Supported Secret Types
Radar detects over 120 types of secrets and credentials across cloud providers, AI platforms, payment services, databases, CI/CD pipelines, identity providers, SaaS tools, and more. Each detection uses format-specific patterns and contextual analysis to minimize false positives.
Continuous Updates
This page lists the most common supported types, but Radar detects many more. New detection patterns are added continuously as providers introduce new credential formats. Beyond known providers, Radar's entropy analysis and AI-powered contextual detection identify internal secrets, custom tokens, and credentials from providers not listed here. See Custom Detection Rules to add patterns for your organization's own credential formats.
Cloud Providers
| Secret Type | Risk | Remediation |
|---|---|---|
AWS Access Key (AKIA...) | Critical | Deactivate in IAM console, rotate key pair, migrate to IAM roles |
| AWS Secret Access Key | Critical | Rotate both keys, check CloudTrail for unauthorized usage |
| Azure Key | High | Rotate in Azure Portal, migrate to managed identities |
| GCP Service Account Key | Critical | Delete key in IAM & Admin, migrate to Workload Identity Federation |
| Alibaba Cloud AccessKey | High | Rotate in Alibaba Cloud console, restrict RAM permissions |
DigitalOcean Token (dop_v1_...) | High | Revoke in Control Panel, generate new token with minimum scopes |
| Cloudflare API Token | High | Roll token in dashboard, use scoped API tokens |
| Heroku API Key | High | Regenerate in Heroku account settings |
| IBM Cloud API Key | High | Rotate in IBM Cloud IAM, review activity tracker |
| Netlify Token | Medium | Regenerate in Netlify user settings |
| Oracle Cloud Key | High | Rotate in OCI console, review audit logs |
| Railway Token | Medium | Regenerate in Railway dashboard |
| Render API Key | Medium | Regenerate in Render account settings |
| Vercel Token | Medium | Regenerate in Vercel account settings |
AI and Machine Learning
| Secret Type | Risk | Remediation |
|---|---|---|
OpenAI API Key (sk-...) | High | Rotate in OpenAI dashboard, review usage logs for unauthorized consumption |
| Anthropic API Key | High | Regenerate in Anthropic console |
HuggingFace Token (hf_...) | Medium | Revoke in HuggingFace settings, generate new token |
| Mistral API Key | High | Rotate in Mistral platform |
| Cohere API Key | Medium | Regenerate in Cohere dashboard |
| Perplexity API Key | Medium | Rotate in Perplexity settings |
| Replicate API Token | Medium | Regenerate in Replicate account |
| Stability AI Key | Medium | Rotate in Stability AI platform |
| Vertex AI Credentials | High | Rotate GCP service account, review Cloud Audit Logs |
| Baseten API Key | Medium | Regenerate in Baseten dashboard |
| LangChain API Key | Medium | Rotate in LangSmith settings |
| LangSmith API Key | Medium | Rotate in LangSmith settings |
| Pinecone API Key | Medium | Regenerate in Pinecone console |
| Chroma Token | Medium | Rotate in Chroma Cloud settings |
| Qdrant API Key | Medium | Regenerate in Qdrant Cloud |
| Weaviate API Key | Medium | Rotate in Weaviate Cloud console |
| Vespa Token | Medium | Regenerate in Vespa Cloud |
Payment Services
| Secret Type | Risk | Remediation |
|---|---|---|
Stripe Secret Key (sk_live_...) | Critical | Roll in Stripe Dashboard (supports transition period), review Event log |
| Stripe CLI Key | High | Regenerate in Stripe CLI settings |
Square Access Token (sq0atp-...) | High | Regenerate in Square Developer Dashboard |
Square OAuth Secret (sq0csp-...) | High | Rotate in app settings |
| PayPal Client Secret | High | Rotate in PayPal Developer Portal |
| Adyen API Key | Critical | Rotate in Adyen Customer Area |
| Braintree Key | High | Regenerate in Braintree Control Panel |
| Paddle API Key | High | Rotate in Paddle dashboard |
| Razorpay Key | High | Regenerate in Razorpay dashboard |
| Revolut API Key | High | Rotate in Revolut Business settings |
| Wise API Token | High | Regenerate in Wise API settings |
Databases and Storage
| Secret Type | Risk | Remediation |
|---|---|---|
MongoDB Connection String (mongodb+srv://...) | Critical | Change password, restrict network access with IP allowlists |
| PostgreSQL Connection String | Critical | Rotate password, review pg_stat_activity, enable SSL/TLS |
| MySQL Connection String | Critical | ALTER USER to change password, restrict grants |
| Redis Connection URL | High | CONFIG SET requirepass, enable TLS, restrict network access |
| Elasticsearch Credentials | High | Rotate in Elasticsearch security settings |
| Firebase Config | Medium | Restrict API key in Firebase console, review security rules |
| Google Cloud Storage Key | High | Rotate service account key, review access logs |
| Supabase Key | High | Rotate in Supabase project settings |
| Cloudant (IBM) Credentials | High | Rotate in IBM Cloudant dashboard |
CI/CD and Deployment
| Secret Type | Risk | Remediation |
|---|---|---|
GitHub Personal Access Token (ghp_...) | High | Revoke in GitHub Settings, generate new token with minimum scopes |
| GitHub Actions Secret | High | Rotate in repository or organization settings |
GitLab Personal Access Token (glpat-...) | High | Revoke in GitLab Preferences, review audit events |
| GitLab CI Token | High | Regenerate in GitLab CI/CD settings |
| Bitbucket Token | High | Rotate in Bitbucket app passwords |
| Bitbucket CI Variable | High | Update in repository pipeline settings |
| Azure DevOps Token | High | Regenerate in Azure DevOps user settings |
| CircleCI Token | High | Regenerate in CircleCI User Settings |
| Travis CI Token | Medium | Regenerate in Travis CI account settings |
| Jenkins Secret | High | Rotate in Jenkins Credentials store |
| Drone CI Token | Medium | Regenerate in Drone CI account |
| Cloudflare Deploy Token | Medium | Roll in Cloudflare Pages/Workers settings |
| Terraform Cloud Token | High | Regenerate in Terraform Cloud user settings |
| Pulumi Access Token | High | Rotate in Pulumi Cloud settings |
Identity Providers
| Secret Type | Risk | Remediation |
|---|---|---|
| Auth0 Secret | High | Rotate in Auth0 application settings, review tenant logs |
| Okta API Token | High | Revoke in Okta Admin Console, generate new token |
| Clerk Secret Key | High | Rotate in Clerk dashboard |
| Firebase Auth Credentials | High | Rotate in Firebase project settings |
| SuperTokens Key | Medium | Regenerate in SuperTokens dashboard |
Monitoring and Analytics
| Secret Type | Risk | Remediation |
|---|---|---|
| Datadog API Key | Medium | Revoke in Datadog Organization Settings, update all agents |
| Datadog Application Key | High | Revoke in user settings |
| New Relic License Key | Medium | Rotate in New Relic Account Settings |
| Sentry DSN | Medium | Create new Client Key in Sentry, disable old key |
| Amplitude API Key | Medium | Regenerate in Amplitude project settings |
| Logtail Token | Medium | Rotate in Logtail source settings |
| Mixpanel Token | Medium | Regenerate in Mixpanel project settings |
Communication and Messaging
| Secret Type | Risk | Remediation |
|---|---|---|
SendGrid API Key (SG....) | High | Revoke in SendGrid dashboard, create new key with minimum permissions |
Mailgun API Key (key-...) | High | Reset in Mailgun Control Panel |
| Mailchimp API Key | Medium | Regenerate in Mailchimp account settings |
| Postmark Server Token | Medium | Regenerate in Postmark dashboard |
| Twilio Auth Token | High | Rotate in Twilio Console, review usage logs |
Slack Bot Token (xoxb-...) | High | Revoke in app settings, reinstall app for new tokens |
| Slack Webhook URL | Medium | Regenerate webhook URL in app settings |
| Discord Bot Token | High | Regenerate in Discord Developer Portal |
| Telegram Bot Token | Medium | Revoke via BotFather, create new token |
| WhatsApp Cloud API Token | High | Rotate in Meta Business settings |
| Vonage API Secret | High | Regenerate in Vonage dashboard |
| Plivo Auth Token | High | Rotate in Plivo console |
| Zoom API Secret | Medium | Regenerate in Zoom Marketplace app settings |
| SMTP Credentials | High | Change password at email provider |
SaaS Platforms
| Secret Type | Risk | Remediation |
|---|---|---|
| Algolia API Key | Medium | Regenerate in Algolia dashboard, use search-only keys client-side |
| Stripe CLI Key | High | Regenerate in Stripe CLI settings |
| Intercom Access Token | Medium | Rotate in Intercom developer hub |
| Segment Write Key | Medium | Regenerate in Segment source settings |
| Posthog API Key | Medium | Rotate in Posthog project settings |
| Linear API Key | Medium | Regenerate in Linear settings |
| Cloudinary Credentials | Medium | Rotate in Cloudinary console |
| Typeform Token | Medium | Regenerate in Typeform account |
| Calendly API Key | Low | Rotate in Calendly integrations |
| Crisp Token | Low | Regenerate in Crisp settings |
| Fathom API Key | Low | Rotate in Fathom settings |
| Imgix Token | Low | Regenerate in Imgix dashboard |
| Saasquatch API Key | Low | Rotate in Saasquatch portal |
Cryptographic Keys
| Secret Type | Risk | Remediation |
|---|---|---|
RSA Private Key (-----BEGIN RSA PRIVATE KEY-----) | Critical | Revoke associated certificates, generate new key pair |
SSH Private Key (-----BEGIN OPENSSH PRIVATE KEY-----) | Critical | Remove public key from authorized_keys on all servers, generate new pair |
PGP Private Key (-----BEGIN PGP PRIVATE KEY BLOCK-----) | Critical | Publish revocation certificate, generate new pair |
X.509 Certificate with Private Key (.pfx, .p12) | Critical | Revoke certificate with CA, generate new key and certificate |
Authentication Tokens
| Secret Type | Risk | Remediation |
|---|---|---|
| JWT Signing Key | Critical | Rotate signing key, invalidate all existing tokens |
| OAuth Client Secret | High | Regenerate at identity provider (Auth0, Okta, Azure AD) |
npm Access Token (npm_...) | High | Revoke in npm account settings, generate new token |
| Artifactory Token | High | Regenerate in JFrog Artifactory settings |
| Basic Auth Credentials | High | Change password, migrate to token-based authentication |
| Bearer Tokens | High | Revoke at issuing service, store replacement in secret manager |
| Generic High-Entropy Secrets | Variable | Identified through entropy analysis and contextual signals. Assess based on context |
Next Steps
Secret Detection Overview
How Radar's detection engine combines pattern matching, entropy analysis, and AI context.
View Secret Findings
Navigate, filter, and understand the secret findings table.
Triage and Remediation
Rotate, revoke, and remediate detected secrets.
Custom Detection Rules
Define organization-specific patterns for internal credentials and proprietary tokens.