Dork source references
September 14, 2026 ยท View on GitHub
The dictionaries in github_dorks/dorks/ favor documented token prefixes and
canonical environment-variable names. The generated github-dorks.txt
aggregate contains every category for backward compatibility. Prefixes
generally produce stronger signals; variable-name searches also catch providers
that do not guarantee a stable public token format.
These references support the modern credential families added to the dictionary. They are not exhaustive, and a match still requires manual review.
Git hosting and package registries
AI providers
- OpenAI API key setup
- Claude API authentication
- Hugging Face user access tokens
- Groq API keys
- Mistral API authentication
- Cohere API keys
- Replicate API tokens
- Pinecone API keys
- LangSmith environment variables
Identity and secrets management
- 1Password service account tokens
- Vault token environment variable
- Doppler service tokens
- Infisical machine identities
- Auth0 application credentials
- Clerk environment variables
Databases and data platforms
- Neon API authentication
- PlanetScale service tokens
- Upstash Redis REST API
- Upstash Vector REST API
- MongoDB Atlas API authentication
- Databricks personal access tokens
Observability and developer security
- New Relic API keys
- Grafana service account tokens
- Honeycomb API keys
- PagerDuty API access keys
- Snyk authentication
Cloud and infrastructure
- HCP Terraform CLI credentials
- Cloudflare API tokens
- DigitalOcean API tokens
- Pulumi access tokens
- Vercel access tokens
- Supabase environment variables
- Sentry authentication tokens
- Netlify access tokens
- Fly.io access tokens
- Firebase CLI authentication