| What it looks for | How it is detected | Example |
|---|---|---|
| Private key | A line that starts with -----BEGIN and names a PRIVATE KEY. |
-----BEGIN RSA PRIVATE KEY----- |
| API key with a known prefix | A prefix a provider puts on its keys, followed by a long run of letters and digits. Prefixes include sk-, ghp_, github_pat_, glpat-, xoxb-, AKIA, AIza, hf_, npm_, pypi-, SG. and whsec_. |
sk-proj-8fJ2kQ… |
| Login token (JWT) | Three parts joined by dots, the first two starting with eyJ. |
eyJhbGci….eyJzdWIi….SflKxw… |
| Password in a link | A link or connection string with a user name and password before the @. |
postgres://admin:hunter2@db.example.com |
| Labelled secret | A word such as password, pwd, passcode, secret, API key, access token, private key, 密码, 口令, 密钥 or 验证码, then : or =, then at least 4 characters. |
password: hunter22 |
| Card number | 13 to 19 digits, spaces or dashes allowed between groups, that pass the Luhn checksum card numbers use. | 4111 1111 1111 1111 |
| Random-looking string | 24 or more characters with no space, / or ., containing upper case, lower case and digits, and with high character entropy (3.5 bits or more per character). This catches keys with no known prefix and generated passwords. |
Q7vN2xLp9RkT4wZb8HcY3mJd |
What passes
Addresses, phone numbers, order numbers, file paths, domains and most links pass. The random-string rule does not count / or ., so paths and URLs split into short pieces and do not match.