GitHub Secret Scanning API

The GitHub Secret Scanning API lets you retrieve and manage secret scanning alerts for repositories, organizations, and enterprises. Secret scanning detects tokens, keys, and other credentials accidentally committed to repositories. The API provides endpoints to list, get, and update alert statuses, as well as manage push protection bypass requests and list alert locations.

Operations 6

Each operation below carries the questions people ask an LLM about it and the instructions they give an agent to run it. Generated by API Evangelist overlay

GET /enterprises/{enterprise}/secret-scanning/alerts List leaked-secret alerts across an enterprise · GitHub List Secret Scanning Alerts for an Enterprise #
Ask an LLM
“Where have secrets been leaked across all the organizations in our enterprise?”
“Can I filter enterprise-wide secret scanning alerts by secret type?”
Tell an agent
List secret scanning alerts across enterprise {enterprise}.
Show {state} secret scanning alerts of type {secret_type} in enterprise {enterprise}.
GET /orgs/{org}/secret-scanning/alerts List leaked-secret alerts across an organization · GitHub List Secret Scanning Alerts for an Organization #
Ask an LLM
“Which repositories in our organization have exposed credentials that are still open?”
“Can I see org secret alerts that were resolved as false positives?”
Tell an agent
List secret scanning alerts for all repositories in {org}.
Show secret alerts in organization {org} resolved as {resolution}.
GET /repos/{owner}/{repo}/secret-scanning/alerts List leaked-secret alerts in a repository · GitHub List Secret Scanning Alerts for a Repository #
Ask an LLM
“Has anyone committed an API key or token to this repository?”
“What's the way to list only open secret scanning alerts in one repo, newest first?”
Tell an agent
List secret scanning alerts for {owner}/{repo}.
Show {state} secret alerts of type {secret_type} in {owner}/{repo}.
GET /repos/{owner}/{repo}/secret-scanning/alerts/{alert_number} Get one secret scanning alert · GitHub Get a Secret Scanning Alert #
Ask an LLM
“What kind of secret triggered a specific alert, and has it been resolved?”
“Can I pull up a single leaked-secret alert by its number?”
Tell an agent
Show secret scanning alert {alert_number} in {owner}/{repo}.
Get the secret type and resolution of alert #{alert_number} in {owner}/{repo}.
PATCH /repos/{owner}/{repo}/secret-scanning/alerts/{alert_number} Resolve or reopen a secret scanning alert · GitHub Update a Secret Scanning Alert #
Ask an LLM
“How do I close a secret scanning alert after I've rotated the leaked credential?”
“Can I mark a leaked-secret alert as used only in tests, with a comment?”
Tell an agent
Resolve secret alert {alert_number} in {owner}/{repo} as {resolution}.
Set secret scanning alert {alert_number} in {owner}/{repo} to {state} with comment {resolution_comment}.
GET /repos/{owner}/{repo}/secret-scanning/alerts/{alert_number}/locations List where a leaked secret was found · GitHub List Locations for a Secret Scanning Alert #
Ask an LLM
“In which files and commits was a leaked secret found?”
“Where exactly does the secret behind an alert appear in the repository history?”
Tell an agent
List the locations of secret alert {alert_number} in {owner}/{repo}.
Show the files and commits containing the secret for alert {alert_number} in {owner}/{repo}.

Documentation

📖
Documentation
https://docs.github.com/en/rest/apps
📖
Documentation
https://docs.github.com/en/rest/codes-of-conduct/codes-of-conduct
📖
Documentation
https://docs.github.com/en/rest/emojis
📖
Documentation
https://docs.github.com/en/rest/gitignore
📖
Documentation
https://docs.github.com/en/rest/apps/installations
📖
Documentation
https://docs.github.com/en/rest/enterprise-admin
📖
Documentation
https://docs.github.com/en/rest/activity/events
📖
Documentation
https://docs.github.com/en/rest/orgs
📖
Documentation
https://docs.github.com/en/rest/rate-limit
📖
Documentation
https://docs.github.com/en/enterprise-cloud@latest/rest/scim
📖
Documentation
https://docs.github.com/en/rest/using-the-rest-api/getting-started-with-the-rest-api
📖
Documentation
https://docs.github.com/en/rest/teams
📖
Documentation
https://docs.github.com/en/rest/meta/meta
📖
Documentation
https://docs.github.com/en/rest/actions
📖
Documentation
https://docs.github.com/en/rest/branches
📖
Documentation
https://docs.github.com/en/rest/code-scanning
📖
Documentation
https://docs.github.com/en/rest/collaborators
📖
Documentation
https://docs.github.com/en/rest/dependabot
📖
Documentation
https://docs.github.com/en/rest/webhooks
📖
Documentation
https://docs.github.com/en/rest/pulls
📖
Documentation
https://docs.github.com/en/rest/git/tags
📖
Documentation
https://docs.github.com/en/rest/repos/autolinks
📖
Documentation
https://docs.github.com/en/rest/collaborators/invitations
📖
Documentation
https://docs.github.com/en/rest/secret-scanning

Specifications

Other Resources

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/github-secret-scanning-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

github-secret-scanning-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  version: 1.1.4
  title: GitHub v3 REST Secret Scanning API
  description: GitHub's v3 REST API.
  license:
    name: MIT
    url: https://spdx.org/licenses/MIT
  termsOfService: https://docs.github.com/articles/github-terms-of-service
  contact:
    name: Support
    url: https://support.github.com/contact?tags=dotcom-rest-api
  x-github-plan: ghes
  x-github-release: 3.9
servers:
- url: '{protocol}://{hostname}/api/v3'
  variables:
    hostname:
      description: Self-hosted Enterprise Server hostname
      default: HOSTNAME
    protocol:
      description: Self-hosted Enterprise Server protocol
      default: http
tags:


# --- truncated at 32 KB (73 KB total) ---
# Full source: https://raw.githubusercontent.com/api-evangelist/github/refs/heads/main/openapi/github-secret-scanning-api-openapi.yml