{"uid":"cap_ehJKlL3R43Qud2WVEDhxx","slug":"github-gitlab-secret-scanner-997369c2","name":"GitHub/GitLab Secret Scanner","description":"Scan public GitHub/GitLab repositories associated with a domain for exposed API keys, tokens, and credentials committed in source code. Call to detect a common supply-chain exposure vector before it's exploited.","url":"https://atq6wtkp6k.execute-api.us-east-1.amazonaws.com/prod/v1/payg/secret-scan","method":"POST","headers":{},"bodySchema":{"type":"object","properties":{"domain":{"type":"string","description":"Your own domain"},"vendor_domains":{"type":"array","items":{"type":"string"},"description":"Optional: vendor domains, up to 5"}}},"responseSchema":null,"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.35","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.35/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.35","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.35","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_QquEMzdblAxg2_fhA18cr","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.35","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Scans public GitHub/GitLab repositories associated with a domain to detect exposed API keys, tokens, and credentials committed in source code.","exampleAgentPrompt":"Scan the public GitHub and GitLab repos associated with acme.com and tell me if any API keys, tokens, or hardcoded credentials have been committed to source code — I want to catch this before someone exploits it.","exampleUseCases":[{"title":"Pre-launch supply chain audit","prompt":"Before we go live, can you scan all public repos linked to startupxyz.com for any exposed API keys or secrets someone might have accidentally committed to GitHub or GitLab?"},{"title":"Third-party vendor security review","prompt":"We're onboarding a new vendor — can you check if vendorcorp.com has any leaked credentials or API tokens sitting in their public repositories? I want to know their supply chain risk before we integrate."},{"title":"Incident response credential triage","prompt":"We just got alerted to a possible breach at our company — can you scan the public GitHub repos tied to ourcompany.com and report back any exposed tokens or secrets that might have been the entry point?"}],"resultDescription":"Returns a list of detected secrets found in public repositories associated with the domain, including secret type (API key, token, credential), the repository URL where they were found, commit references or file paths, and severity or risk indicators. The response helps identify specific exposed credentials that require immediate rotation or remediation.","failureModes":["Domain has no associated public GitHub or GitLab repositories — returns empty results","Domain association lookup fails if the domain is not linked to any public repo namespace","Rate limiting or API throttling from GitHub/GitLab may limit scan depth","Only public repositories are scanned — private repos will not be included","False positives may occur with test/dummy credentials in code","Request times out for domains with a very large number of associated repositories"],"whenToPreferThis":"Choose this endpoint when you need to detect exposed secrets specifically in public source code repositories linked to a domain — particularly valuable for supply chain risk assessments, pre-integration vendor reviews, or pre-launch security audits. Prefer this over general breach or dark web checks when the specific concern is developer-committed credentials in GitHub or GitLab, not account-level data breaches or infostealer harvests.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-14T06:41:40.461Z","isFirstParty":false}