kingfisher-bin
Kingfisher secret scanning CLI (packaged binary)
Decision gist · record as of 2026-08-14
Yes. Kingfisher is actively maintained, has no runtime dependencies, supports modern Python versions, carries a permissive Apache-2.0 license, and offers comprehensive secret detection with live validation across 1,089 rules and many platforms. It is well-suited for developers, security teams, and compliance workflows. Install via Homebrew, PyPI, or Docker depending on your environment.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- Requires Python 3.8 or later.
- Platform-specific binary wheels are provided for macOS (Intel and ARM), Linux (x86_64 and aarch64), and Windows (AMD64 and ARM64).
- Medium install friction due to platform-specific binary wheels (macOS, Linux, Windows, ARM support).
License · maintenance · safety
Apache-2.0 (permissive) — Apache-2.0 permissive license allows commercial and private use with minimal restrictions, making it suitable for enterprise and compliance-focused workflows.
last release 2026-08-08 (6 days) · last repo commit 2026-08-12 · 1,198 stars
0 known vulnerabilities (OSV.dev, 2026-08-14) · 74,556 downloads/mo, #14,816 on PyPI
Alternatives
Verify before relying
# Install via PyPI
uv tool install kingfisher-bin
# Scan a directory for secrets
kingfisher scan /path/to/code
# Scan and view results in browser
kingfisher scan /path/to/code --view-report- Whether the 1,089 built-in rules cover all major secret types your organization uses
- Performance characteristics on very large codebases or repositories with extensive history
- Accuracy of live validation against provider APIs and false-positive rates in practice
- Whether custom YAML rules are sufficient for proprietary or non-standard secret formats
What it is and what it does
Kingfisher is a Rust-based command-line tool that scans for exposed secrets—API keys, tokens, and credentials—across multiple sources including local files, Git repositories, GitHub, GitLab, Azure Repos, Bitbucket, Gitea, Hugging Face, Docker, Jira, Confluence, Slack, Microsoft Teams, Postman, AWS S3, and Google Cloud Storage. It uses an Intel SIMD-accelerated regex engine (Hyperscan) combined with language-aware parsing to achieve high accuracy at scale.
Beyond detection, Kingfisher validates discovered secrets by checking them against provider APIs to reduce false positives, and supports direct revocation for many platforms. It generates output in JSON, SARIF, TOON, and HTML formats, sends alerts to Slack, Microsoft Teams, Discord, Mattermost, Google Chat, or custom webhooks, and includes a browser-based report viewer that can visualize and triage findings from Kingfisher, SARIF, Gitleaks, and TruffleHog reports. The tool is designed for both offensive security engineers and blue-team defenders scanning repositories, cloud storage, chat systems, and CI pipelines.
Use it for
- Scan Git repositories and commit history for accidentally committed API keys and tokens before they reach production
- Validate discovered credentials against provider APIs to confirm they are live and reduce false-positive alerts
- Generate compliance-ready audit reports with scan metadata and validation results for security and regulatory reviews
- Integrate secret scanning into CI/CD pipelines with JSON, SARIF, or webhook alerts to Slack or Microsoft Teams
- Triage and deduplicate findings from multiple scanning tools (Gitleaks, TruffleHog) in a unified browser-based viewer
- Map blast radius of leaked credentials to identify which cloud resources and identities are exposed across 43 providers
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
Yes.
Kingfisher is actively maintained, has no runtime dependencies, supports modern Python versions, carries a permissive Apache-2.0 license, and offers comprehensive secret detection with live validation across 1,089 rules and many platforms. It is well-suited for developers, security teams, and compliance workflows. Install via Homebrew, PyPI, or Docker depending on your environment.
Install
kingfisher-bin on PyPI
Before you install
Medium install friction due to platform-specific binary wheels (macOS, Linux, Windows, ARM support). The package is actively maintained with a recent release, no runtime dependencies, and clear installation paths via Homebrew, PyPI, or Docker.
Requires Python 3.8 or later. Platform-specific binary wheels are provided for macOS (Intel and ARM), Linux (x86_64 and aarch64), and Windows (AMD64 and ARM64).
License in practice
Apache-2.0 permissive license allows commercial and private use with minimal restrictions, making it suitable for enterprise and compliance-focused workflows.
Quickstart
# Install via PyPI
uv tool install kingfisher-bin
# Scan a directory for secrets
kingfisher scan /path/to/code
# Scan and view results in browser
kingfisher scan /path/to/code --view-report
Verify before relying
- Whether the 1,089 built-in rules cover all major secret types your organization uses
- Performance characteristics on very large codebases or repositories with extensive history
- Accuracy of live validation against provider APIs and false-positive rates in practice
- Whether custom YAML rules are sufficient for proprietary or non-standard secret formats
Package facts
| License | Apache-2.0 permissive |
| Python support | Supports the current Python release >=3.8 |
| Install friction | Medium. Platform-specific wheel |
| Runtime dependencies | None |
| Maintenance | Actively maintained 6 days since the last release |
| Last repo commit | |
| First released | |
| Downloads | 74,556 / month, #14,816 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
| Classifiers | License :: OSI Approved :: Apache Software LicenseProgramming Language :: Python :: 3Programming Language :: Python :: 3 :: Only |
Evidence: kingfisher_bin-1.112.0-py3-none-macosx_10_9_x86_64.whl; kingfisher_bin-1.112.0-py3-none-macosx_11_0_arm64.whl; kingfisher_bin-1.112.0-py3-none-manylinux_2_17_aarch64.musllinux_1_2_aarch64.whl; kingfisher_bin-1.112.0-py3-none-manylinux_2_17_x86_64.musllinux_1_2_x86_64.whl; kingfisher_bin-1.112.0-py3-none-win_amd64.whl; kingfisher_bin-1.112.0-py3-none-win_arm64.whl
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “secret validation tool”
- kingfisher-binKingfisher is a command-line secret scanner that detects, validates,…
- truffleHogScans Git repositories and other sources for leaked credentials,…
- cycodeCycode is a command-line security scanner that detects secrets,…
Give your agent the search over MCP, or paste the wish link into any chat.
More Security packages
Provides Python bindings to the FreeDesktop.org Secret Service API for securely storing and retrieving passwords and secrets through GNOME Keyring, KWallet, or KeePassXC.
MSAL for Python handles OAuth2 and OpenID Connect authentication with Microsoft identity services, managing token acquisition, caching, and refresh for applications integrating with Microsoft Entra ID, Microsoft Accounts, and Azure AD B2C.
joserfc implements JOSE standards (JWS, JWE, JWK, JWT, and related RFCs) for signing, encrypting, and managing JSON-based cryptographic tokens in Python.
Authlib provides a complete implementation of OAuth 1.0, OAuth 2.0, and OpenID Connect 1.0 for building both authentication clients and servers, with built-in support for JWS, JWK, JWA, and JWT standards.
Provides low-level CFFI bindings to the official Argon2 password hashing algorithm for use by libraries and applications that need direct access to Argon2 without higher-level abstractions.
ADAL for Python authenticates applications with Azure Active Directory to obtain tokens for accessing Azure AD-protected resources.
Install only if maintaining existing code that already depends on it, and plan a migration.
See also truffleHog · skylos · microsoft-security-utilities-secret-masker · bc-detect-secrets · trufflehog3 · ggshield · detect-secrets · cycode · bbot · scanoss