Skip to content

List secret scanning alerts: secrets found in pushes (blocked) and in history (open), newest first, in a repository or (with workspace) across a workspace.

GET/repos/{owner}/{name}/secret-scanning/alerts

Filter by state (open, dismissed, fixed), secret_type, validity (active, inactive, unknown, unsupported) and bypassed. The secret itself is never returned: a preview and a fingerprint-based id only.

Filter Values
state open (in the history, or blocked at a push), dismissed, fixed
secret_type aws_access_key, github_token, custom_pattern, …
validity active, inactive, unknown, unsupported
bypassed true or false

The secret itself is never returned: preview is enough to recognise it. status says where it stands: open, blocked (stopped at a push, never landed), allowed or resolved.

Name Type Required Description
owner string Yes The workspace that owns the repository.
name string Yes The repository’s name.
Name Type Required Description
state string No Only alerts in this state. One of open, dismissed, fixed.
secret_type string No Only this kind of secret: aws_access_key, github_token, custom_pattern, …
validity string No Only alerts whose issuer said this when last asked. One of active, inactive, unknown, unsupported.
bypassed boolean No Only alerts someone bypassed push protection for (true), or not (false).
curl "https://api.g1t.sh/repos/flagon-io/hello/secret-scanning/alerts?state=open" \
-H "Authorization: Bearer $G1T_TOKEN"

A successful request answers 200 with:

[
{
"id": "sec_01kq2m7d4e5f6g7h8j9k0m1n2p",
"repo_id": "rep_01kp0a1b2c3d4e5f6g7h8j9k0m",
"kind": "github_token",
"label": "a GitHub token",
"path": "scripts/release.sh",
"line": 12,
"commit": "4807077b296e6edbf410d55e72749d3e1170c291",
"preview": "ghp_X7…",
"status": "open",
"source": "push",
"found_by": "syntaqx",
"found_at": "2026-10-06T09:14:02.118Z",
"decided_by": null,
"reason": null,
"decided_at": null,
"dismissed_reason": null,
"test_value": null,
"state": "open",
"validity": "active",
"validity_checked_at": "2026-10-06T09:20:41.502Z",
"bypass": {
"reason": "will_fix_later",
"comment": "Rotating it this afternoon.",
"by": "syntaqx",
"at": "2026-10-06T09:14:02.118Z",
"approved_by": null
},
"pattern_id": null,
"pattern_name": null,
"locations": 1
}
]

A failed request answers with one of these statuses and a body like {"error": {"code": "not_found", "message": "Repository not found."}}. See errors.

Status Code When
401 unauthenticated A token is required, or the one sent is not valid.
403 forbidden The token is valid but not allowed to do this, such as a member-only change or an agent token outside its repository.
404 not_found It does not exist, or you cannot see it.
422 invalid The input is not valid. message says which field and why.