Secrets Configuration
Last updated
Secrets detection is configured from the Nullify dashboard — there is no checked-in config file. Findings are split across two namespaces:
/secrets/credentials/* — detected secrets and credentials (API keys, tokens, and other secrets). /secrets/findings/* is a legacy alias for this same namespace and returns the same data.
/secrets/sensitivedata/* — sensitive data such as PII.
Each namespace exposes the same shape: GET .../findings, GET,PATCH .../findings/{findingId}, POST .../findings/{findingId}/allowlist, and a bulk POST .../findings/allowlist/batch.
Allowlist a secret when you have rotated it or verified it is safe to retain. Suppression is per-finding from the dashboard or via the API, e.g.:
POST /secrets/findings/{findingId}/allowlistRequest body:
{
"allowlistReason": "Rotated and stored in the secure vault",
"allowlistType": "UserFixed"
}allowlistType is one of AI, UserFixed, UserAssumeRisk, UserFalsePositive, or UserOther. To allowlist several findings at once, use the batch endpoint for the relevant namespace (e.g. POST /secrets/findings/allowlist/batch) and add a findingIds array to the body.
Last updated