Secrets
Last updated: Oct 5, 2026
Supported
Currently, Fluid Attacks detects more than 290 types of hardcoded secrets. For about half of them, it also checks with the provider whether the secret is still active.
These are the secrets Fluid Attacks can detect, grouped by category, with examples of the providers covered:
- Cloud providers: AWS (access keys, session tokens, Cognito client secrets), Azure (SAS tokens, connection strings, DevOps personal access tokens), Google Cloud (API keys, service account keys), Alibaba Cloud, Cloudflare, DigitalOcean, Fly.io, Heroku, IBM Cloud, Linode, Netlify, Railway, Scaleway, Tencent Cloud, Vercel and Vultr
- Source code management, CI/CD and package registries: GitHub (all token types), GitLab, Bitbucket, Buildkite, CircleCI, Docker Hub, Drone CI, Jenkins, JFrog, npm, NuGet, Pulumi, PyPI, RubyGems, crates.io, TeamCity, Terraform Cloud and Travis CI
- AI and machine learning services: OpenAI, Anthropic, Cohere, DeepSeek, ElevenLabs, Groq, Hugging Face, Mistral, NVIDIA, OpenRouter, Perplexity, Pinecone, Replicate and xAI
- Payment processors and financial services: Stripe, PayPal, Braintree, Coinbase, Dwolla, Flutterwave, GoCardless, Mercado Pago, Pagar.me, Paystack, Plaid, Razorpay, Square, Wise and Xendit
- Communication and messaging: Slack (tokens and webhook URLs), Discord and Microsoft Teams webhook URLs, Mailchimp, Mailgun, Postmark, Resend, SendGrid, Brevo, Telegram, Twilio, Vonage, Webex and Zoom
- Monitoring and observability: Datadog, Dynatrace, Grafana, Honeycomb, New Relic, Opsgenie, PagerDuty, Rollbar, Sentry, Splunk and Sumo Logic
- Identity, secrets management and security tools: 1Password, Clerk, Doppler, Duo, HashiCorp Vault, JumpCloud, Keycloak, Okta, OneLogin, Ping Identity, Snyk, Stytch and Wiz
- Databases and data platforms: connection strings and credentials for PostgreSQL, MySQL, MariaDB, MongoDB, Redis, Oracle, IBM Db2, Couchbase, Neo4j, Snowflake, Amazon Redshift and RabbitMQ, and keys for Confluent, Databricks, Elastic, InfluxDB, PlanetScale and Supabase
- SaaS and productivity platforms: Airtable, Algolia, Atlassian (Jira, Confluence), Contentful, Figma, HubSpot, Intercom, Linear, Mapbox, Notion, Salesforce, Shopify, Typeform and Zendesk
- Credentials for protocols and services: FTP, LDAP, SMTP and SSH
- Keys and tokens: private keys (PEM, OpenSSH and PuTTY), JWT, and framework secrets (Django, Laravel and Ruby on Rails)
- Hardcoded credentials in configuration files
- Secrets in source code:
- Express-session secrets
- Hardcoded emails (in security-related contexts)
- Hardcoded environment variables
(e.g.,
api_key,password,secret) - Hardcoded secrets in cryptographic calls
- Initialization vectors
- Salts
- Symmetric keys
- Other obtained manually (only in the Advanced plan)
Unsupported
Fluid Attacks' secrets support does not currently include the following:
- Firebase Cloud Messaging server keys (Firebase web API keys are detected as Google Cloud API keys)
- Generic secrets (random values with no provider-specific format or context)
- HTTP basic authentication parameters
(e.g.,
https://user:password@hostURLs andAuthorization: Basicheaders) outside the supported databases and services - Kubernetes secrets
(
Secretmanifests and kubeconfig credentials) - MFA tokens (e.g., TOTP seeds and one-time password setup URIs)
- OAuth access and refresh tokens without a provider-specific format
- PGP private keys
Search for vulnerabilities in your apps for free with Fluid Attacks' automated security testing! Start your 21-day free trial and discover the benefits of the Essential plan. If you prefer the Advanced plan, which includes the expertise of Fluid Attacks' pentesting team, fill out this contact form.
SCM systems
Source code management systems supported by Fluid Attacks. Fluid Attacks is committed to adaptability so that it can integrate with your existing workflows.
Standards
Learn about the international security standards supported by Fluid Attacks to ensure compliance and enhance the security posture of your application.