Public APIs
GitGuardian favicon

GitGuardian

Security

Scan files for secrets (API Keys, database credentials).

GitGuardian's website screenshot

About GitGuardian

GitGuardian's API provides secret detection and remediation across software development workflows, including scanning content for policy breaks and managing secret incidents once detected. It supports honeytoken creation and deployment for detecting unauthorized access, IP allowlisting, and health checks on connected sources and repositories.

The API covers incident management workflows including assigning, resolving, ignoring, reopening, sharing, and tracking remediation status of detected secrets, along with retrieving the scope of impact and any public leak locations. It includes team and member management with SCIM support for provisioning users and groups, permission checks, and access control on incidents and resources. Authentication is available via OAuth2/OIDC and API tokens, including JWT creation.

The API is intended for organizations integrating automated secret-scanning and incident-response capabilities into their development pipelines and identity systems. The base URL is https://api.gitguardian.com/v1 or https://api.eu1.gitguardian.com/v1 depending on region, with all data exchanged as JSON and timestamps in ISO-8601 format.

Key features

  • Detects secrets and policy breaks in code and text content via scanning API
  • Manages and tracks secret incidents including assignment, resolution, and remediation workflows
  • Deploys and manages honeytokens to detect unauthorized access
  • IP allowlist management for access control
  • Team and member management with SCIM support for user provisioning
  • OAuth2/OIDC support for authentication and API token management

Frequently asked questions

What does the GitGuardian API do?

It lets developers scan code and text content for secrets and policy breaks, and manage the resulting incidents programmatically.

What authentication methods are supported?

The API supports API tokens as well as OAuth2/OIDC, including JWT creation and dynamic client registration.

What data format does the API use?

All data is sent and received as JSON by default, with ISO-8601 compliant timestamps.

Are there regional API endpoints?

Yes, the base URL is https://api.gitguardian.com/v1 or https://api.eu1.gitguardian.com/v1 depending on location.

Does GitGuardian support enterprise user management?

Yes, it provides SCIM endpoints for managing users and groups, plus team, invitation, and permission management.

Advertise here

Featured products

  • SerpApi - Search API favicon
  • Screenshot Scout favicon
  • TalorData favicon
  • CoreClaw favicon

Show your product to thousands of developers

· 100k monthly pageviews
· 7k newsletter subscribers

Advertise your product