Secrets management
Protecting secrets from AI agents
Tools 44
- enject - Hide .env secrets from AI coding toolsgithub.com
- Agent Vault - Keep secrets hidden from AI agentsgithub.com
- aivault - Stop leaking API keys to AI agentsaivault.moldable.sh
- WardGate - Give AI agents API access without giving them secretsgithub.com
- GAP - Give AI agents secure access to your APIsgithub.com
- DepthFirst - Secrets Shouldn't Be Guessworkdepthfirst.com
- agent-sweep - find and redact secrets in AI coding agent historiesgithub.com
- API Radar - live feed of leaked LLM API keys found on GitHubapiradar.live
- Automic Vault - secrets manager that authorizes exact operations for AI agentsautomicvault.com
- Betterleaks: The Gitleaks Successor Built for Faster Secrets Scanningaikido.dev
- Dave Blumenfeld introduces keypo vault - Mac Secure Enclave secrets manager for agentsx.com
- dumpscan - extract secrets from kernel and Windows minidump memorygithub.com
- ghtkn - CLI for short-lived GitHub App user access tokensgithub.com
- git-alerts - monitor GitHub org users' public repos for secrets and sensitive filesgithub.com
- git-hound - Scans GitHub for leaked secrets using GitHub dorksgithub.com
- github-actions-log-checker - scan GitHub Actions logs for exposed secretsgithub.com
- github-secrets - find secrets in dangling and force-pushed GitHub commitsgithub.com
- GitleaksVerifier - CLI tool to verify secrets flagged by Gitleaksgithub.com
- HasMySecretLeaked - GitGuardian search across exposed secrets on public GitHubgitguardian.com
- Infisical - secrets, certificates and identity platform for developers and agentsinfisical.com
- Introducing HAR Sanitizer: secure HAR sharingblog.cloudflare.com
- Introducing Kingfisher: Real-Time Secret Detection And Validationmongodb.com
- jit - just-in-time secrets behind Touch ID for your dev machinegithub.com
- KeyDrop - reducing API key abusekeydrop.io
- Kingfisher - secret scanner with live validation and blast-radius mappinggithub.com
- kubernetes-reflector - replicate secrets, configmaps and certificates across namespacesgithub.com
- LeakLens - web-aware secrets scanner for JS apps, source maps and Git historygithub.com
- LogShield - CLI that redacts secrets from logs before sharinggithub.com
- LUKSbox - encrypted container vaults with FIDO2, TPM 2.0 and post-quantum keyslotsgithub.com
- Madeline Lawrence on Betterleaks - new open source secrets scanner from the Gitleaks authorx.com
- mantra - hunt down API key leaks in JS files and pagesgithub.com
- Nosey Parker - finds secrets and sensitive information in text and Git historygithub.com
- OpenBao - open-source secrets, certificates and key managementgithub.com
- pivit - manage x509 certificates on PIV smart cards for git signinggithub.com
- postleaks - search for sensitive data in Postman public librarygithub.com
- retriever - secure client-side secret sharing in the browser using web cryptogithub.com
- Retriever - serverless secret sharing in the browser with Web Crypto, by Corgearetriever.corgea.io
- secret-bridge - Monitors GitHub for leaked secretsgithub.com
- secrets-patterns-db - open-source regex database for detecting secrets and API keysgithub.com
- sift - credential and sensitive-data exposure triage for file sharesgithub.com
- Straylight-AI - AI agent credential proxy for zero-knowledge secret managementaj-geddes.github.io
- Sulla - scan SMB shares for secrets with NoseyParkergithub.com
- truffleshow - client-side web viewer for TruffleHog JSON outputgithub.com
- webtrufflehog - browser extension scanning web traffic for exposed secretsgithub.com
Platform features 19
- Amp Code - Secret Redactionampcode.com
- Amp Security Reference - Secret Redactionampcode.com
- Secret Redaction in GitHub Copilot (Issue #11517)github.com
- Advanced Data Protection now available in HCP Vaulthashicorp.com
- Doppler Bug Bounty Program on HackerOnehackerone.com
- GitGuardian - Monitor Public GitHub for leaked secretsgitguardian.com
- GitHub secret scanning AI-generated custom patternsgithub.blog
- GitHub Secret Scanning Partner Programdocs.github.com
- GitHub secret scanning shows metrics for push protection at the organization levelgithub.blog
- HashiCorp acquires BluBracket to add secrets scanninghashicorp.com
- Introducing Cloudflare Secrets Store Betablog.cloudflare.com
- Introducing fine-grained personal access tokensgithub.blog
- Introducing GitHub Secret Protection and GitHub Code Securitygithub.blog
- Multi-secondary performance replication is now available on HCP Vaulthashicorp.com
- OpenTofu 1.7.0 with State Encryption and Provider-Defined Functionsopentofu.org
- Pasha Sviderski on Docker's native Secrets Engine - secret references injected at runtimex.com
- Secret scanning detects generic passwords with AI, public beta - GitHub Changeloggithub.blog
- Semantic Analysis for Secrets Detection - Semgrep Secretssemgrep.dev
- Vault PR 22484 - advanced TTL management for database static rolesgithub.com
Guides 32
- A better way to limit Claude Code access to secretspatrickmccanna.net
- Don't let AI read your .env files (Filip Hric / 1Password approach)filiphric.com
- Access Azure Key Vault from a Local Kubernetes Cluster with Azure Arc Workload Identitypowers-hell.com
- Anyone can Access Deleted and Private Repository Data on GitHub - Truffle Securitytrufflesecurity.com
- API Security Best Practices - Leak Mitigation Checklistgithub.com
- Automate Postman Secret Scanning with TruffleHogandrelia.net
- Azure AD Client Secret Leak: The Keys to Cloudresecurity.com
- Behind GitHub's new authentication token formatsgithub.blog
- Charlie Marsh on uv pipeline breaking over Bearer Token redaction in GitHub Actionsx.com
- Cracking the Vault: Zero-Day Flaws in Authentication, Identity, and Authorization in HashiCorp Vaultcyata.ai
- Detecting and removing dangerous secrets on dev workstations before Shai-Hulud doesrecyclebin.zip
- Google API keys keep working after you delete them long enough to be exploitedaikido.dev
- Google API Keys Weren't Secrets, But Then Gemini Changed the Rulestrufflesecurity.com
- Hidden GitHub Commits and How to Reveal Themneodyme.io
- How I Found 3,800+ Leaked Secrets on GitHub Archive Using AIaydinnyunus.github.io
- How I Scanned all of GitHub's Oops Commits for Leaked Secrets - Truffle Securitytrufflesecurity.com
- How to Monitor GitHub for Secrets - Duo Labsduo.com
- jtgi on wallet drained after leaked private key in old public GitHub commitx.com
- Keeping Secrets Out of Logsallan.reyes.sh
- Leaked-Credentials - finding leaked credentials with DevTools regexgithub.com
- Making TruffleHog Faster with Aho-Corasicktrufflesecurity.com
- Martez Reed on authenticating to HashiCorp Vault from Proxmox with JWT authx.com
- Native Secure Enclave backed SSH keys on macOSgist.github.com
- Regex is almost all you need - how Gitleaks combines regex, entropy and allowlists to find secretslookingatcomputer.substack.com
- The Day We Unveiled the Secret Rotation Illusionclutch.security
- The end of GitHub PATs: You can't leak what you don't havechainguard.dev
- The Postman Carries Lots of Secrets - leaked credentials in public Postman workspacestrufflesecurity.com
- The State of Secrets Sprawl Report 2025gitguardian.com
- The Trivy Attack Revealed a Blind Spot in Every Secrets Managervaultproof.dev
- Thousands of Exposed Secrets Found on Docker Hubflare.io
- Top HashiCorp Vault Alternativesinfisical.com
- Unauthorized access to any organization's Codespace secrets via a GitHub Security Advisory flawophionsecurity.com