{"repo":"odomojuli/regextokens","free":true,"listed":false,"github":"https://github.com/odomojuli/regextokens","clone":"git clone https://github.com/odomojuli/regextokens.git","description":"list of regex patterns for oauth / api tokens with provided source","language":"Python","stars":289,"topics":["oauth","regex"],"license":"MIT","category":"auth-billing-email","readme_excerpt":"regextokens A sourced, tested, offline-proving scanner for OAuth / API tokens and secrets. Every pattern is sourced (primary provider docs), tested (positive + negative samples), and proven (RE2-compatible, ReDoS-checked). Ships a CLI with confidence tiers. Source of truth is DATA in build patterns.py ; patterns.json and this file are generated from it. 109 patterns / 64 providers / generated 2026-07-02 Install Scan Exit status: 0 no findings, 1 findings at/above the requested tier, 2 error. Point it at a diff or tree in CI to gate merges. Secrets are redacted in output by default. Baseline / allowlist Accept reviewed findings (test fixtures, docs examples) so CI only fails on new secrets: The baseline stores fingerprints ( sha256 of pattern id + hashed secret body), never the secrets themselves, so it is safe to commit. Matching is line-independent — editing above an accepted finding does not un-suppress it — but the same token in a different file is a new exposure and is reported. A hand-edited allow section holds policy: fnmatch path globs and pattern ids. --write-baseline preserves and applies it. This repo commits its own baseline covering the synthetic samples in build patterns.py ; CI self-scans against it. Pre-commit hook and GitHub Action Both default to -m probable : the low tier includes public identifiers and placeholders that would make a commit gate unusable. Confidence tiers Every finding is scored by offline proof — local computation only, no network, no calls","default_branch":null,"files":null,"tree":[],"storefront":"/r/odomojuli","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/odomojuli/regextokens/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}