Skip to content

Ask a landed secret's issuer whether it still works, and mark the alert active or inactive.

POST/repos/{owner}/{name}/secret-scanning/alerts/{id}/validity

The check is the issuer’s own read-only identity call over HTTPS; the secret goes nowhere else. Needs validity checks on for the workspace (and the g1t plan on a private repository). Formats with no safe check answer unsupported.

Made for GitHub, GitLab, Stripe, Slack, npm, OpenAI, Anthropic and SendGrid tokens, with the issuer’s own read-only call. Other formats answer unsupported; a secret that never landed answers unknown.

  • Authentication: Required. Send an access token as Authorization: Bearer.
  • MCP tool: security with action check_validity, and the same inputs
  • Scope: An access token needs security:write.
Name Type Required Description
owner string Yes The workspace that owns the repository.
name string Yes The repository’s name.
id string Yes The alert’s id: sec_…
curl -X POST https://api.g1t.sh/repos/flagon-io/hello/secret-scanning/alerts/sec_01kq2m7d4e5f6g7h8j9k0m1n2p/validity \
-H "Authorization: Bearer $G1T_TOKEN"

A successful request answers 200 with:

{
"id": "sec_01kq2m7d4e5f6g7h8j9k0m1n2p",
"repo_id": "rep_01kp0a1b2c3d4e5f6g7h8j9k0m",
"kind": "github_token",
"label": "a GitHub token",
"path": "scripts/release.sh",
"line": 12,
"commit": "4807077b296e6edbf410d55e72749d3e1170c291",
"preview": "ghp_X7…",
"status": "open",
"source": "push",
"found_by": "syntaqx",
"found_at": "2026-10-06T09:14:02.118Z",
"decided_by": null,
"reason": null,
"decided_at": null,
"dismissed_reason": null,
"test_value": null,
"state": "open",
"validity": "active",
"validity_checked_at": "2026-10-06T09:20:41.502Z",
"bypass": {
"reason": "will_fix_later",
"comment": "Rotating it this afternoon.",
"by": "syntaqx",
"at": "2026-10-06T09:14:02.118Z",
"approved_by": null
},
"pattern_id": null,
"pattern_name": null,
"locations": 1
}

A failed request answers with one of these statuses and a body like {"error": {"code": "not_found", "message": "Repository not found."}}. See errors.

Status Code When
401 unauthenticated A token is required, or the one sent is not valid.
403 forbidden The token is valid but not allowed to do this, such as a member-only change or an agent token outside its repository.
404 not_found It does not exist, or you cannot see it.
409 conflict The request conflicts with the current state.
422 invalid The input is not valid. message says which field and why.