
Detect secrets + live validation. Map blast radius. Revoke fast. Use the CLI or embed in Rust and Python.
Find leaked secrets. Validate what’s live. Map the blast radius. Revoke fast.
Kingfisher is a blazingly fast, completely free and open source secret scanner built in Rust. It detects leaked secrets across your entire stack with hundreds of built-in rules, validates which credentials are actually live, maps the blast radius of every leak, and revokes exposed secrets in minutes - the full defender workflow in one Apache-2.0-licensed release:
Detect → Validate → Map → Triage → Revoke
Defender workflow: Follow the end-to-end defender workflow for secret detection, validation, notifications, blast-radius mapping, and revocation.
Add Kingfisher's fast secret scanning, live credential validation, and revocation to your own applications through a Python module or native Rust library. Everything runs in-process, with no CLI subprocess required.
uv add kingfisher-secret-scanner and import kingfisher_sdk.
See the Python SDK guide and runnable examples
for scanning, validation, rule inspection, and explicit revocation.kingfisher-scanner. See the library guide and
runnable examples for scanning and validation,
plus revocation via kingfisher-scanner.Kingfisher handles local files and directories, Git repositories and history, compressed and office-document archives, SQLite databases, Python bytecode, Docker images, source-hosting organizations, cloud object storage, collaboration tools, and API-development platforms.
| Files / Dirs | Local Git | GitHub | GitLab | Azure Repos | Bitbucket | Gitea | Hugging Face |
|---|---|---|---|---|---|---|---|
Files / Dirs | Local Git | GitHub | GitLab | Azure Repos | Bitbucket | Gitea | Hugging Face |
| Docker | Jira | Confluence | Slack | Teams | Postman | AWS S3 | Google Cloud |
|---|---|---|---|---|---|---|---|
Docker | Jira | Confluence | Slack | Teams | Postman | AWS S3 | Cloud Storage |
For target-specific commands, authentication, scope, and pagination behavior, use the platform integration guide.
Of the popular secret scanning tools compared below, only Kingfisher and Betterleaks 2.0 offer built-in credential revocation. All open source, with no paid edition required.
| Built-in capability | Kingfisher | Betterleaks 2.0 | TruffleHog OSS | Gitleaks |
|---|---|---|---|---|
| (Find) Secret discovery | ✅ | ✅ | ✅ | ✅ |
| (Validate) Live credential verification | ✅ | ✅ | ✅ | ❌ |
| (Map) Identity and permission analysis | ✅ | ✅ | ✅ | ❌ |
| (Revoke) Credential revocation | ✅ | ✅ | ❌ | ❌ |
| License | Apache-2.0 | MIT | AGPL-3.0 | MIT |
✅ Supported · ❌ Not Supported
Kingfisher's multithreaded Vectorscan engine recorded the lowest runtime on every repository in the published benchmark suite, from small projects through the Linux kernel and GitLab monorepo. Lower runtimes are better.