For the complete documentation index, see llms.txt. This page is also available as Markdown.

Secrets Configuration

Overview

Secrets detection is configured from the Nullify dashboard — there is no checked-in config file. Findings are split across two namespaces:

  • /secrets/credentials/* — detected secrets and credentials (API keys, tokens, and other secrets). /secrets/findings/* is a legacy alias for this same namespace and returns the same data.

  • /secrets/sensitivedata/* — sensitive data such as PII.

Each namespace exposes the same shape: GET .../findings, GET,PATCH .../findings/{findingId}, POST .../findings/{findingId}/allowlist, and a bulk POST .../findings/allowlist/batch.

Ignore secrets

Allowlist a secret when you have rotated it or verified it is safe to retain. Suppression is per-finding from the dashboard or via the API, e.g.:

POST /secrets/findings/{findingId}/allowlist

Request body:

{
  "allowlistReason": "Rotated and stored in the secure vault",
  "allowlistType": "UserFixed"
}

allowlistType is one of AI, UserFixed, UserAssumeRisk, UserFalsePositive, or UserOther. To allowlist several findings at once, use the batch endpoint for the relevant namespace (e.g. POST /secrets/findings/allowlist/batch) and add a findingIds array to the body.

Last updated