Secrets — Communication & Messaging

Slack, Twilio, Discord, Telegram, SendGrid, Mailgun and other messaging credentials.

All rules in this category are kind secrets. They run under vulnetix secrets and the secrets stage of vulnetix scan.

Rule IDNameSeverityDetection
VNX-SEC-097Postmark server API tokenHighkeyword + regex
VNX-SEC-401Mailchimp API key (-us datacenter)Criticalkeyword + regex
VNX-SEC-402Mandrill API keyHighkeyword + regex + entropy
VNX-SEC-403SparkPost API keyHighkeyword + regex + entropy
VNX-SEC-404Mailjet API key (public)Mediumkeyword + regex + entropy
VNX-SEC-405Mailjet secret keyHighkeyword + regex + entropy
VNX-SEC-406Vonage/Nexmo API secretHighkeyword + regex + entropy
VNX-SEC-407Vonage/Nexmo API keyMediumkeyword + regex + entropy
VNX-SEC-408MessageBird/Bird access keyHighkeyword + regex + entropy
VNX-SEC-409Plivo Auth ID (MA)Mediumkeyword + regex + entropy
VNX-SEC-410Plivo Auth ID (SA subaccount)Mediumkeyword + regex + entropy
VNX-SEC-411Plivo Auth TokenHighkeyword + regex + entropy
VNX-SEC-412Telnyx API key (KEY)Criticalkeyword + regex + entropy
VNX-SEC-413Bandwidth API token/secretHighkeyword + regex + entropy
VNX-SEC-414Sinch service plan API tokenHighkeyword + regex + entropy
VNX-SEC-415Infobip API keyHighkeyword + regex + entropy
VNX-SEC-416ClickSend API keyHighkeyword + regex + entropy
VNX-SEC-418Discord client secretHighkeyword + regex + entropy
VNX-SEC-419Slack app-level token (xapp-)Criticalkeyword + regex
VNX-SEC-420Slack config refresh token (xoxe-)Criticalkeyword + regex
VNX-SEC-421Slack config access token (xoxe.xoxp-/xoxb-)Criticalkeyword + regex
VNX-SEC-422Microsoft Graph / Azure AD client secretCriticalkeyword + regex + entropy
VNX-SEC-423Intercom access tokenHighkeyword + regex + entropy
VNX-SEC-424Zendesk API tokenHighkeyword + regex + entropy
VNX-SEC-425Freshchat API tokenHighkeyword + regex + entropy
VNX-SEC-426Front API tokenHighkeyword + regex + entropy
VNX-SEC-427Help Scout API key / app secretHighkeyword + regex + entropy
VNX-SEC-428Crisp API key / identifierHighkeyword + regex + entropy
VNX-SEC-429Drift API tokenHighkeyword + regex + entropy
VNX-SEC-430Customer.io tracking/app API keyHighkeyword + regex + entropy
VNX-SEC-431Klaviyo private API key (pk_)Criticalkeyword + regex
VNX-SEC-432Klaviyo OAuth refresh tokenHighkeyword + regex + entropy
VNX-SEC-433Iterable API keyHighkeyword + regex + entropy
VNX-SEC-434Braze REST API keyHighkeyword + regex + entropy
VNX-SEC-435OneSignal REST API key (os_v2)Criticalkeyword + regex
VNX-SEC-436OneSignal REST API key (legacy hex)Highkeyword + regex + entropy
VNX-SEC-437Pusher Channels app secretHighkeyword + regex + entropy
VNX-SEC-438Pusher Channels app keyMediumkeyword + regex + entropy
VNX-SEC-439Ably API keyCriticalkeyword + regex + entropy
VNX-SEC-440PubNub publish key (pub-c-)Highkeyword + regex
VNX-SEC-441PubNub subscribe key (sub-c-)Mediumkeyword + regex
VNX-SEC-442PubNub secret key (sec-c-)Criticalkeyword + regex
VNX-SEC-443Stream (getstream) API secretHighkeyword + regex + entropy
VNX-SEC-444Stream (getstream) API keyMediumkeyword + regex + entropy
VNX-SEC-445Courier auth token (pk_prod_/pk_test_)Highkeyword + regex
VNX-SEC-446Knock API key (sk_/sk_test_)Highkeyword + regex + entropy
VNX-SEC-447Loops API keyHighkeyword + regex + entropy
VNX-SEC-448Resend API key (re_)Criticalkeyword + regex
VNX-SEC-449Brevo/Sendinblue API key (xkeysib-)Criticalkeyword + regex
VNX-SEC-450Brevo/Sendinblue SMTP key (xsmtpsib-)Highkeyword + regex
VNX-SEC-451Mailtrap API tokenHighkeyword + regex + entropy
VNX-SEC-452SMTP2GO API key (api-)Highkeyword + regex + entropy
VNX-SEC-453SendGrid subuser/marketing API key (SG.)Highkeyword + regex + entropy
VNX-SEC-454Mailgun sending API key (key-)Highkeyword + regex + entropy
VNX-SEC-455Postmark account tokenHighkeyword + regex + entropy
VNX-SEC-456Telnyx public key (TKEY/v2 public)Mediumkeyword + regex + entropy
VNX-SEC-458Twilio SendGrid subuser SMTP passwordHighkeyword + regex + entropy
VNX-SEC-459Telnyx Messaging Profile secretHighkeyword + regex + entropy
VNX-SEC-460Mailchimp Transactional (Mandrill md- key)Highkeyword + regex + entropy
VNX-SEC-461Knock public API key (pk_)Lowkeyword + regex + entropy
VNX-SEC-462Customer.io App API key (Bearer)Highkeyword + regex + entropy
VNX-SEC-463Customer.io tracking site/API key pairHighkeyword + regex + entropy
VNX-SEC-464Infobip Basic auth API key (App)Highkeyword + regex + entropy
VNX-SEC-465Ably API key (keyword context)Criticalkeyword + regex + entropy
VNX-SEC-466PubNub secret/keyword keyHighkeyword + regex + entropy
VNX-SEC-467Courier auth token (keyword context)Highkeyword + regex + entropy
VNX-SEC-468Loops transactional API key (keyword)Highkeyword + regex + entropy
VNX-SEC-469Sinch service plan ID + token (Bearer)Highkeyword + regex + entropy
VNX-SEC-470Help Scout OAuth2 app id/secret pairHighkeyword + regex + entropy
VNX-SEC-471Intercom OAuth client secretHighkeyword + regex + entropy
VNX-SEC-472ClickSend username+API key Basic headerHighkeyword + regex + entropy
VNX-SEC-473Bandwidth account API token+secret pairHighkeyword + regex + entropy
VNX-SEC-474Plivo Basic auth header (Auth ID:Token)Highkeyword + regex + entropy
VNX-SEC-475Stream getstream JWT server tokenHighkeyword + regex + entropy
VNX-SEC-476Freshchat bundle/app token (keyword)Highkeyword + regex + entropy
VNX-SEC-477Resend webhook signing secret (whsec_)Mediumkeyword + regex
VNX-SEC-478Drift OAuth client secretHighkeyword + regex + entropy
VNX-SEC-479Crisp plugin token (keyword)Highkeyword + regex + entropy
VNX-SEC-480Iterable JWT-enabled API keyHighkeyword + regex + entropy

Remediation

Rotate any exposed credential immediately, remove it from source, and load it from a secrets manager or environment variable instead. Purge it from git history with git filter-repo. See CWE-798 and the OWASP Secrets Management Cheat Sheet.