OAuth client secrets

Identifies oauth client secrets patterns in security and access control contexts. Detects potential exposure of sensitive security information in international systems.

Type
regex
Engine
boost_regex
Confidence
medium
Confidence justification
category-aware structural regex with anchor and context constraints replaces phrase-only detection. Added context gating and exclusion rules improve precision and reduce incidental matches.
Detection quality
Topic verified
Jurisdictions
global
Regulations
GDPR, Criminal Code Act 1995 (Cth), NDB Scheme (Cth), SOCI Act 2018 (Cth), TIA Act 1979 (Cth)
Data categories
credentials, security
Scope
wide
Risk rating
8
Platform compatibility
Purview: Compatible, GCP DLP: Compatible, Macie: Compatible, Zscaler: Compatible, Palo Alto: Degraded, Netskope: Unsupported

Pattern

(?is)\b(?:client\s+secret|client\s+id|authorization\s+code|access\s+token|refresh\s+token|bearer\s+token|openid\s+connect|grant\s+type|redirect\s+uri|token\s+endpoint)\b

Corroborative evidence keywords

oauth client secrets, oauth, client, secrets, credentials, keys, OFFICIAL, OFFICIAL:Sensitive, PROTECTED, SECRET, TOP SECRET, CABINET-IN-CONFIDENCE, NOFORN, REL TO, ORCON, National Cabinet, AUSTEO, [object Object], Sensitive: Legal, Sensitive: Personal Privacy (+54 more)

Proximity: 300 characters

Should match

Should not match

Known false positives