Token & Key Detectors
github_token
Detects GitHub personal access tokens (ghp_, gho_, ghu_, ghs_, ghr_ followed by 36 base62 characters).
ts
const redactor = createRedactor({
rules: { github_token: { action: "redact" } },
});
redactor.redact("Token: ghp_1234567890abcdefghijklmnopqrstuvwxyz1234");
// "Token: [GITHUB_TOKEN_1]"- ID:
github_token - Entity type:
github_token - Context required: No
- Stream supported: Yes
- Validation: ghp_/gho_/ghu_/ghs_/ghr_ prefix + 36 base62 chars
jwt_token
Detects JWT tokens (3 base64url segments separated by dots).
ts
const redactor = createRedactor({
rules: { jwt_token: { action: "redact" } },
});
redactor.redact(
"Authorization: Bearer eyJhbGciOiJIUzI1NiJ9.eyJzdWIiOiIxMjM0NTY3ODkwIn0.abc123",
);
// "Authorization: Bearer [JWT_TOKEN_1]"- ID:
jwt_token - Entity type:
jwt_token - Context required: No
- Stream supported: Yes
- Validation: 3 base64url segments separated by dots
private_key
Detects PEM-encoded private keys (RSA, EC, OpenSSH, PGP).
ts
const redactor = createRedactor({
rules: { private_key: { action: "redact" } },
});
redactor.redact(
"-----BEGIN RSA PRIVATE KEY-----\nMIIEpAIBAAKCAQEA...\n-----END RSA PRIVATE KEY-----",
);
// "[PRIVATE_KEY_1]"- ID:
private_key - Entity type:
private_key - Context required: No
- Stream supported: Yes
- Validation: PEM header/footer for RSA, EC, OpenSSH, or PGP keys
generic_api_key
Detects generic API keys with context labels. Requires nearby labels like "API key", "API secret", "access token", etc.
ts
const redactor = createRedactor({
rules: { generic_api_key: { action: "redact" } },
});
redactor.redact("API key: sk_test_1234567890abcdef");
// "API key: [GENERIC_API_KEY_1]"- ID:
generic_api_key - Entity type:
generic_api_key - Context required: Yes (labels: API key, API secret, access token, etc.)
- Stream supported: Yes
- Validation: Context label presence