Gitleaks
Scan git repos for secrets, passwords, and API keys that were accidentally committed.
External Tool
This open-source tool is maintained externally. View the source on GitHub to learn more or run it yourself.
Browse security tools →What's next with Gitleaks?
Choose how you want to get started.
Use it free
Open the official tool or demo — no account needed.
Self-host it
Run the open-source version on your own infrastructure.
What is Gitleaks?
Gitleaks is an open-source secret scanner designed to detect sensitive information such as API keys, passwords, and tokens in Git repositories, files, and directories. Its primary purpose is to identify accidentally committed secrets that could compromise security. Security professionals, enterprises, and developers use Gitleaks to mitigate risks associated with data breaches caused by exposed credentials. The tool addresses the critical problem of human error in version control systems, where sensitive data is often unintentionally pushed to public or private repositories. By scanning codebases and commit histories, Gitleaks helps organizations maintain compliance with security standards and protect intellectual property. Its widespread adoption, evidenced by over 17,000 GitHub stars and 9 million downloads, underscores its reliability in securing software development workflows.
How it works
Gitleaks is a security tool that scans Git repositories for secrets, including cryptographic keys, authentication tokens, and API credentials. It operates by searching through commit histories, branches, and files to identify patterns matching predefined secret regex patterns. The tool is particularly valuable for teams using Git as their version control system, as it can uncover secrets that have been inadvertently committed to repositories, whether public or private. Gitleaks can scan entire repositories, individual files, or specific directories, making it versatile for both small projects and large codebases. It supports integration with GitHub Actions via Gitleaks-Action, enabling automated secret scans during pull requests and commits. The tool also allows customization of secret patterns through configuration files, enabling users to tailor detection rules to their specific needs.
How to use it
- 1Install Gitleaks via package managers like Homebrew or by downloading binaries. 2. Configure secret patterns in a `.gitleaks.toml` file or use default rules. 3. Run the scanner on a repository using the `gitleaks detect` command. 4. Review the output to identify and remediate exposed secrets. Practical tips include running scans on CI/CD pipelines, using the `--no-fail` flag to avoid build failures, and leveraging the `--debug` option for detailed diagnostics.
What it can do
- secret scanning
Use cases
Assumptions and limitations
Assumptions
- source: https://github.com/gitleaks/gitleaks
- license: MIT — free to use
- privacy: Self-hosted — you control your data
Limitations
- For authorized use only — use on systems you own or have explicit permission to test.
- Does not support non-Git version control systems like SVN
- Relies on regex patterns, which may miss novel or obfuscated secret formats
- Limited to scanning files and histories within Git repositories, not external dependencies
- Requires manual configuration for custom secret types, which can be time-consuming
Understanding the result
Scan git repos for secrets, passwords, and API keys that were accidentally committed.
Tool details
- Clearly flagged when a network request is needed.
- No account, no sign-up, and no tracking of your content.
- Powered by (MIT).
- Built with
- (gitleaks/gitleaks)
- License
- MIT
- Runs locally
- No — requires a network request
- Verification
- Not yet verified
- Input
- Query
- Output
- Text
Built with gitleaks/gitleaks. OpenToolVault provides the discovery and browser interface while crediting the original project maintainers.
- Built with
- License
- MIT
Open-source project
OpenToolVault is an independent directory. We are not affiliated with or endorsed by this project.
References
- / — GitHub Repository
Upstream project · GitHub
- MIT License
Upstream project
Frequently asked
How does Gitleaks handle false positives?
Gitleaks uses regex patterns to identify potential secrets, which may occasionally flag non-sensitive data. Users can refine detection rules in the `.gitleaks.toml` configuration file to reduce false positives. Additionally, the tool provides context about matches, allowing users to assess their validity before taking action.
How does Gitleaks integrate with GitHub Actions?
Gitleaks-Action is a GitHub Action that automatically runs a Gitleaks scan on pull requests and commits. To use it, add the action to your workflow YAML file, specifying the repository to scan. The action outputs results to the GitHub Actions UI, enabling teams to enforce secret scanning as part of their development lifecycle.
How do I scan a specific directory for secrets?
To scan a directory, run `gitleaks detect --path=/path/to/directory` from the command line. This command searches the specified directory and its subdirectories for matches against configured secret patterns. You can also combine this with the `--repo` flag to scan a Git repository's entire history.
How does Gitleaks compare to alternatives like truffleHog or git-secrets?
Gitleaks focuses on scanning Git histories for secrets, while truffleHog emphasizes brute-force password detection and git-secrets prevents commits with secrets. Gitleaks is more suited for post-commit auditing, whereas git-secrets enforces real-time checks. TruffleHog is specialized for password recovery, making it less effective for general secret detection.
What should I do if Gitleaks reports a false positive?
If a false positive occurs, edit the `.gitleaks.toml` configuration file to exclude the specific pattern. For example, add a `[[exclude]]` rule with the exact string or regex that caused the false positive. Alternatively, use the `--no-fail` flag to suppress warnings during scans, then manually verify the result.