterleaks Uncovered a Typeform API token, which could lead to unauthorized survey management and data collection. betterleaks.typeform-api-token High None None
Betterleaks Unkey administrative root key. betterleaks.unkey-root-key.1 High Yes None
Betterleaks Identified an UpCloud API token, which may expose cloud infrastructure resources to unauthorized access. betterleaks.upcloud-api-token High Yes None
Betterleaks Detected an Upstage AI API key, which may expose Solar language models and document AI services to unauthorized access. betterleaks.upstage-api-key Medium Yes None
Betterleaks Upstash Redis REST token, which may grant read-only or full access to an Upstash database. betterleaks.upstash-redis-rest-token.1 High Yes None
Betterleaks Upstash Redis REST URL, used as a component of the Upstash REST-token composite rule. (helper) betterleaks.upstash-redis-rest-url.1 High None None
Betterleaks Val Town API token. betterleaks.val-town-api-token.1 High Yes None
Betterleaks Detected a Vault Batch Token, risking unauthorized access to secret management services and sensitive data. betterleaks.vault-batch-token High None None
Betterleaks Identified a Vault Service Token, potentially compromising infrastructure security and access to sensitive credentials. betterleaks.vault-service-token High None None
Betterleaks Detected a Vercel AI Gateway API Key (vck_), which may expose AI model routing and gateway access to unauthorized parties. betterleaks.vercel-ai-gateway-key High Yes None
Betterleaks Detected a Vercel API Token, which may expose deployment and serverless infrastructure to unauthorized access. betterleaks.vercel-api-token High Yes Yes
Betterleaks Detected a Vercel App Access Token (vca_), which may allow Sign in with Vercel apps to access user resources. betterleaks.vercel-app-access-token High Yes Yes
Betterleaks Detected a Vercel App Refresh Token (vcr_), which may allow persistent unauthorized access through token refresh flows. betterleaks.vercel-app-refresh-token High Yes Yes
Betterleaks Detected a Vercel Integration Token (vci_), which may allow third-party service integrations to act on behalf of users. betterleaks.vercel-integration-token High Yes Yes
Betterleaks Detected a Vercel Personal Access Token (vcp_), which may expose full account and deployment management capabilities. betterleaks.vercel-personal-access-token High Yes Yes
Betterleaks VirusTotal API key, which may expose private submissions, intelligence, or account API access. betterleaks.virustotal-api-key.1 High Yes None
Betterleaks Vultr API key, which may allow management of cloud account resources. betterleaks.vultr-api-key.1 Medium Yes None
Betterleaks WakaTime API key version 1 (UUID format). betterleaks.wakatime-api-key.1 High Yes None
Betterleaks WakaTime API key version 2 (waka_ format). betterleaks.wakatime-api-key.2 High Yes None
Betterleaks Weatherstack API key. betterleaks.weatherstack-api-key.1 Medium Yes None
Betterleaks Detected a Weights & Biases API Key, which may expose ML experiment tracking and model registry access to unauthorized parties. betterleaks.weights-and-biases-api-key Medium Yes None
Betterleaks Detected a Weights & Biases v1 API Key (wandb_v1_), which may expose ML experiment tracking and artifact storage to unauthorized access. betterleaks.weights-and-biases-api-key-v1 High Yes None
Betterleaks Wiz OAuth client ID, used as a component of the Wiz client-secret composite rule. (helper) betterleaks.wiz-client-id.1 Medium None None
Betterleaks Wiz OAuth client secret, which may allow access to the Wiz API when paired with its client ID. betterleaks.wiz-client-secret.1 High Yes None
Betterleaks WooCommerce REST API consumer secret, which may allow read or write access to a store with the associated consumer key. betterleaks.woocommerce-consumer-secret.1 High None None
Betterleaks Workato Developer API token. betterleaks.workato-developer-api-token.1 High Yes None
Betterleaks WorkOS production API key. betterleaks.workos-production-api-key.1 High Yes None
Betterleaks Detected an xAI (Grok) API Key, which may expose Grok AI model access to unauthorized parties. betterleaks.xai-api-key High None None
Betterleaks Xendit production API key, which may allow access to payment and balance APIs. betterleaks.xendit-production-api-key.1 High Yes None
Betterleaks Found a Yandex Access Token, posing a risk to Yandex service integrations and user data privacy. betterleaks.yandex-access-token High None None
Betterleaks Discovered a Yandex API Key, which could lead to unauthorized access to Yandex services and data manipulation. betterleaks.yandex-api-key High None None
Betterleaks Uncovered a Yandex AWS Access Token, potentially compromising cloud resource access and data security on Yandex Cloud. betterleaks.yandex-aws-access-token High None None
Betterleaks Detected a Z.ai API key, which may expose GLM model access and usage to unauthorized parties. betterleaks.zai-api-key Medium Yes None
Betterleaks Detected a Zendesk Secret Key, risking unauthorized access to customer support services and sensitive ticketing data. betterleaks.zendesk-secret-key High None None
Betterleaks Zoho OAuth client ID, used as a component of the zoho-client-secret.1 composite rule. (helper) betterleaks.zoho-client-id.1 Medium None None
Betterleaks Zoho OAuth client secret, which may allow OAuth client authentication when paired with the associated client ID. betterleaks.zoho-client-secret.1 High Yes None
Betterleaks Zoho OAuth access or refresh token, which may allow access to Zoho APIs or minting of new access tokens. betterleaks.zoho-oauth-token.1 High Yes None
Betterleaks Zoho ZAPI key, which may authorize CRM functions, extensions, webhooks, or other Zoho APIs. betterleaks.zoho-zapi-key.1 High None None
Betterleaks Zuplo consumer API key. betterleaks.zuplo-consumer-api-key.1 High Yes None
Veles Bitbucket Git Credentials veles.secrets/bitbucketcredentials Medium Yes None
Veles Bitwarden OAuth2 Client Secret veles.secrets/bitwardenoauth2access Medium Yes None
Veles CircleCI Project Token veles.secrets/circleciproject Medium Yes None
Veles Cloudflare API Token veles.secrets/cloudflareapitoken Medium Yes Yes
Veles AWS CodeCatalyst Git Credentials veles.secrets/codecatalystcredentials Medium Yes None
Veles AWS CodeCommit Git Credentials veles.secrets/codecommitcredentials Medium Yes None
Veles Deno Organization Token veles.secrets/denopatorg Medium Yes None
Veles DigitalOcean API Token veles.secrets/digitaloceanapikey Medium Yes Yes
Veles xAI API Key veles.secrets/grokxaiapikey Medium Yes None
Veles HashiCorp Cloud Platform Client Secret veles.secrets/hcpclientcredentials Medium Yes None
Veles HashiCorp Cloud Platform Client ID (helper) veles.secrets/hcpclientcredentials-client-id Medium None None
Veles Heroku Platform Key veles.secrets/herokuplatformkey Medium Yes Yes
Veles npm Access Token veles.secrets/npmjsaccesstoken Medium Yes Yes
Veles OpenRouter API Key veles.secrets/openrouter Medium Yes None
Veles Packagist Organization Read Token veles.secrets/packagistorgreadtoken Medium Yes None
Veles Packagist Organization Read Token Repository URL (helper) veles.secrets/packagistorgreadtoken-repository Medium None None
Veles Packagist Organization Update Token veles.secrets/packagistorgupdatetoken Medium Yes None
Veles Packagist Organization Update Token Repository URL (helper) veles.secrets/packagistorgupdatetoken-repository Medium None None
Veles Packagist API Secret veles.secrets/packagistsecret Medium Yes None
Veles Packagist API Key (helper) veles.secrets/packagistsecret-api-key Medium None None
Veles Postman API Key veles.secrets/postmanapikey Medium Yes None
Veles Postman Collection Access Token veles.secrets/postmancollectiontoken Medium Yes None
Veles SendGrid API Key veles.secrets/sendgrid Medium Yes None
Veles Slack App Configuration Access Token veles.secrets/slackappconfigaccesstoken Medium Yes None
Veles Slack App Configuration Refresh Token veles.secrets/slackappconfigrefreshtoken Medium Yes None
Veles Slack App-Level Token veles.secrets/slackappleveltoken Medium Yes Yes