Secure code scanning for developers

Catch secrets before the commit

SonarQube catches exposed secrets—like passwords and access tokens—the moment they are written. With actionable code intelligence, developers can remediate immediately, ensuring code security and code health are maintained at the speed of development.

Secrets Detection
TRUSTED BY OVER 7M DEVELOPERS WORLDWIDE
Nvidia
Mercedes Benz
J P Morgan
Santander
secure

The risk of hardcoded secrets

warning

Why prevention is better than remediation

How does secrets detection work?

SonarQube for IDE image

SonarQube for IDE

SonarQube Cloud image

SonarQube Cloud

SonarQube Server image

SonarQube Server

What makes SonarQube’s secrets detection the best code scanning tool for you

lock

Powerful

lightning

Fast

devops

Comprehensive

sonar

Accurate

heart

Reliable

oss

Open source

code merge

Integrated

secure

Governance

Additional resources

Build trust into every line of code

Ready to deliver better, secure code? Get started today with the SonarQube deployment that's right for you.

Rating image

4.6 / 5

Secrets Detection FAQs

What is secrets detection and why is it important for quality code?

How does Sonar detect secrets in source code?

Can Sonar’s secrets detection be automated in CI/CD pipelines?

Which types of secrets does Sonar detect in code?

How can developers remediate secrets detected by Sonar?

Does Sonar store any identifiable data about the secrets it finds?

How long is secrets detection data retained by Sonar?

Can secrets detection be configured for different environments or user journeys?

What happens if a secret is found after code is deployed?

How does secrets detection contribute to compliance and audit readiness?

Does secrets detection work with AI-generated code?

How is secrets detection priced, and which plans include it?