Skip to content

Create a custom secret pattern: a name, a regular expression for the secret, optional regular expressions for what comes right before and after it, and test strings.

POST/repos/{owner}/{name}/secret-scanning/custom-patterns

Patterns run in linear time (no look-around or back-references) and within size limits. With publish true, push protection and scans use it at once and the history is scanned again for it; otherwise it is a draft. A repository’s takes Admin; a workspace’s, an owner. On a private repository it needs the g1t plan.

tests gives, for each test string, where the pattern matched (start and end, in characters), or null. A pattern that does not compile, matches an empty string, or is too complex is refused with 422 and says why.

Name Type Required Description
owner string Yes The workspace that owns the repository.
name string Yes The repository’s name.

Send a JSON object. Names are snake_case, as in responses; the camelCase spelling is accepted too.

Name Type Required Description
test_strings array of strings No Up to 20 strings to show the pattern working on.
publish boolean No Use it in push protection and scans now (true), or keep a draft (false, the default).
pattern_name string Yes What people call it: “Acme API key”.
pattern string Yes The secret’s format, as a regular expression (the regex crate’s syntax: no look-around or back-references). At most 1,000 characters; it may not match an empty string.
before string No What must come right before the secret, as a regular expression. Default: the start of the line or a character that is not a letter or digit.
after string No What must come right after it. Default: the end of the line or a character that is not a letter or digit.
workspace string No Instead of repo: the workspace’s slug, for all of it (or its own, for patterns).
curl -X POST https://api.g1t.sh/repos/flagon-io/hello/secret-scanning/custom-patterns \
-H "Authorization: Bearer $G1T_TOKEN" \
-H "Content-Type: application/json" \
-d '{
"pattern_name": "Acme API key",
"pattern": "acme_[a-z0-9]{32}",
"test_strings": [
"ACME_KEY=acme_0123456789abcdef0123456789abcdef"
],
"publish": true
}'

A successful request answers 200 with:

{
"pattern": {
"id": "pat_01kq2p9f6g7h8j9k0m1n2p3q4r",
"scope": "repository",
"workspace": "flagon-io",
"repo": "hello",
"name": "Acme API key",
"pattern": "acme_[a-z0-9]{32}",
"before": null,
"after": null,
"test_strings": [
"ACME_KEY=acme_0123456789abcdef0123456789abcdef"
],
"state": "published",
"created_by": "syntaqx",
"created_at": "2026-10-06T09:14:02.118Z",
"updated_by": "syntaqx",
"updated_at": "2026-10-06T09:14:02.118Z",
"open_alerts": 0
},
"tests": [
[
9,
46
]
]
}

A failed request answers with one of these statuses and a body like {"error": {"code": "not_found", "message": "Repository not found."}}. See errors.

Status Code When
401 unauthenticated A token is required, or the one sent is not valid.
403 forbidden The token is valid but not allowed to do this, such as a member-only change or an agent token outside its repository.
404 not_found It does not exist, or you cannot see it.
409 conflict The request conflicts with the current state.
422 invalid The input is not valid. message says which field and why.