Skip to content

docs(security): Token and Credential Format - #19631

Merged
geoffg-sentry merged 3 commits into
masterfrom
geoffg-sentry/add-token-formats
Oct 7, 2026
Merged

geoffg-sentry merged 3 commits into
masterfrom
geoffg-sentry/add-token-formats

Conversation

@geoffg-sentry

@geoffg-sentry geoffg-sentry commented Sep 25, 2026 •

Copy link
Copy Markdown
Contributor

DESCRIBE YOUR PR

Docs on our legacy and existing credentials formats for make Sentry secrets identification simpler. Provides a first-party reference for secret scanners, agents, and incident responders.

IS YOUR CHANGE URGENT?

Help us prioritize incoming PRs by letting us know when the change needs to go live.
Select exactly one option. For deadlines, replace YYYY-MM-DD with the due date. You can update this information later by editing the PR description.

  • No deadline: Not urgent, can wait up to 1 week+

SLA

  • Teamwork makes the dream work, so please add a reviewer to your PRs.
  • Please give the docs team up to 1 week to review your PR unless you've supplied a deadline.

Thanks in advance for your help!

PRE-MERGE CHECKLIST

Make sure you've checked the following before merging your changes:

  • Checked Vercel preview for correctness, including links
  • PR was reviewed and approved by any necessary SMEs (subject matter experts)
  • PR was reviewed and approved by a member of the Sentry docs team

Docs on our legacy and existing credentials formats for make Sentry secrets identification simpler. Provides a first-party reference for secret scanners, agents, and incident responders.
@vercel

vercel Bot commented Sep 25, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
sentry-docs Ready Ready Preview Sep 25, 2026 8:12pm UTC
1 Skipped Deployment
Project Deployment Actions Updated
develop-docs Ignored Ignored Preview Sep 25, 2026 8:12pm UTC

Request Review

@github-actions github-actions Bot added the Priority: Normal Docs review has no urgent deadline label Sep 25, 2026
@codeowner-assignment
codeowner-assignment Bot requested a review from a team September 25, 2026 19:05
@geoffg-sentry geoffg-sentry changed the title New Token and Credential Format doc docs(security): Token and Credential Format Sep 25, 2026

Other apps may rename variables, wrap values in their own config, or store tokens with none of these strings nearby, so treat this as a starting point.

## Matching Caveats

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Is this supposed to be the section that is explaining how false positives might appear? Or is it the sum of all the information being shared here? It's not super clear, though I'm not an SME in the space. Would this page benefit from a TL;DR or what in fact might cause false positives?

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

A 32- or 64-character hex string is really generic on its own and I think the false positives here. I included the list of commons key names pulled from our own docs and source in the paragraph above, but that may not be the variable names others use so it's up to the folks scanning to reduce their own false positives with respect to generic formats.

@sfanahata sfanahata left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

👍 Not blocking, but left a comment asking for clarity, if it makes sense to add it.

@geoffg-sentry
geoffg-sentry merged commit 5884f8b into master Oct 7, 2026
28 checks passed
@geoffg-sentry
geoffg-sentry deleted the geoffg-sentry/add-token-formats branch October 7, 2026 18:42
solnic pushed a commit that referenced this pull request Oct 8, 2026
## DESCRIBE YOUR PR

Docs on our legacy and existing credentials formats for make Sentry
secrets identification simpler. Provides a first-party reference for
secret scanners, agents, and incident responders.

## IS YOUR CHANGE URGENT?

Help us prioritize incoming PRs by letting us know when the change needs
to go live.
Select exactly one option. For deadlines, replace `YYYY-MM-DD` with the
due date. You can update this information later by editing the PR
description.

- [X] No deadline: Not urgent, can wait up to 1 week+

## SLA

- Teamwork makes the dream work, so please add a reviewer to your PRs.
- Please give the docs team up to 1 week to review your PR unless you've
supplied a deadline.

Thanks in advance for your help!

## PRE-MERGE CHECKLIST

_Make sure you've checked the following before merging your changes:_

- [X] Checked Vercel preview for correctness, including links
- [X] PR was reviewed and approved by any necessary SMEs (subject matter
experts)
- [ ] PR was reviewed and approved by a member of the [Sentry docs
team](https://github.com/orgs/getsentry/teams/docs)

This branch was successfully deployed

2 active (1 outdated) deployments
Preview – sentry-docs — cf146d5b Deployed Sep 25, 2026 by vercel[bot]
Preview – develop-docs — a6964085 Deployed Sep 25, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Priority: Normal Docs review has no urgent deadline

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants