How to Find and Resolve Exposed API Keys with Secret Scanner

A practical workflow for reviewing and resolving possible secret exposure in Apidog assets.

Oliver Kingsley

Oliver Kingsley

31 August 2026

How to Find and Resolve Exposed API Keys with Secret Scanner

Apidog for Enterprise

On-Premises Deploy

SSO & RBAC

SOC 2 Compliant

Explore Apidog Enterprise

Secret Scanner detects possible API keys, access tokens, credentials, webhook URLs, and other sensitive values in supported Apidog assets. Findings show where a possible secret appears without displaying its full value.

This tutorial explains how to review a finding, respond to a real exposure, record the resolution, and add a custom detection pattern when your team uses an internal secret format.

Before you start

Secret Scanner is available on the Enterprise SaaS plan. It is not currently available in Apidog On-Premises.

Access depends on your role:

Role Available actions
Organization Owner or Admin View organization-level reports across teams
Team Owner or Admin Review team findings, resolve or reopen findings, manage custom patterns, and view analytics
Team Member or Guest View findings only for projects they can access

Use fictional values when testing. Never paste a real credential into a resource simply to confirm that scanning works.

Step 1: Review the organization report

Organization Owners and Admins can use the organization report to identify teams with unresolved findings.

  1. Open the organization-level Secret Scanner report.
  2. Review the counts for unresolved findings and published leaks.
  3. Check the last detected time and scan status.
  4. Open the affected team or contact its Team Owner or Team Admin.
Organization Secret Scanner report with team-level risk information

The organization report helps administrators identify which teams require follow-up.

The report is a triage view. Investigation and resolution take place in the affected team's Secret Scanner pages.

Step 2: Open and filter the team's findings

In the team, open Secret Scanner and select Secrets Detected.

Use the available filters to narrow the list by:

Each finding is grouped by its detection pattern and a secure fingerprint. One finding can have several occurrences when the same detected value appears in more than one location.

Secret Scanner findings with masked values, status, project, and occurrence information

Values are masked. Use the project, resource type, occurrence count, and source location to investigate the finding.

Start with unresolved findings marked as published exposure, then review findings that appear in several resources or projects.

Step 3: Inspect every occurrence

Open a finding and review its occurrences. For each occurrence, confirm:

  1. the project and resource containing the value
  2. the resource type and source location
  3. whether the value appears in published documentation
  4. the first and last detected times
  5. whether the value is a real credential or a false positive

Do not rely on the masked snippet alone when deciding whether a value is real. Check the source resource and, when necessary, ask the resource owner to identify the issuing system without copying the credential into a ticket or chat message.

Step 4: Respond to a real exposure

Secret Scanner reports possible exposure; it does not change the credential. Handle a confirmed secret in the system where it was issued.

Use this order:

  1. Revoke, rotate, or invalidate the credential in the external service.
  2. Review available usage logs for unexpected activity.
  3. Remove the value from every source occurrence shown in Apidog.
  4. Replace the raw value with an appropriate variable or Vault Secret reference when the workflow still needs the credential.
  5. Save each changed resource so an asynchronous scan can run again.

If the credential appears in published documentation, treat it as externally exposed even when no suspicious use is visible.

Removing a value from Apidog does not invalidate copies that may already exist elsewhere. Rotation or revocation is the primary containment action for a real leak.

Step 5: Record the resolution

After the response is complete, set the finding's resolution reason.

Resolution reason Use it when
Revoked The value was a real secret and has been revoked, rotated, or invalidated outside Apidog
False positive The detected value is not a secret
Won't fix The value is a real secret, but the team has accepted the risk and will not change it

Marking a finding as resolved only changes its status in Apidog. It does not revoke, rotate, invalidate, remove, or replace the underlying value.

If further action becomes necessary, reopen the finding.

Step 6: Verify the cleanup

Secret Scanner runs asynchronously rather than in real time. Scans are triggered when a supported resource is added or when Save is selected after a supported resource is changed.

After remediation:

  1. confirm that all known source occurrences were changed
  2. save the affected resources
  3. allow time for asynchronous scanning
  4. review the finding and its last detected time
  5. confirm separately that the old credential no longer works in the issuing service

The scanner's status is not a credential-validity test. Verify revocation in the external service.

Step 7: Add a custom detection pattern

Team Owners and Team Admins can create custom patterns for organization-specific secret formats.

  1. Open Secret Scanner > Patterns.
  2. Select the option to create a custom pattern.
  3. Enter a clear name.
  4. Add the regular expression and any useful keywords.
  5. Test with a fictional value.
  6. Enable the pattern and save it.

Current limits are:

Built-in patterns are read-only. Their internal regular expressions are not displayed and they cannot be edited, deleted, enabled, or disabled.

Step 8: Review team analytics

Team Owners and Team Admins can open Analytics to review where findings are concentrated.

Secret Scanner analytics showing findings and exposure trends

Use analytics to identify projects, patterns, and asset types that need additional review.

Analytics can help prioritize work, but each finding still requires source-level investigation.

Supported asset types

Secret Scanner currently scans supported assets including:

The source detail available for an occurrence depends on its resource type and the viewer's permissions.

Troubleshooting

Problem What to check
A recent change has no result yet Scanning is asynchronous. Confirm the resource was saved and review it again later.
A team member cannot see a finding Confirm that the member has access to the related project.
A user cannot manage patterns or analytics Pattern management and analytics require Team Owner or Team Admin access.
A resolved finding still contains a working secret Resolution status does not alter the credential. Revoke or rotate it in the issuing service.
An external repository is not scanned Secret Scanner does not scan external GitHub or GitLab repositories. Use the repository provider's scanning controls as well.

Important limitations

Secret Scanner does not prevent users from entering secrets, block documentation publishing, scan external repositories, or guarantee detection of every secret format. It also does not automatically remove source values or replace them with variables or Vault references.

Use it as one part of a credential-management process that also includes least-privilege issuance, secure storage, rotation, revocation, and usage monitoring.

Related API governance tutorials:

These tutorials cover complementary controls for governing an enterprise API workspace:

Related official documentation:

Explore more

GPT-6.1 Sol vs Claude Sonnet 5.5: same $2/$10 price, launched a day apart, and no shared benchmark

GPT-6.1 Sol vs Claude Sonnet 5.5: same $2/$10 price, launched a day apart, and no shared benchmark

GPT-6.1 Sol vs Claude Sonnet 5.5: same $2/$10 price, launched a day apart, no shared benchmark. Specs, vendor claims, and how to test both yourself.

30 September 2026

Is GPT-6.1 Sol Free?

Is GPT-6.1 Sol Free?

Is GPT-6.1 Sol free? No: it's for Plus and up in ChatGPT Work and Codex, and the API has no free tier. Here are the cheapest routes, with real cost math.

30 September 2026

How to Use Claude Sonnet 5.5 for Free: Every Route That Works (and the Ones That Don't)

How to Use Claude Sonnet 5.5 for Free: Every Route That Works (and the Ones That Don't)

Is Claude Sonnet 5.5 free? Yes on Claude.ai (web, iOS, Android). Every free route checked, plus what isn't: Claude Code, the API, and Copilot Free.

29 September 2026

Practice API Design-first in Apidog

Discover an easier way to build and use APIs

How to Find and Resolve Exposed API Keys with Secret Scanner