detect-secrets
Tool for detecting secrets in the codebase
Decision gist · record as of 2026-08-14
Yes. This is a mature, actively maintained tool with low install friction and no known vulnerabilities. It solves a real security problem (preventing credential leaks) with an enterprise-friendly approach that doesn't require fixing all historical secrets immediately. The permissive license and broad plugin ecosystem make it suitable for most projects.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- Low install friction with only two runtime dependencies (pyyaml, requests).
- Active maintenance with recent commits and 4620 repository stars indicate solid community adoption and ongoing support.
License · maintenance · safety
permissive license (permissive) — Permissive license allows use in commercial and private projects without significant restrictions.
last release 2024-05-06 (830 days) · last repo commit 2026-04-02 · 4,620 stars
0 known vulnerabilities (OSV.dev, 2026-08-14) · 7,376,210 downloads/mo, #1,748 on PyPI
Alternatives
Verify before relying
pip install detect-secrets
# Create baseline of current secrets
detect-secrets scan > .secrets.baseline
# Or use in Python:
from detect_secrets import SecretsCollection
from detect_secrets.settings import default_settings
secrets = SecretsCollection()
with default_settings():
secrets.scan_file('config.ini')- Whether all secret types (API keys, tokens, credentials) are detected with acceptable false-positive rates across different formats
- Performance characteristics when scanning large repositories or many files in a single pass
What it is and what it does
detect-secrets is a command-line tool and Python library for finding hardcoded secrets in code repositories. It uses heuristic regex patterns and entropy analysis to identify API keys, tokens, credentials, and other sensitive data that should not be committed. Unlike simple grep-based tools, it's designed for enterprise use by establishing a baseline of existing secrets and then preventing new ones from entering the codebase—avoiding the need to remediate all historical secrets at once.
The package works by scanning git diffs rather than entire history, reducing overhead. It provides three main workflows: creating and updating a baseline of known secrets, running as a pre-commit hook to alert on new secrets, and auditing baselines to label false positives. It includes detectors for common secret types (AWS keys, GitHub tokens, Slack tokens, private keys, etc.) and supports custom plugins and filters for specialized detection rules.
Use it for
- Set up pre-commit hooks to prevent developers from accidentally committing API keys or database credentials to git
- Create a baseline of existing secrets in a large legacy codebase, then enforce that no new secrets are added
- Audit and label false positives in a baseline to improve detection accuracy for your specific codebase patterns
- Integrate into CI/CD pipelines to scan staged files and fail builds if new secrets are detected
- Use custom detector plugins to find organization-specific secret patterns (internal tokens, proprietary key formats)
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
Yes.
This is a mature, actively maintained tool with low install friction and no known vulnerabilities. It solves a real security problem (preventing credential leaks) with an enterprise-friendly approach that doesn't require fixing all historical secrets immediately. The permissive license and broad plugin ecosystem make it suitable for most projects.
Install
detect-secrets on PyPI
Before you install
Low install friction with only two runtime dependencies (pyyaml, requests). Active maintenance with recent commits and 4620 repository stars indicate solid community adoption and ongoing support.
License in practice
Permissive license allows use in commercial and private projects without significant restrictions.
Quickstart
pip install detect-secrets
# Create baseline of current secrets
detect-secrets scan > .secrets.baseline
# Or use in Python:
from detect_secrets import SecretsCollection
from detect_secrets.settings import default_settings
secrets = SecretsCollection()
with default_settings():
secrets.scan_file('config.ini')
Verify before relying
- Whether all secret types (API keys, tokens, credentials) are detected with acceptable false-positive rates across different formats
- Performance characteristics when scanning large repositories or many files in a single pass
Package facts
| License | permissive license permissive |
| Python support | Not specified |
| Install friction | Low. Pure-Python wheel |
| Runtime dependencies | 2 packagespyyamlrequests |
| Maintenance | Actively maintained 830 days since the last release |
| Last repo commit | |
| First released | |
| Downloads | 7,376,210 / month, #1,748 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
| Classifiers | Development Status :: 5 - Production/StableEnvironment :: ConsoleIntended Audience :: DevelopersLicense :: OSI Approved :: Apache Software LicenseOperating System :: OS IndependentProgramming Language :: Python :: 3Topic :: Software DevelopmentTopic :: UtilitiesTyping :: Typed |
Evidence: detect_secrets-1.5.0-py3-none-any.whl
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “detect secrets in code”
- detect-secretsDetects secrets (API keys, tokens, credentials) in code repositories…
- dodgyDodgy scans Python source code for suspicious patterns—accidental…
- ggshieldggshield is a CLI tool that scans files, repositories, Docker images,…
Give your agent the search over MCP, or paste the wish link into any chat.
More Software Development packages
Provides backported and experimental type hints for Python 3.9+, allowing use of newer typing features on older Python versions and enabling early experimentation with type system PEPs before they enter the standard library.
NumPy provides an N-dimensional array object and a comprehensive suite of mathematical, linear algebra, Fourier transform, and random number functions for scientific computing in Python.
FastAPI is a Python web framework for building REST APIs using type hints, with automatic request validation, serialization, and interactive API documentation.
Provides a way to document function parameters, class attributes, return types, and variables inline using Python's `Annotated` type hint syntax instead of traditional docstrings.
Typer builds command-line applications from Python functions using type hints, automatically generating help text, argument parsing, and shell completion.
Install it if you are building CLIs in Python.
Distlib provides low-level packaging utilities for building, distributing, and managing Python software—including metadata handling, version specifiers, wheel support, script installation, and dependency resolution.
See also bc-detect-secrets · dodgy · trufflehog3 · truffleHog · cycode · kingfisher-bin · pygitguardian · ggshield · microsoft-security-utilities-secret-masker · git-filter-repo