Skip to contents

Creates an opt-in signature registry for common provider credentials plus a contextual high-entropy token check. Values matching an allowlist pattern or obvious placeholders are ignored. Detection never verifies a credential over the network.

Usage

secret_registry(
  signatures = NULL,
  allowlist = c("(?i)(example|sample|placeholder|dummy|redacted|your[_ -]?(key|token))"),
  min_entropy = 3.5,
  decoding_depth = 1L,
  version = "2026.1",
  show_stats = FALSE
)

Arguments

signatures

Optional named character vector of regular expressions. NULL uses the package registry.

allowlist

Character vector of regular expressions to ignore.

min_entropy

Minimum Shannon entropy for contextual generic tokens.

decoding_depth

Maximum bounded URL/base64 decode passes, from 0 to 3.

version

Registry version recorded with findings.

show_stats

Show construction time and available usage metrics.

Value

A shieldr_secret_registry object for scanner_options().

Examples

scanners <- scanner_options(secrets = secret_registry())