Skip to main content
Secrets policies configure TealSecrets to prevent API keys, tokens, and credentials from leaking through agent input, output, or memory. TealSecrets uses 500+ detection patterns with confidence scoring.

API Key Detection

Detect and block API keys and tokens across all major providers.

Credential Rotation — 90 Day

Enforce credential age limits with warning and denial thresholds.

Cloud Secrets — AWS

Targeted detection for AWS access keys, secret keys, and session tokens.

When to Use

Any agent that handles code, configuration, or infrastructure should have secrets detection enabled. Start with API Key Detection as your baseline, add Cloud Secrets for cloud-native workloads, and layer on Credential Rotation for compliance environments.
Combine with Deny Secrets in Memory to prevent secrets from persisting in agent memory stores.