OVERALL RATINGS
INSTALLS
50
SUPPORT
- Partner Supported
TRUST SIGNALS
- Requires
- CONFLUENCE
- Works with
- JIRA
Key highlights of the appDetect and redact 50+ leaked credential types in Confluence — with automatic Jira incident escalation

Detect and redact 50+ credential types
Scans Confluence pages and comments for AWS/GCP keys, GitHub and Stripe tokens, database connection strings, SSH/PEM private keys, JWTs, and more — then redacts each one in place, formatting preserved.
Escalate high-risk leaks straight to Jira
A real, exploitable secret can auto-open a tracked Jira incident with project, issue type, priority, and assignee already set (requires Secret Sentinel for Jira, same site) — not just a dashboard entry nobody checks.
Tune detection to your organization
Override severity and escalation per credential type or space, mark known-safe placeholder values as permanently ignored, and add your own regex patterns with the Advanced edition's ReDoS-safe custom rule engine.
Supporting media
Editions New
This app offers two different editions - Standard and Advanced. You can start a free trial of either edition, and change your edition anytime during or after the trial.
Standard
Onboard your team and scale fast
Includes:
Automatic secret detection & redaction
Broad secret type coverage
Jira incident escalation
Severity & escalation rules
Per-value allowlist
Advanced
Unlock the full range of app features
Everything from Standard, plus:
Custom regex detection rules
Compliance dashboard
More details
Secret Sentinel scans Confluence content for 50+ types of leaked credentials — AWS and GCP keys, GitHub and Stripe tokens, DB connection strings, SSH/PEM private keys, JWTs, and more — built on the open-source secretlint engine, not a closed pattern list. Every finding is classified by real exploitability, not keyword matching, so you see fewer, more meaningful alerts. Secrets are redacted in place with formatting preserved.
High-risk leaks can auto-open a tracked Jira incident (requires Secret Sentinel for Jira, same site). Severity, escalation, and exclusions are configurable per credential type — every override is auditable.
Built entirely on Atlassian Forge — no external servers, no environment variables, nothing leaves your instance. Advanced edition adds a compliance dashboard and custom, ReDoS-safe regex patterns.
Verify before installing: Trust Center — data flow, storage, permissions, benchmark, and methodology.
Resources
App documentation
Comprehensive set of documentation from the partner on how this app works
Privacy and Security
Privacy policy
Atlassian's privacy policy is not applicable to the use of this app. Please refer to the privacy policy provided by this app's partner.
Partner privacy policySecurity program
This app is not part of the Marketplace Bug Bounty program.
Integration permissions
Secret Sentinel - Password Leak Scanner for Confluence integrates with your Atlassian app
Version information
Version 3.0.0•for Confluence Cloud
- Release date
- Aug 4th 2026
- Summary
- Required scopes and editions enabled status changed
- Details
Required scopes changed:
- Added: read:space:confluence
- Payment model
- Paid via Atlassian
- License type
- Commercial