> For the complete documentation index, see [llms.txt](https://docs.nullify.ai/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.nullify.ai/configuration/configuration-secrets.md).

# Secrets Configuration

## Overview

Secrets detection is configured from the Nullify dashboard — there is no checked-in config file. Findings are split across two namespaces:

* `/secrets/credentials/*` — detected secrets and credentials (API keys, tokens, and other secrets). `/secrets/findings/*` is a legacy alias for this same namespace and returns the same data.
* `/secrets/sensitivedata/*` — sensitive data such as PII.

Each namespace exposes the same shape: `GET .../findings`, `GET,PATCH .../findings/{findingId}`, `POST .../findings/{findingId}/allowlist`, and a bulk `POST .../findings/allowlist/batch`.

## Ignore secrets

Allowlist a secret when you have rotated it or verified it is safe to retain. Suppression is per-finding from the dashboard or via the API, e.g.:

```
POST /secrets/findings/{findingId}/allowlist
```

Request body:

```json
{
  "allowlistReason": "Rotated and stored in the secure vault",
  "allowlistType": "UserFixed"
}
```

`allowlistType` is one of `AI`, `UserFixed`, `UserAssumeRisk`, `UserFalsePositive`, or `UserOther`. To allowlist several findings at once, use the batch endpoint for the relevant namespace (e.g. `POST /secrets/findings/allowlist/batch`) and add a `findingIds` array to the body.
