Skip to main content

GitLab Token

Description​

General​

Details for GitLab Token​

  • Family: token

  • Category: version_control_platform

  • Company: GitLab

  • High recall: False

  • Validity check available: True

  • Analyzer available: True

  • Revoker available: True

  • On-premise instances exist: True

  • Only valid secrets raise an alert: False

  • Occurrences found for one million commits: 5.51

  • Prefixed: False

Details for GitLab Token​

  • Family: token

  • Category: version_control_platform

  • Company: GitLab

  • High recall: False

  • Validity check available: True

  • Analyzer available: True

  • Revoker available: True

  • On-premise instances exist: True

  • Only valid secrets raise an alert: True

  • Occurrences found for one million commits: 0.08

  • Prefixed: False

Details for GitLab Token​

  • Family: token

  • Category: version_control_platform

  • Company: GitLab

  • High recall: True

  • Validity check available: True

  • Analyzer available: True

  • Revoker available: True

  • On-premise instances exist: True

  • Only valid secrets raise an alert: False

  • Occurrences found for one million commits: 127.5

  • Prefixed: True

Secret Analyzer​

Analysis Method​

  • Provider allows scopes enumeration: False
  • Total network call count: 68
  • Total call count may vary: True

HTTP Calls​

Requests are designed to capture metadata and not to function effectively.

  • DELETE: /api/v4/personal_access_tokens/*
  • DELETE: /api/v4/snippets/*
  • DELETE: /api/v4/user/emails/*
  • DELETE: /api/v4/user/gpg_keys/*
  • DELETE: /api/v4/user/keys/*
  • GET: /api/v4/bulk_imports/*/entities/*/failures
  • GET: /api/v4/bulk_imports/entities
  • GET: /api/v4/bulk_imports
  • GET: /api/v4/groups
  • GET: /api/v4/member_roles
  • GET: /api/v4/metadata
  • GET: /api/v4/namespaces/*/gitlab_subscription
  • GET: /api/v4/namespaces
  • GET: /api/v4/notification_settings
  • GET: /api/v4/orbit/schema
  • GET: /api/v4/personal_access_tokens/self
  • GET: /api/v4/personal_access_tokens
  • GET: /api/v4/projects
  • GET: /api/v4/search
  • GET: /api/v4/security/vulnerability_exports/*
  • GET: /api/v4/snippets
  • GET: /api/v4/todos
  • GET: /api/v4/user/activities
  • GET: /api/v4/user/emails
  • GET: /api/v4/user/gpg_keys
  • GET: /api/v4/user/keys
  • GET: /api/v4/user/preferences
  • GET: /api/v4/user/status
  • GET: /api/v4/user/support_pin
  • GET: /api/v4/user_counts
  • GET: /api/v4/user
  • GET: /api/v4/users/*/followers
  • GET: /api/v4/users/*/following
  • GET: /api/v4/users/*/starred_projects
  • GET: /api/v4/users/*
  • POST: /api/v4/ai/duo_workflows/workflows/*/resume
  • POST: /api/v4/bulk_imports
  • POST: /api/v4/chat/completions
  • POST: /api/v4/code_suggestions/completions
  • POST: /api/v4/code_suggestions/connection_details
  • POST: /api/v4/code_suggestions/direct_access
  • POST: /api/v4/groups/*/access_requests
  • POST: /api/v4/groups/import
  • POST: /api/v4/groups
  • POST: /api/v4/import/bitbucket_server
  • POST: /api/v4/import/bitbucket
  • POST: /api/v4/import/github/cancel
  • POST: /api/v4/import/github/gists
  • POST: /api/v4/import/github
  • POST: /api/v4/personal_access_tokens/*/rotate
  • POST: /api/v4/projects/import
  • POST: /api/v4/projects
  • POST: /api/v4/snippets
  • POST: /api/v4/topics/merge
  • POST: /api/v4/topics
  • POST: /api/v4/usage_data/increment_counter
  • POST: /api/v4/usage_data/track_event
  • POST: /api/v4/user/emails
  • POST: /api/v4/user/gpg_keys/*/revoke
  • POST: /api/v4/user/gpg_keys
  • POST: /api/v4/user/keys
  • POST: /api/v4/user/personal_access_tokens
  • POST: /api/v4/user/runners
  • POST: /api/v4/users/*/follow
  • POST: /api/v4/users/*/unfollow
  • PUT: /api/v4/snippets/*
  • PUT: /api/v4/user/avatar
  • PUT: /api/v4/user/preferences

Other Calls​

Non-HTTP queries or HTTP calls made through a third-party app (e.g., Python package). No other calls for this analyzer.

Revoker​

Auth Credentials​

Valid credentials needed to authenticate the request. No extra credentials needed for this revoker.

HTTP Calls​

List of calls performed by the revoker.

  • DELETE: /api/v4/personal_access_tokens/self

Revocation Mode​

Revocation is synchronous.