GitHub Secret Scanning detects hardcoded credentials - such as API keys, tokens, and passwords - committed across a repository's Git history, and raises alerts so they can be rotated.
Required Permissions
read: organization/administration
read: repository/metadata
Scytale follows the least-privilege principle, limiting permission scopes strictly to what's required for reliable audit evidence collection.
How to Connect
In Scytale, go to 'Integrations'.
Search for GitHub Secret Scanning and select 'Connect'.
You will be redirected to GitHub to install the Scytale Secret Scanning app.
Note: You must have the owner or admin role on your GitHub organization in order to install the app.
Select the organization you want to monitor, choose the repositories to include, and approve the requested permissions.
Add a connection name — this will be used to differentiate between your connections — and then select 'Connect'.
You have now successfully connected to GitHub Secret Scanning.
