Secret scanning CLI for hardcoded keys and API tokens.

Use Radar as a local secret scanning CLI to catch hardcoded secrets, API keys, private credentials, and risky placeholders before review.

radar scan . --quick

Hardcoded secrets scanner

Radar reports committed tokens and credential-like literals alongside SAST, dependency, and code-health findings so reviewers see one merge-readiness signal.

  • API key scanner
  • Git secrets scanner alternative
  • Private credential findings
  • Review-ready severity

Evidence to inspect

Use “Secret scanning CLI for hardcoded keys and API tokens.” as the scope for this decision: verify the input, finding detail, workflow handoff, and product boundary before you install or buy.

CriterionEvidence to inspectBoundary
Input scopeSelected files, configuration, scan mode, and enabled rules.Only included paths and configured checks are evaluated.
Finding detailFile, line, rule ID, severity, explanation, and repair direction.Illustrative output is not a result from your repository.
Workflow handoffLocal result, report format, agent context, and optional CI signal.Enable exports or CI only when the workflow needs them.
Decision fitUse the same criteria on a real repository before choosing a plan or tool.No universal winner or guaranteed outcome is claimed.

Run this check locally

Works before push and in CI

Run secret checks locally, from a Git hook, or inside GitHub Actions with the same report model.

radar scan . --quick
radar hook install
radar scan . --format sarif --fail-on high

Validate the workflow on your own code.

Apply this page’s evidence to one real repository. For “Secret scanning CLI for hardcoded keys and API tokens.”, confirm which finding is produced, whether the proposed next step is reproducible, and where local scanning, reports, agents, or CI should stop or expand.