# Gitleaks Secret Scanner (`ayeeyee/gitleaks-secret-scanner`) Actor

Scan a public git repository's full commit history for hardcoded secrets: API keys, tokens, passwords, and credentials, using Gitleaks. Fingerprinted, deduped findings with severity scoring, plus SARIF and HTML reports for CI. Optional live-validation flags which leaked keys are still active.

- **URL**: https://apify.com/ayeeyee/gitleaks-secret-scanner.md
- **Developed by:** [Virtual Footprint LLC](https://apify.com/ayeeyee) (community)
- **Categories:** Developer tools
- **Stats:** 2 total users, 1 monthly users, 100.0% runs succeeded, 0 bookmarks
- **User rating**: No ratings yet

## Pricing

from $490.00 / 1,000 scan completeds

This Actor is paid per event. You are not charged for the Apify platform usage, but only a fixed price for specific events.

Learn more: https://docs.apify.com/platform/actors/running/actors-in-store#pay-per-event

## What's an Apify Actor?

Actors are web data automations that power AI and operations. They run on the Apify platform to scrape websites, process data, connect APIs, and automate workflows.
In Batch mode, an Actor accepts a well-defined JSON input, performs an action which can take anything from a few seconds to a few hours,
and optionally produces a well-defined JSON output, datasets with results, or files in key-value store.
In Standby mode, an Actor provides a web server which can be used as a website, API, or an MCP server.
Actors are written with capital "A".

## How to integrate an Actor?

If asked about integration, you help developers integrate Actors into their projects.
You adapt to their stack and deliver integrations that are safe, well-documented, and production-ready.
The best way to integrate Actors is as follows.

- **AI agents and MCP clients** — the [Apify MCP server](https://docs.apify.com/integrations/mcp.md) at `https://mcp.apify.com` (remote, streamable HTTP, OAuth on first use).
- **Agentic workflows and local Actor development** — [Agent Skills](https://apify.com/.well-known/agent-skills/index.json) with the [Apify CLI](https://docs.apify.com/cli/docs.md): `npm install -g apify-cli`, then `apify login`.
- **JavaScript/TypeScript projects** — the official [JS/TS client](https://docs.apify.com/api/client/js/docs.md): `npm install apify-client`.
- **Python projects** — the official [Python client](https://docs.apify.com/api/client/python/docs.md): `pip install apify-client`.
- **Any other language** — the [REST API](https://docs.apify.com/api/v2.md).

For usage examples, see the [API](#api) section below.

For more details, see Apify documentation as [Markdown index](https://docs.apify.com/llms.txt) and [Markdown full-text](https://docs.apify.com/llms-full.txt).

# README

<p align="center">
<img src="data:image/svg+xml;base64,PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHdpZHRoPSIxMjAwIiBoZWlnaHQ9IjMyMCIgdmlld0JveD0iMCAwIDEyMDAgMzIwIiByb2xlPSJpbWciIGFyaWEtbGFiZWxsZWRieT0idGl0bGUgZGVzYyI+CiAgPHRpdGxlIGlkPSJ0aXRsZSI+R2l0bGVha3MgU2VjcmV0IFNjYW5uZXI8L3RpdGxlPgogIDxkZXNjIGlkPSJkZXNjIj5GdWxsIGdpdCBoaXN0b3J5IHNjYW5uZWQgYnkgZGVmYXVsdCDigJQgbm90IGp1c3QgY3VycmVudCBmaWxlczwvZGVzYz4KICA8ZGVmcz4KICAgIDxsaW5lYXJHcmFkaWVudCBpZD0iZWRnZSIgeDE9IjAiIHkxPSIwIiB4Mj0iMSIgeTI9IjEiPgogICAgICA8c3RvcCBvZmZzZXQ9IjAiIHN0b3AtY29sb3I9IiNmOTczMTYiIHN0b3Atb3BhY2l0eT0iMC4xOCIvPgogICAgICA8c3RvcCBvZmZzZXQ9IjEiIHN0b3AtY29sb3I9IiNmOTczMTYiIHN0b3Atb3BhY2l0eT0iMCIvPgogICAgPC9saW5lYXJHcmFkaWVudD4KICA8L2RlZnM+CiAgPHJlY3Qgd2lkdGg9IjEyMDAiIGhlaWdodD0iMzIwIiByeD0iMjYiIGZpbGw9IiMwYTBkMTIiLz4KICA8cmVjdCB3aWR0aD0iMTIwMCIgaGVpZ2h0PSIzMjAiIHJ4PSIyNiIgZmlsbD0idXJsKCNlZGdlKSIvPgogIDxyZWN0IHg9IjAuNSIgeT0iMC41IiB3aWR0aD0iMTE5OSIgaGVpZ2h0PSIzMTkiIHJ4PSIyNS41IiBmaWxsPSJub25lIiBzdHJva2U9IiMxYzIxMjkiIHN0cm9rZS13aWR0aD0iMSIvPgoKICA8ZyBpZD0idGl0bGUtYmxvY2siIHRyYW5zZm9ybT0idHJhbnNsYXRlKDU2IDY0KSI+CiAgICA8cmVjdCB4PSIwIiB5PSItMjgiIHdpZHRoPSIxMCIgaGVpZ2h0PSIxMCIgcng9IjIiIGZpbGw9IiNmOTczMTYiLz4KICAgIDx0ZXh0IHg9IjIwIiB5PSItMjAiIGZvbnQtZmFtaWx5PSJ1aS1tb25vc3BhY2UsIFNGTW9uby1SZWd1bGFyLCBNZW5sbywgbW9ub3NwYWNlIiBmb250LXNpemU9IjEyIiBmaWxsPSIjZjk3MzE2Ij5TRUNVUklUWSBTQ0FOTkVSIMK3IFJFQUwgREFUQSwgTk8gRkFCUklDQVRJT048L3RleHQ+CiAgICA8dGV4dCB4PSIwIiB5PSIyNiIgZm9udC1mYW1pbHk9Ii1hcHBsZS1zeXN0ZW0sIEJsaW5rTWFjU3lzdGVtRm9udCwgU2Vnb2UgVUksIHNhbnMtc2VyaWYiIGZvbnQtc2l6ZT0iNDAiIGZvbnQtd2VpZ2h0PSI4MDAiIGZpbGw9IiNmZmZmZmYiPkdpdGxlYWtzIFNlY3JldCBTY2FubmVyPC90ZXh0PgogICAgPHRleHQgeD0iMCIgeT0iNjAiIGZvbnQtZmFtaWx5PSItYXBwbGUtc3lzdGVtLCBCbGlua01hY1N5c3RlbUZvbnQsIFNlZ29lIFVJLCBzYW5zLXNlcmlmIiBmb250LXNpemU9IjE2IiBmaWxsPSIjYzlkMWQ5Ij5GdWxsIGdpdCBoaXN0b3J5IHNjYW5uZWQgYnkgZGVmYXVsdCDigJQgbm90IGp1c3QgY3VycmVudCBmaWxlczwvdGV4dD4KICAgIDxnIHRyYW5zZm9ybT0idHJhbnNsYXRlKDAgMTAwKSI+CiAgICAgIAogICAgPGcgdHJhbnNmb3JtPSJ0cmFuc2xhdGUoMCAwKSI+CiAgICAgIDx0ZXh0IHg9IjAiIHk9IjAiIGZvbnQtZmFtaWx5PSItYXBwbGUtc3lzdGVtLCBCbGlua01hY1N5c3RlbUZvbnQsIFNlZ29lIFVJLCBzYW5zLXNlcmlmIiBmb250LXNpemU9IjI4IiBmb250LXdlaWdodD0iNzAwIiBmaWxsPSIjZmZmZmZmIj4xNTArPC90ZXh0PgogICAgICA8dGV4dCB4PSIwIiB5PSIyMCIgZm9udC1mYW1pbHk9Ii1hcHBsZS1zeXN0ZW0sIEJsaW5rTWFjU3lzdGVtRm9udCwgU2Vnb2UgVUksIHNhbnMtc2VyaWYiIGZvbnQtc2l6ZT0iMTIiIGZpbGw9IiM4Yjk0OWUiPkRldGVjdGlvbiBydWxlczwvdGV4dD4KICAgIDwvZz4KICAgIDxnIHRyYW5zZm9ybT0idHJhbnNsYXRlKDE1MCAwKSI+CiAgICAgIDx0ZXh0IHg9IjAiIHk9IjAiIGZvbnQtZmFtaWx5PSItYXBwbGUtc3lzdGVtLCBCbGlua01hY1N5c3RlbUZvbnQsIFNlZ29lIFVJLCBzYW5zLXNlcmlmIiBmb250LXNpemU9IjI4IiBmb250LXdlaWdodD0iNzAwIiBmaWxsPSIjZmZmZmZmIj5oaXN0b3J5PC90ZXh0PgogICAgICA8dGV4dCB4PSIwIiB5PSIyMCIgZm9udC1mYW1pbHk9Ii1hcHBsZS1zeXN0ZW0sIEJsaW5rTWFjU3lzdGVtRm9udCwgU2Vnb2UgVUksIHNhbnMtc2VyaWYiIGZvbnQtc2l6ZT0iMTIiIGZpbGw9IiM4Yjk0OWUiPlNjYW4gbW9kZTwvdGV4dD4KICAgIDwvZz4KICAgIDxnIHRyYW5zZm9ybT0idHJhbnNsYXRlKDMwMCAwKSI+CiAgICAgIDx0ZXh0IHg9IjAiIHk9IjAiIGZvbnQtZmFtaWx5PSItYXBwbGUtc3lzdGVtLCBCbGlua01hY1N5c3RlbUZvbnQsIFNlZ29lIFVJLCBzYW5zLXNlcmlmIiBmb250LXNpemU9IjI4IiBmb250LXdlaWdodD0iNzAwIiBmaWxsPSIjZmZmZmZmIj5yZWRhY3RlZDwvdGV4dD4KICAgICAgPHRleHQgeD0iMCIgeT0iMjAiIGZvbnQtZmFtaWx5PSItYXBwbGUtc3lzdGVtLCBCbGlua01hY1N5c3RlbUZvbnQsIFNlZ29lIFVJLCBzYW5zLXNlcmlmIiBmb250LXNpemU9IjEyIiBmaWxsPSIjOGI5NDllIj5GYWxzZSBwb3NpdGl2ZXM8L3RleHQ+CiAgICA8L2c+CiAgICA8L2c+CiAgPC9nPgoKICA8ZyBpZD0icHJvamVjdC1wcm9vZiIgdHJhbnNmb3JtPSJ0cmFuc2xhdGUoNzAwIDc2KSI+CiAgICA8cmVjdCB4PSItMjQiIHk9Ii00MCIgd2lkdGg9IjQ3MCIgaGVpZ2h0PSIyMjAiIHJ4PSIxNCIgZmlsbD0iIzBkMTExNyIgc3Ryb2tlPSIjMWMyMTI5IiBzdHJva2Utd2lkdGg9IjEiLz4KICAgIDx0ZXh0IHg9IjAiIHk9Ii0xNCIgZm9udC1mYW1pbHk9InVpLW1vbm9zcGFjZSwgU0ZNb25vLVJlZ3VsYXIsIE1lbmxvLCBtb25vc3BhY2UiIGZvbnQtc2l6ZT0iMTEiIGZpbGw9IiM4Yjk0OWUiPiQgYXBpZnkgY2FsbCBnaXRsZWFrcy1zZWNyZXQtc2Nhbm5lcjwvdGV4dD4KICAgIDxnIHRyYW5zZm9ybT0idHJhbnNsYXRlKDAgMTYpIj4KICAgICAgCiAgICA8ZyB0cmFuc2Zvcm09InRyYW5zbGF0ZSgwIDApIj4KICAgICAgPHJlY3QgeD0iMCIgeT0iMCIgd2lkdGg9IjEwIiBoZWlnaHQ9IjEwIiByeD0iMiIgZmlsbD0iI2ZmNWY1NiIvPgogICAgICA8dGV4dCB4PSIxOCIgeT0iOSIgZm9udC1mYW1pbHk9InVpLW1vbm9zcGFjZSwgU0ZNb25vLVJlZ3VsYXIsIE1lbmxvLCBtb25vc3BhY2UiIGZvbnQtc2l6ZT0iMTIiIGZpbGw9IiNjOWQxZDkiPmdpdGh1Yi1wYXQgIGNvbmZpZy5weTozPC90ZXh0PgogICAgPC9nPgogICAgPGcgdHJhbnNmb3JtPSJ0cmFuc2xhdGUoMCAyNikiPgogICAgICA8cmVjdCB4PSIwIiB5PSIwIiB3aWR0aD0iMTAiIGhlaWdodD0iMTAiIHJ4PSIyIiBmaWxsPSIjZmY1ZjU2Ii8+CiAgICAgIDx0ZXh0IHg9IjE4IiB5PSI5IiBmb250LWZhbWlseT0idWktbW9ub3NwYWNlLCBTRk1vbm8tUmVndWxhciwgTWVubG8sIG1vbm9zcGFjZSIgZm9udC1zaXplPSIxMiIgZmlsbD0iI2M5ZDFkOSI+YXdzLWFjY2Vzcy10b2tlbiAgY29uZmlnLnB5OjE8L3RleHQ+CiAgICA8L2c+CiAgICA8ZyB0cmFuc2Zvcm09InRyYW5zbGF0ZSgwIDUyKSI+CiAgICAgIDxyZWN0IHg9IjAiIHk9IjAiIHdpZHRoPSIxMCIgaGVpZ2h0PSIxMCIgcng9IjIiIGZpbGw9IiNmOTczMTYiLz4KICAgICAgPHRleHQgeD0iMTgiIHk9IjkiIGZvbnQtZmFtaWx5PSJ1aS1tb25vc3BhY2UsIFNGTW9uby1SZWd1bGFyLCBNZW5sbywgbW9ub3NwYWNlIiBmb250LXNpemU9IjEyIiBmaWxsPSIjYzlkMWQ5Ij5jb21taXQgYTFiMmMzZCDCtyBhdXRob3IgcmVkYWN0ZWQ8L3RleHQ+CiAgICA8L2c+CiAgICA8ZyB0cmFuc2Zvcm09InRyYW5zbGF0ZSgwIDc4KSI+CiAgICAgIDxyZWN0IHg9IjAiIHk9IjAiIHdpZHRoPSIxMCIgaGVpZ2h0PSIxMCIgcng9IjIiIGZpbGw9IiM1MWNmNjYiLz4KICAgICAgPHRleHQgeD0iMTgiIHk9IjkiIGZvbnQtZmFtaWx5PSJ1aS1tb25vc3BhY2UsIFNGTW9uby1SZWd1bGFyLCBNZW5sbywgbW9ub3NwYWNlIiBmb250LXNpemU9IjEyIiBmaWxsPSIjYzlkMWQ5Ij5vY3RvY2F0L0hlbGxvLVdvcmxkIMK3IDAgc2VjcmV0cyBmb3VuZDwvdGV4dD4KICAgIDwvZz4KICAgIDwvZz4KICA8L2c+Cjwvc3ZnPg==" width="100%" alt="gitleaks-secret-scanner hero banner">
</p>

<p align="center">
  <a href="https://github.com/gitleaks/gitleaks"><img src="https://img.shields.io/badge/powered%20by-Gitleaks-F97316?style=for-the-badge" alt="Powered by Gitleaks"></a>
  <img src="https://img.shields.io/badge/License-MIT-555555?style=for-the-badge" alt="MIT">
  <img src="https://img.shields.io/badge/Detection%20Rules-150%2B-F86606?style=for-the-badge" alt="150+ rules">
  <img src="https://img.shields.io/badge/Scan%20Mode-Full%20History-20A34E?style=for-the-badge" alt="Full history scan">
</p>

<p align="center">
  <a href="#why-full-history">Why full history</a> &bull;
  <a href="#use-cases">Use cases</a> &bull;
  <a href="#input">Input</a> &bull;
  <a href="#output">Output</a> &bull;
  <a href="#pricing">Pricing</a>
</p>

## Gitleaks Secret Scanner

**Find hardcoded API keys, tokens, and credentials anywhere in a public repo's git history — not just its current files.**

> **Verified live**: a test repo with a fake GitHub PAT and AWS access key committed and never removed — this Actor caught both, correctly, with rule ID, file, line, and commit metadata. A companion test against a real clean repo (`octocat/Hello-World`) correctly returned zero findings.

### Why full history

Deleting a secret from the latest commit does not remove it from git history — anyone who clones the repo can still dig it out of an old commit. Most scanners only check what's currently checked out. This one scans the **full commit log by default**, because that's where forgotten secrets actually hide.

### Use cases

- **Pre-open-source audit** — scan a private repo for committed credentials before flipping it public.
- **Onboarding/offboarding cleanup** — sweep a repo's full history after a contractor or employee with credential access leaves.
- **M\&A / acquisition due diligence** — check a target company's codebase for leaked keys before the deal closes.
- **Incident response** — after any credential is suspected leaked, confirm scope: which repos, which commits, which files.
- **CI/CD gate** — block merges that introduce new secrets, and periodically re-scan full history to catch what slipped through earlier.
- **Vendor/contractor code review** — scan third-party code before integrating it into your monorepo.
- **Compliance evidence** — produce an audit trail showing regular secret-scanning as part of SOC2 or ISO 27001 controls.

### Input

| Field | Type | Required | Notes |
| --- | --- | --- | --- |
| `target` | string | yes | Public git repo URL |
| `scanMode` | string | no | `history` (default, full commit log) or `working-tree` (current files only) |
| `engine` | string | no | `gitleaks` (default, pattern match only) or `betterleaks` (pattern match + optional live validation) |
| `liveValidation` | boolean | no | `betterleaks` engine only. Makes an authenticated HTTP request per match to confirm the credential is still active -- turns "this looks like an AWS key" into "this AWS key still works" |
| `revealSecrets` | boolean | no | Off by default — matched secrets are redacted (`ghp_****...ab12`) |

```json
{ "target": "https://github.com/owner/repo", "scanMode": "history", "engine": "betterleaks", "liveValidation": true }
```

### Output

One row per real secret found (rule, file, line, commit, author, redacted value, severity, confidence, fingerprint, remediation guidance), plus one `scan_summary` row with totals by rule and severity. Redaction is on by default so this Actor's own output can't become a new leak.

Every scan also writes a **SARIF 2.1.0 report** (`report.sarif`, GitHub code-scanning compatible) and a self-contained **HTML report** (`report.html`) to the key-value store, linked from the summary row.

#### Engines

- **gitleaks** (default) — fast, no network calls beyond the clone itself, zero false-negative risk from a validation endpoint being unreachable.
- **betterleaks** — built by the original Gitleaks author. Same detection lineage, plus an opt-in live-validation step: when `liveValidation` is on, each matched secret is checked with a real authenticated request, and its `confidence` field becomes `confirmed-live`, `invalid`, `unknown`, or `needs_validation` instead of just `confirmed` (pattern match only). This is the difference between "a key-shaped string exists in this file" and "this key still opens something."

#### Sample output

One real finding from a live scan of a public test-fixture repo with intentionally committed fake credentials:

```json
{
  "findingType": "secret",
  "target": "https://github.com/trufflesecurity/test_keys",
  "engine": "gitleaks",
  "ruleId": "aws-access-token",
  "severity": "high",
  "confidence": "confirmed",
  "remediation": "Rotate this credential immediately, then remove it from git history (git filter-repo / BFG) if it appeared in a prior commit -- deleting the file alone does not remove it from history.",
  "description": "Identified a pattern that may indicate AWS credentials, risking unauthorized cloud resource access and data breaches on AWS platforms.",
  "file": "new_key",
  "startLine": 2,
  "secret": "AKIA************ZAM2",
  "fingerprint": "c664d5332d5f24ac",
  "commit": "0416560b1330d8ac42045813251d85c688717eaf",
  "author": "counter",
  "commitDate": "2023-10-19T02:56:37Z",
  "entropy": 3.6464393,
  "scannedAt": "2026-08-01T15:19:53.394484+00:00"
}
```

### Pricing

Pay per completed scan (Pay-Per-Event) — **$0.49 per scan**, charged once the scan finishes regardless of findings count. Failed scans (clone error) are never charged.

### FAQ

**Does it scan private repos?**
It clones whatever URL you give it, so yes if the Actor's run environment has access (pass credentials via `target` as an authenticated clone URL). Public repos work with no extra configuration.

**Will it re-report the same secret every run?**
No — each finding gets a stable `fingerprint` (hash of rule + file + secret, independent of line number), so you can dedupe across repeated scans in your own pipeline.

**What happens if the repo is huge?**
Full-history scanning is the default and the point of this Actor, but scan time scales with commit count, not just file count. Use `scanMode: "working-tree"` if you only need current-file coverage and want a faster/cheaper run.

**Can I use this as a CI/CD gate?**
Yes — point it at the repo URL on a schedule or via webhook, and treat any `severity: "critical"` or `"high"` finding with `confidence: "confirmed"` (or `"confirmed-live"` on the betterleaks engine) as a merge blocker.

**Why pay for this instead of running gitleaks myself for free?**
Fair question — gitleaks itself is free and open source. This Actor is for hosted, schedulable, API-callable scanning with structured output (SARIF + HTML + normalized JSON), full-history-by-default coverage, and the optional betterleaks live-validation engine, without standing up your own CI runner for it.

### Related Actors

Part of a five-Actor security scanning catalog: [Trivy Security Scanner](https://apify.com/ayeeyee/trivy-security-scanner) (CVEs + secrets + misconfig in one pass), [Syft SBOM Generator](https://apify.com/ayeeyee/syft-sbom-generator), [Grype Vulnerability Matcher](https://apify.com/ayeeyee/grype-vulnerability-matcher), [OSV-Scanner Vulnerability Checker](https://apify.com/ayeeyee/osv-scanner-vulnerability-checker).

# Actor input Schema

## `target` (type: `string`):

Public git repository URL to scan, e.g. https://github.com/owner/repo

## `scanMode` (type: `string`):

history scans the full git commit log (finds secrets even if later deleted); working-tree scans only the current checked-out files.

## `revealSecrets` (type: `boolean`):

By default matched secrets are redacted (e.g. ghp\_\*\*\*\*...ab12). Enable to see the full matched value in results.

## `engine` (type: `string`):

gitleaks (default) is pattern-match only -- fast, no network calls. betterleaks is maintained by the original Gitleaks author and adds an optional live-validation step (see liveValidation) that confirms a matched secret is still an active credential, not just a pattern match.

## `liveValidation` (type: `boolean`):

Only applies when engine=betterleaks. Makes an authenticated HTTP request per matched secret to confirm it's still active, and sets each finding's confidence to confirmed-live / invalid / unknown accordingly. Off by default: adds scan time and outbound network calls, and pattern-match findings are still reported either way.

## Actor input object example

```json
{
  "target": "https://github.com/gitleaks/gitleaks",
  "scanMode": "history",
  "revealSecrets": false,
  "engine": "gitleaks",
  "liveValidation": false
}
```

# Actor output Schema

## `results` (type: `string`):

No description

# API

You can run this Actor programmatically using our API. Below are code examples in JavaScript, Python, and CLI, as well as the OpenAPI specification and MCP server setup.

## JavaScript example

```javascript
import { ApifyClient } from 'apify-client';

// Initialize the ApifyClient with your Apify API token
// Replace the '<YOUR_API_TOKEN>' with your token
const client = new ApifyClient({
    token: '<YOUR_API_TOKEN>',
});

// Prepare Actor input
const input = {
    "target": "https://github.com/gitleaks/gitleaks"
};

// Run the Actor and wait for it to finish
const run = await client.actor("ayeeyee/gitleaks-secret-scanner").call(input);

// Fetch and print Actor results from the run's dataset (if any)
console.log('Results from dataset');
console.log(`💾 Check your data here: https://console.apify.com/storage/datasets/${run.defaultDatasetId}`);
const { items } = await client.dataset(run.defaultDatasetId).listItems();
items.forEach((item) => {
    console.dir(item);
});

// 📚 Want to learn more 📖? Go to → https://docs.apify.com/api/client/js/docs

```

## Python example

```python
from apify_client import ApifyClient

# Initialize the ApifyClient with your Apify API token
# Replace '<YOUR_API_TOKEN>' with your token.
client = ApifyClient("<YOUR_API_TOKEN>")

# Prepare the Actor input
run_input = { "target": "https://github.com/gitleaks/gitleaks" }

# Run the Actor and wait for it to finish
run = client.actor("ayeeyee/gitleaks-secret-scanner").call(run_input=run_input)

# Fetch and print Actor results from the run's dataset (if there are any)
print("💾 Check your data here: https://console.apify.com/storage/datasets/" + run["defaultDatasetId"])
for item in client.dataset(run["defaultDatasetId"]).iterate_items():
    print(item)

# 📚 Want to learn more 📖? Go to → https://docs.apify.com/api/client/python/docs/quick-start

```

## CLI example

```bash
echo '{
  "target": "https://github.com/gitleaks/gitleaks"
}' |
apify call ayeeyee/gitleaks-secret-scanner --silent --output-dataset

```

## MCP server setup

```json
{
    "mcpServers": {
        "apify": {
            "command": "npx",
            "args": [
                "mcp-remote",
                "https://mcp.apify.com/?tools=ayeeyee/gitleaks-secret-scanner",
                "--header",
                "Authorization: Bearer <YOUR_API_TOKEN>"
            ]
        }
    }
}

```

## OpenAPI specification

Download the OpenAPI definition: https://api.apify.com/v2/acts/fiDYc6l2HNvwDBHXx/builds/5RmTMHUim2sCqMKhR/openapi.json
