3 ms·
It's totally free - there are details of how to join the program at https://docs.github.com/en/developers/overview/secret-scanning-partner-program#joining-the-s
by greysteil 4y ago
It's totally free - there are details of how to join the program at https://docs.github.com/en/developers/overview/secret-scanning-partner-program#joining-the-secret-scanning-program-on-github https://docs.github.com/en/developers/overview/secret-scanni...
- josephg 4y agoHm - this would work better if keys were easy to scan with regular expressions. Next time I implement api keys I wonder if it’s worth going out of my way to make them easy to identify. Eg, by prefixing every key with a few well known characters. Like FMLA_xxxxx for a fastmail app key.
- crazysim 4y agoThat's exactly what GitHub did with their own keys and their new keys fit this format. https://github.blog/2021-04-05-behind-githubs-new-authentication-token-formats/ https://github.blog/2021-04-05-behind-githubs-new-authentica...
- tough 4y agoI just implemented our API with a PREFIX_KEY so our self-hosted customers can change it they want to. We will be applying thanks for sharing greystell
- nijave 4y agoSome services also use prefixes to provide additional context like account type and token validity length. I think Slack does this (service accounts have different prefixes than user accounts and I think temporary tokens have another prefix)
- nmjenkins 4y agoIf you go make an API key in Fastmail (Settings -> Password & Security -> API tokens), you'll see that it's prefixed very similarly to that (e.g. `fmo1-`) for this very reason! (There are some other neat things about our API key format I'd be happy to tell you about sometime if you're interested.)
- josephg 4y agoHah I just used that as the first example which came to mind. Yeah absolutely - I'd love to hear about it!
- fragmede 4y agoIt's absolutely worth it, for everyone's sanity involved.