OVERALL RATINGS
INSTALLS
50
SUPPORT
- Partner Supported
TRUST SIGNALS
Key highlights of the appDetect and redact 50+ leaked credential types in Jira — with automatic security incident escalation

Detect and redact 50+ credential types
Scans Jira issues and comments for AWS/GCP keys, GitHub and Stripe tokens, database connection strings, SSH/PEM private keys, JWTs, and more — then redacts each one in place, formatting preserved.
Escalate high-risk leaks automatically
A real, exploitable secret can automatically open a tracked Jira security incident with project, issue type, priority, and assignee already set — not just a dashboard entry nobody checks.
Tune detection to your organization
Override severity and escalation per credential type or project, mark known-safe placeholder values as permanently ignored, and add your own regex patterns with the Advanced edition's ReDoS-safe custom rule engine.
Supporting media
Editions New
This app offers two different editions - Standard and Advanced. You can start a free trial of either edition, and change your edition anytime during or after the trial.
Standard
Onboard your team and scale fast
Includes:
Automatic secret detection & redaction
Broad secret type coverage
Security incident escalation
Severity & escalation rules
Per-value allowlist
Advanced
Unlock the full range of app features
Everything from Standard, plus:
Custom regex detection rules
Compliance dashboard
More details
Secret Sentinel scans Jira issues and comments for 50+ types of leaked credentials — AWS and GCP keys, GitHub and Stripe tokens, database connection strings, SSH/PEM private keys, JWTs, and more — built on the open-source secretlint engine, not a closed pattern list. Every finding is classified by real exploitability, not keyword matching, so you see fewer, more meaningful alerts. Secrets are redacted in place with formatting preserved.
High-risk leaks can automatically open a tracked Jira security incident. Severity, escalation, and exclusions are configurable per credential type or project — every override is auditable.
Built entirely on Atlassian Forge — no external servers, no environment variables, nothing leaves your instance. Advanced edition adds a compliance dashboard and custom, ReDoS-safe regex patterns.
Verify before installing: Trust Center — data flow, storage, permissions, benchmark, and methodology.
Resources
App documentation
Comprehensive set of documentation from the partner on how this app works
Privacy and Security
Privacy policy
Atlassian's privacy policy is not applicable to the use of this app. Please refer to the privacy policy provided by this app's partner.
Partner privacy policySecurity program
This app is not part of the Marketplace Bug Bounty program.
Integration permissions
Secret Sentinel - Password Leak Scanner for Jira integrates with your Atlassian app
Version information
Version 2.5.0•for Jira Cloud
- Release date
- Aug 5th 2026
- Summary
- Editions enabled status changed
- Details
Editions enabled status changed
- Payment model
- Paid via Atlassian
- License type
- Commercial