SAFE PRODUCT WALKTHROUGH
See the scanner's behavior without pasting a secret
Choose a verified scenario from Secret Sentinel's automated test suite. Every input below is synthetic and precomputed. This page runs no detection engine, accepts no user content, and sends no credential to Simplify or a third party.
GitHub token in a Jira comment
Verified against the Jira ADF tree-walking redactor.
Synthetic input
leaked: ghp_a1B2c3D4e5F6g7H8i9J0k1L2m3N4o5P6q7R8 endExpected Jira content
leaked: [REDACTED by Secret Sentinel:
github_token, ghp_****q7R8] end- Type
github_token- Severity
- High
- Content model
- Jira ADF text node
- Assertion
- Surrounding text remains unchanged
What this scenario proves—and what it does not
The fixture verifies classification, masking, and replacement inside a Jira ADF text node. It does not claim attachment scanning, credential validity checking, or automatic revocation. A real detected credential must still be rotated.
AWS identifier and secret in Confluence
Verified against the Confluence storage-format HTML redactor.
Synthetic input
aws_access_key_id=AKIAABCDEFGHIJKLMNOP
aws_secret_access_key=abcdEFGHijkl1234abcdEFGHijkl1234abcdEFGHExpected classification
aws_access_key_id → Medium
aws_secret_access_key → High
both matched spans → RedactedThe access-key ID is an identifier and is not independently exploitable, so the test expects Medium. The paired secret is High. This distinction prevents a bare identifier from being represented as equivalent to an usable credential.
Why the familiar AWS documentation key is not used as the positive case
AWS's well-known AKIAIOSFODNN7EXAMPLE documentation identifier is explicitly expected to produce no finding. The positive fixture above is constructed for the test suite and was not issued by AWS.
Slack webhook embedded in a link
The credential is not safe merely because it is hidden behind anchor text.
Confluence storage input
<a href="https://hooks.slack.com/services/
T00000000/B00000000/XXXXXXXXXXXXXXXXXXXXXXXX">
Incoming webhook
</a>Expected safety action
Type: slack_webhook
Severity: High
href: replaced with #
visible credential occurrence: redactedThe Confluence renderer first neutralizes a credential-bearing href orsrc, then redacts remaining visible occurrences. This avoids leaving a live secret URL in markup after the visible text has been cleaned.
A placeholder must remain untouched
A useful scanner needs negative tests, not only impressive positive examples.
Input
token=changemeExpected result
Findings: 0
Content mutation: none
Jira incident: noneThis fixture exercises placeholder filtering for a generic assignment. It does not mean every string containing “example” is globally ignored: provider rules have their own documented behavior, and administrators can maintain installation-specific ignored values.
Already-redacted content stays unchanged
Repeated content events must converge instead of nesting redaction markers.
Input from a previous scan
[REDACTED by Secret Sentinel:
aws_access_key_id, AKIA****MNOP]Expected second scan
Output: byte-for-byte unchanged
New findings: 0
Nested marker: noneHow these demonstrations were selected
The results are transcribed from automated fixtures and unit-level behavior in the private Secret Sentinel codebase, reviewed on 2 August 2026. The public page contains inputs and expected outputs only—not production patterns or executable detection logic. For the rule composition, severity model, and known limitations, read theopen methodology andTrust Center.
A walkthrough can establish expected behavior, but only an installed sandbox evaluation can exercise Atlassian events, permissions, configuration, and incident routing together.
Run the real acceptance test in your Atlassian sandbox
Install the relevant app, copy the same synthetic fixtures, and compare the result with this page. Do not use a live or previously active credential.