Apidog Docs
🇺🇸 English
  • 🇺🇸 English
  • 🇯🇵 日本語
  • 🇪🇸 Español
  • 🇰🇷 한국인
  • 🇨🇳 简体中文
  • 🇵🇹 Português (Portugal)
  • 🇮🇩 Bahasa Indonesia
  • 🇧🇷 Português (Brasil)
  • 🇻🇳 Tiếng Việt
  • 🇨🇳 繁體中文
🇺🇸 English
  • 🇺🇸 English
  • 🇯🇵 日本語
  • 🇪🇸 Español
  • 🇰🇷 한국인
  • 🇨🇳 简体中文
  • 🇵🇹 Português (Portugal)
  • 🇮🇩 Bahasa Indonesia
  • 🇧🇷 Português (Brasil)
  • 🇻🇳 Tiếng Việt
  • 🇨🇳 繁體中文
🇺🇸 English
  • 🇺🇸 English
  • 🇯🇵 日本語
  • 🇪🇸 Español
  • 🇰🇷 한국인
  • 🇨🇳 简体中文
  • 🇵🇹 Português (Portugal)
  • 🇮🇩 Bahasa Indonesia
  • 🇧🇷 Português (Brasil)
  • 🇻🇳 Tiếng Việt
  • 🇨🇳 繁體中文
HomeLearning Center
Support CenterAPI ReferencesDownloadChangelog
HomeLearning Center
Support CenterAPI ReferencesDownloadChangelog
  1. Data & Security
  • Apidog Learning Center
  • Getting Started
    • Introduction to Apidog
    • Basic Concepts in Apidog
    • Navigating Apidog
    • Quick Start
      • Overview
      • Creating an Endpoint
      • Making a Request
      • Adding an Assertion
      • Creating Test Scenarios
      • Sharing API Documentation
      • Explore More
    • Migration to Apidog
      • Overview
      • Manual Import
      • Scheduled Import (Bind Data Sources)
      • Import Options
      • Export Data
      • Import From
        • Import from Postman
        • Import from Stoplight
        • Import OpenAPI Spec
        • Import cURL
        • Import Markdowns
        • Import from Insomnia
        • Import from apiDoc
        • Import .har File
        • Import WSDL
  • Design APIs
    • Overview
    • Create a New API Project
    • Endpoint Basics
    • APl Design Guidelines
    • Module
    • Configure Multiple Request Body Examples
    • Components
    • Common Fields
    • Global Parameters
    • Endpoint Change History
    • Comments
    • Batch Endpoint Management
    • Custom Protocol API
    • Spec-first Mode (Beta)
    • Schemas
      • Overview
      • Create a New Schema
      • Build a Schema
      • Generate Schemas from JSON Etc
      • oneOf, allOf, anyOf
      • Using Discriminator
    • Security Schemes
      • Overview
      • Create a Security Scheme
      • Use the Security Scheme
      • Security Scheme in Online Documentation
    • Advanced Features
      • Custom Endpoint Fields
      • Associated Test Scenarios
      • Endpoint Status
      • Appearance of Parameter Lists
      • Endpoint Unique Identification
  • Develop and Debug APIs
    • Overview
    • Generating Requests
    • Sending Requests
    • Debugging Cases
    • Test Cases
    • Dynamic Values
    • Validating Responses
    • Design-First vs Request-First
    • Generating Code
    • AI Debugging
      • AI Agent Debugger
      • A2A Debugger
    • Environments & Variables
      • Overview
      • Using Variables
      • Environment Management
    • Vault Secrets
      • Overview
      • HashiCorp Vault
      • Azure Key Vault
      • AWS Secrets Manager
    • Pre and Post Processors
      • Overview
      • Assertion
      • Extract Variable
      • Wait
      • Security
      • Database Operations
        • Overview
        • MySQL
        • MongoDB
        • Redis
        • Oracle Client
      • Using Scripts
        • Overview
        • Pre Processor Scripts
        • Post Processor Scripts
        • Public Scripts
        • Postman Scripts Reference
        • Calling Other Programming Languages
        • Using JS Libraries
        • Visualizing Responses
        • Script Examples
          • Assertion Scripts
          • Using Variables
          • Modifying Requests
          • Other Examples
    • Dynamic Values Modules
  • Mock API Data
    • Overview
    • Smart Mock
    • Custom Mock
    • Mock Priority Sequence
    • Mock Scripts
    • Cloud Mock
    • Self-Hosted Runner Mock
    • Mock Language (Locales)
  • API Testing
    • Overview
    • Test Reports
      • Test Reports
    • Test Scenarios
      • Create a Test Scenario
      • Pass Data Between Requests
      • Flow Control Conditions
      • Sync Data from Endpoints and Endpoint Cases
      • Import Endpoints and Endpoint Cases from Other Projects
      • Export Test Scenarios
    • Run Test Scenarios
      • Run a Test Scenario
      • Run Test Scenarios in Batch
      • Data-Driven Testing
      • Shared Test Data
      • Scheduled Tasks
      • Manage Runtime Environment of APIs from Other Projects
    • Test APIs
      • Integration Testing
      • Performance Testing
      • End-to-End Testing
      • Regression Testing
      • Contract Testing
    • Test Suite
      • Overview
      • Create A Test Suite
      • Orchestrate Test Suite
      • Run Test Suites Locally
      • Scheduled Tasks
  • Apidog CLI
    • Overview
    • Installing and Running Apidog CLI
    • Run Test Suites Via CLI
    • Apidog CLI Commands & Options
    • Use Apidog CLI with an AI Agent
    • CI CD
      • Overview
      • Trigger Test by Git Commit
      • Integrate with Github Actions
      • Integrate with Gitlab
      • Integrate with Jenkins
  • Publish API Docs
    • Overview
    • API Technologies Supported
    • Quick Share
    • Viewing API Documentation
    • Markdown Documentation
    • Publishing Documentation Sites
    • Custom Login Page
    • Custom Layouts
    • Custom CSS, JavaScript, HTML
    • Custom Domain
    • AI Features
    • SEO Settings
    • Advanced Settings
      • Documentation Search
      • CORS Proxy
      • Integrating Google Analytics
      • Folder Tree Settings
      • Visibility Settings
      • Embedding Values in Document URLs
    • API Versions
      • Overview
      • Creating API Versions
      • Publishing API Versions
      • Sharing Endpoints with API Versions
  • Send Requests
    • Overview
    • SSE Debugging
    • MCP Client
    • Socket.IO
    • WebSocket
    • Webhook
    • SOAP or WebService
    • GraphQL
    • gRPC
    • Use Request Proxy Agents for Debugging
    • Create Requests
      • Request History
      • Request Basics
      • Parameters and Body
      • Request Headers
      • Request Settings
      • Debug Requests
      • Saving Requests as Endpoints
      • HTTP/2
    • Response and Cookies
      • Viewing API Responses
      • Managing Cookies
      • Overview
    • Authentication and Authorization
      • Overview
      • CA and Client Certificates
      • Authorization Types
      • Digest Auth
      • OAuth 1.0
      • OAuth 2.0
      • Hawk Authentication
      • Kerberos
      • NTLM
      • Akamai EdgeGrid
  • Branches
    • Overview
    • Creating a Sprint Branch
    • Testing APIs in a Branch
    • Designing APIs in a Branch
    • Merging Sprint Branches
    • Managing Sprint Branches
    • AI Branch (Beta)
  • AI Features
    • Overview
    • Enabling AI Features
    • Generating Test Cases
    • Modifying Schemas with AI
    • Endpoint Compliance Check
    • API Documentation Completeness Check
    • AI-Powered Field Naming
    • FAQs
  • Apidog MCP Server
    • Overview
    • Connect Apidog Project to AI
    • Connect Published Documentation to AI
    • Connect OpenAPI Files to AI
  • Best Practices
    • Handling API Signatures
    • Accessing OAuth 2.0 Protected APIs
    • Collaboration Workflow
    • Managing Authentication State
  • Offline Space
    • Overview
  • Administration
    • Onboarding Checklist
      • Basic Concepts
      • Onboarding Guide
    • Managing Projects
      • Managing Projects
      • Notification Settings
      • Managing Project Members
      • Project Resources
        • Database Connection
        • Git Connection
    • Managing Teams
      • Managing Teams
      • Managing Team Members
      • Team Activities
      • Team Roles & Permissions
      • Team Resources
        • General Runner
        • Team Variables
        • Request Proxy Agent
      • Real-time Collaborations
        • Team Collaboration
    • Managing Organization
      • Managing Organization
      • Organization Role & Permissions
      • Audit Logs
      • Single Sign-On (SSO)
        • SSO Overview
        • Configuring Microsoft Entra ID
        • Configuring Okta
        • Configuring SSO for an Organization
        • Managing User Accounts
        • Mapping Groups to Teams
      • SCIM Provisioning
        • Introduction to SCIM Provisioning
        • Microsoft Entra ID
        • Okta
      • Plans Management
        • Billing Managers in Organizations
      • Organization Resources
        • Self-Hosted Runner
  • Billing
    • Overview
    • Credits
    • Upgrading Your Plan
    • Alternative Payment Methods
    • Managing Subscriptions
    • Moving Paid Teams to Organizations
  • Data & Security
    • Data Storage and Security
    • User Data Privacy and Security
    • Request Routing and Data Security
    • Secret Scanner
  • Add-ons
    • API Hub
    • Apidog Intellij IDEA Plugin
    • Browser Extension
      • Chrome
      • Microsoft Edge
    • Request Proxy
      • Request Proxy in Web
      • Request Proxy in Shared Docs
      • Request Proxy in Client
  • Account & Preferences
    • Account Settings
    • Generating OpenAPI Access Token
    • Notification
    • Language Settings
    • Hot Keys
    • Network Proxy Configuration
    • Backing Up Data
    • Updating Apidog
    • Deleting Account
    • Experimental Features
  • References
    • API Design-First Approach
    • Apidog OpenAPI Specificaiton Extensions
    • JSONPath
    • XPath
    • Regular Expressions
    • JSON Schema
    • CSV File Format
    • Installing Java Environment
    • Runner Deployment Environment
    • Apidog Markdown Syntax
    • Apidog Swagger Extensions
      • Overview
      • x-apidog-folder
      • x-apidog-status
      • x-apidog-name
      • x-apidog-maintainer
    • Apidog JSON Schema Extensions
      • Overview
      • x-apidog-mock
      • x-apidog-orders
      • x-apidog-enum
  • Apidog Europe
    • Apidog Europe
  • Support Center
  1. Data & Security

Secret Scanner

Secret Scanner helps you detect possible exposed secrets in Apidog assets, such as API keys, access tokens, credentials, webhook URLs, and other sensitive values. You can use Secret Scanner to review detected secrets, locate where they appear, manage detection patterns, and track whether a finding has been handled.
Secret Scanner is available on Enterprise plans. Access to reports, analytics, and pattern management depends on your organization, team, and project permissions.

What You Can Do With Secret Scanner#

With Secret Scanner, you can:
View secret risk reports across teams in an organization.
Review detected secrets in a team.
Locate where a detected secret appears.
Check whether a detected secret appears in published documentation.
Mark findings as resolved or reopen them.
Manage built-in and team custom detection patterns.
View team-level analytics for detected secrets.
Secret Scanner helps you detect and review possible exposed secrets. It does not automatically revoke, rotate, remove, or replace secrets for you.

Permissions#

Secret Scanner follows your organization, team, and project permissions.
RoleAvailable actions
Org Owner / AdminView organization-level Secret Scanner reports.
Team Owner / AdminView team findings, manage custom patterns, resolve or reopen findings, and view analytics.
Team Member / GuestView Secret Scanner information according to their project access permissions.
Team Members and Guests can only view findings for projects they have access to. They cannot manage custom patterns or view team analytics.

Organization Secret Scanner Reports#

Organization-level reports help Org Owners and Org Admins identify which teams have unresolved secret risks.
1
Go to your Organization Settings.
2
In the Security menu, click Secret Scanner.
image.png
The organization report provides a team-level overview, including:
Teams
Unresolved findings
Published leaks
Matched patterns
Team owner and admins
Occurrences
Scan status
Last detected time
Use this report to identify affected teams and contact the corresponding Team Owner or Team Admin for follow-up.

Team Secret Scanner#

Team-level Secret Scanner is available from team management.
image.png
1
Open the target Team.
2
Go to Team Management.
3
Click Secret Scanner.
Team Secret Scanner includes the following sections:
SectionDescription
Secrets DetectedReview detected secret findings and their status.
PatternsView built-in patterns and manage team custom patterns.
AnalyticsView team-level statistics for detected secrets. Available to Team Owners and Team Admins.

Review Detected Secrets#

Open Secrets Detected to view detected secret findings in the current team.
image.png
A finding represents a detected secret grouped by its detection pattern and secure fingerprint. A finding may appear in multiple places. Each place where it appears is called an occurrence.
The findings list includes information such as:
Status
Pattern
Masked secret value
Related project
Resource type
Occurrence count
Published exposure
First detected time
Last detected time
Secret Scanner supports the following finding statuses:
StatusDescription
UnresolvedThe finding still needs review or handling.
ResolvedThe finding has been handled or confirmed as not requiring further action.
You can filter findings by:
Status
Project
Pattern
Resource type
Keyword
Secret values are masked in Secret Scanner. Apidog does not display the full raw secret value in the findings list or detail page.

Resolve or reopen a finding#

After reviewing a finding, you can update its resolution status.
Supported resolution reasons include:
Resolution reasonWhen to use it
RevokedThe exposed secret was real, and you have revoked, rotated, or invalidated it outside Apidog.
False positiveThe detected value is not an actual secret.
Won't fixThe detected value is a real secret, but your team has decided not to change it.
You can also reopen a resolved finding if it still needs follow-up.
1
Open Secrets Detected.
2
Select one or more findings.
3
Choose a resolution action, such as Revoked, False positive, or Won't fix.
4
Add an optional note if needed.
5
Confirm the update.
Marking a finding as resolved only updates its status in Apidog. It does not revoke, rotate, or invalidate the actual secret. If the secret is real, handle it in the service where it was issued.

Manage detection patterns#

Open Patterns to view and manage detection rules.
Secret Scanner supports two types of patterns:
Pattern typeDescription
Built-inDetection patterns provided by Apidog. Built-in patterns are read-only.
CustomTeam-level patterns created by Team Owners or Team Admins.

Built-in patterns#

Built-in patterns are managed by Apidog. You can view and search them, but you cannot edit, delete, enable, or disable them.
For security reasons, Apidog does not expose the internal regular expressions of built-in patterns.

Custom patterns#

Team Owners and Team Admins can create custom patterns to detect organization-specific secret formats.
A custom pattern includes:
Name
Regex pattern
Keywords
Custom pattern limits include:
ItemLimit
Custom rules per teamUp to 5
NameUp to 128 characters
Regex patternUp to 256 characters in the UI
KeywordsUp to 10
Each keywordUp to 64 characters
Custom patterns can be enabled or disabled.
StatusDescription
EnabledThe pattern is active and can produce new findings.
DisabledThe pattern is inactive and does not produce new findings.
Only Team Owners and Team Admins can create, edit, delete, enable, or disable custom patterns.

View analytics#

Team Owners and Team Admins can open Analytics to review team-level Secret Scanner statistics.
image.png
Analytics may include:
Total findings
Resolved findings
Unresolved findings
Unresolved occurrences
Active occurrences
Live public exposures
Top vulnerable projects
Top risk generators
Most leaked patterns
Exposure by asset type
Use analytics to understand where secret risks are concentrated and prioritize follow-up.

Scan behavior#

Secret Scanner runs asynchronously. Results are not real-time. Last detected shows when the finding was last detected by the scanner.
This means, scans are triggered when:
New resources are added, such as the ones listed in the Supported asset types section.
The Save button is clicked after making changes to any of the assets.
Secret Scanner can help detect possible exposed secrets, but it cannot guarantee that every possible secret will be found. Continue to follow your team’s security review and credential management practices.

Supported asset types#

Secret Scanner can detect secrets across supported team and project assets, including:
APIs and API requests
API cases
Project modules
Project module variables
Response examples
Markdown documents
Data schemas
Environment variables
Global variables
Team variables
Common scripts
Common parameters
The exact source location shown for each occurrence depends on the resource type and your access permissions.

Security notes#

To protect sensitive information, Apidog handles detected secrets carefully:
Full secret values are not displayed in the UI.
Findings show masked values and masked snippets.
Findings are grouped using secure fingerprints instead of exposing the original secret value.
Access to findings follows organization, team, and project permissions.
Custom pattern regex values are visible only to users with the required team management permissions.

Limitations#

Secret Scanner does not:
Prevent users from entering secrets.
Block API documentation publishing.
Automatically revoke or rotate external secrets.
Automatically remove secrets from source resources.
Automatically replace secrets with variables or vault references.
Scan external GitHub or GitLab repositories.
Guarantee complete detection of all possible secret formats.
If a real secret is detected, remove it from the source location and revoke or rotate it in the external system where it was issued.
Modified at 2026-07-28 10:30:01
Previous
Request Routing and Data Security
Next
API Hub
Built with