Secrets

Last updated: Oct 5, 2026


Supported

Currently, Fluid Attacks detects more than 290 types of hardcoded secrets. For about half of them, it also checks with the provider whether the secret is still active.

These are the secrets Fluid Attacks can detect, grouped by category, with examples of the providers covered:

  • Cloud providers: AWS (access keys, session tokens, Cognito client secrets), Azure (SAS tokens, connection strings, DevOps personal access tokens), Google Cloud (API keys, service account keys), Alibaba Cloud, Cloudflare, DigitalOcean, Fly.io, Heroku, IBM Cloud, Linode, Netlify, Railway, Scaleway, Tencent Cloud, Vercel and Vultr
  • Source code management, CI/CD and package registries: GitHub (all token types), GitLab, Bitbucket, Buildkite, CircleCI, Docker Hub, Drone CI, Jenkins, JFrog, npm, NuGet, Pulumi, PyPI, RubyGems, crates.io, TeamCity, Terraform Cloud and Travis CI
  • AI and machine learning services: OpenAI, Anthropic, Cohere, DeepSeek, ElevenLabs, Groq, Hugging Face, Mistral, NVIDIA, OpenRouter, Perplexity, Pinecone, Replicate and xAI
  • Payment processors and financial services: Stripe, PayPal, Braintree, Coinbase, Dwolla, Flutterwave, GoCardless, Mercado Pago, Pagar.me, Paystack, Plaid, Razorpay, Square, Wise and Xendit
  • Communication and messaging: Slack (tokens and webhook URLs), Discord and Microsoft Teams webhook URLs, Mailchimp, Mailgun, Postmark, Resend, SendGrid, Brevo, Telegram, Twilio, Vonage, Webex and Zoom
  • Monitoring and observability: Datadog, Dynatrace, Grafana, Honeycomb, New Relic, Opsgenie, PagerDuty, Rollbar, Sentry, Splunk and Sumo Logic
  • Identity, secrets management and security tools: 1Password, Clerk, Doppler, Duo, HashiCorp Vault, JumpCloud, Keycloak, Okta, OneLogin, Ping Identity, Snyk, Stytch and Wiz
  • Databases and data platforms: connection strings and credentials for PostgreSQL, MySQL, MariaDB, MongoDB, Redis, Oracle, IBM Db2, Couchbase, Neo4j, Snowflake, Amazon Redshift and RabbitMQ, and keys for Confluent, Databricks, Elastic, InfluxDB, PlanetScale and Supabase
  • SaaS and productivity platforms: Airtable, Algolia, Atlassian (Jira, Confluence), Contentful, Figma, HubSpot, Intercom, Linear, Mapbox, Notion, Salesforce, Shopify, Typeform and Zendesk
  • Credentials for protocols and services: FTP, LDAP, SMTP and SSH
  • Keys and tokens: private keys (PEM, OpenSSH and PuTTY), JWT, and framework secrets (Django, Laravel and Ruby on Rails)
  • Hardcoded credentials in configuration files
  • Secrets in source code:
    • Express-session secrets
    • Hardcoded emails (in security-related contexts)
    • Hardcoded environment variables (e.g., api_key, password, secret)
    • Hardcoded secrets in cryptographic calls
    • Initialization vectors
    • Salts
    • Symmetric keys
  • Other obtained manually (only in the Advanced plan)

Unsupported

Fluid Attacks' secrets support does not currently include the following:

  • Firebase Cloud Messaging server keys (Firebase web API keys are detected as Google Cloud API keys)
  • Generic secrets (random values with no provider-specific format or context)
  • HTTP basic authentication parameters (e.g., https://user:password@host URLs and Authorization: Basic headers) outside the supported databases and services
  • Kubernetes secrets (Secret manifests and kubeconfig credentials)
  • MFA tokens (e.g., TOTP seeds and one-time password setup URIs)
  • OAuth access and refresh tokens without a provider-specific format
  • PGP private keys

On this page