Dry-run a custom pattern
Run a pattern over the default branch without saving it: of the repository, or (with workspace) of up to ten of its repositories, or those named in repos.
POST
/repos/{owner}/{name}/secret-scanning/custom-patterns/dry-runReturns the files read and up to fifty matches each, masked.
Reads up to 2,000 files and 20 MB of the default branch, skipping what secret scanning skips. Nothing is recorded.
- Authentication: Required. Send an access token as
Authorization: Bearer. - MCP tool:
securitywithactiondry_run_pattern, and the same inputs - Scope: An access token needs
security:write. - Also at:
POST /workspaces/{workspace}/secret-scanning/custom-patterns/dry-run
Path parameters
Section titled “Path parameters”| Name | Type | Required | Description |
|---|---|---|---|
owner |
string | Yes | The workspace that owns the repository. |
name |
string | Yes | The repository’s name. |
Body parameters
Section titled “Body parameters”Send a JSON object. Names are snake_case, as in responses; the camelCase spelling is accepted too.
| Name | Type | Required | Description |
|---|---|---|---|
repos |
array of strings | No | With workspace: repository names to run it on; the first ten when empty. |
pattern_name |
string | No | What people call it: “Acme API key”. |
pattern |
string | Yes | The secret’s format, as a regular expression (the regex crate’s syntax: no look-around or back-references). At most 1,000 characters; it may not match an empty string. |
before |
string | No | What must come right before the secret, as a regular expression. Default: the start of the line or a character that is not a letter or digit. |
after |
string | No | What must come right after it. Default: the end of the line or a character that is not a letter or digit. |
workspace |
string | No | Instead of repo: the workspace’s slug, for all of it (or its own, for patterns). |
Example request
Section titled “Example request”curl -X POST https://api.g1t.sh/repos/flagon-io/hello/secret-scanning/custom-patterns/dry-run \ -H "Authorization: Bearer $G1T_TOKEN" \ -H "Content-Type: application/json" \ -d '{ "pattern": "acme_[a-z0-9]{32}" }'Example response
Section titled “Example response”A successful request answers 200 with:
{ "repos": [ { "name": "hello", "files_scanned": 214, "matches": [ { "path": "config/dev.env", "line": 3, "preview": "ACME_KEY=acme_01••••••••••••••••••••••••" } ], "truncated": false, "commit": "4807077b296e6edbf410d55e72749d3e1170c291" } ]}Errors
Section titled “Errors”A failed request answers with one of these statuses and a body like {"error": {"code": "not_found", "message": "Repository not found."}}. See errors.
| Status | Code | When |
|---|---|---|
| 401 | unauthenticated |
A token is required, or the one sent is not valid. |
| 403 | forbidden |
The token is valid but not allowed to do this, such as a member-only change or an agent token outside its repository. |
| 404 | not_found |
It does not exist, or you cannot see it. |
| 409 | conflict |
The request conflicts with the current state. |
| 422 | invalid |
The input is not valid. message says which field and why. |