Kingfisher Secret Scanner for Python
Fast secret detection, credential validation and revocation for Python, powered by Kingfisher's Rust libraries. Native, in-process execution; no CLI subprocess required. Requires CPython 3.10+.
Install
uv add kingfisher-secret-scanner
The PyPI distribution is kingfisher-secret-scanner; the Python import is
kingfisher_sdk. It coexists with the separately distributed kingfisher-bin CLI.
Scan offline
from kingfisher_sdk import Scanner
scanner = Scanner() # Compile the bundled rules once and reuse the scanner.
for finding in scanner.scan_file("application.conf"):
if finding.visible:
print(finding.to_dict()) # Secrets and captures are redacted by default.
Validate explicitly
from kingfisher_sdk import Scanner, Validator
findings = Scanner().scan_file("application.conf")
for result in Validator(timeout=10, concurrency=4).validate(findings):
if result.finding.visible:
print(result.to_dict())
Scanning is offline. Validation may contact providers using detected credentials.
Keep the complete scan result, including invisible supporting findings, until
validation finishes. Report redacted results; do not log finding.secret.
Revocation is available through Revoker.revoke() and requires confirm=True.
It can disable or delete real credentials. The
local lifecycle example
demonstrates detection, validation and revocation against a loopback mock with a
synthetic credential. Blocking SDK operations release the GIL; use
asyncio.to_thread in async applications.
Documentation and examples
- Python guide on GitHub:
API reference, custom YAML/TOML rules, validation outcomes, revocation, local
uvbuilds and tests, supported platforms, and publishing. - Runnable Python examples: offline scans, live validation, explicit revocation and a safe local lifecycle.
- Kingfisher repository: source, project documentation, CLI features and contributions.
- Report an issue.
For a source checkout, build and run the local example from the repository root:
uv sync --locked --no-install-project
uv run --no-sync maturin develop --locked --profile dev
uv run --no-sync python python/examples/local_workflow.py
For a downloaded example and a published package, use:
uv run --no-project --with kingfisher-secret-scanner python local_workflow.py
Download demo.yml beside local_workflow.py; the example loads that synthetic
rule by its location. Source archives include the examples and fixture together.
Metadata
Release files for kingfisher-secret-scanner 1.0.1
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| kingfisher_secret_scanner-1.0.1.tar.gz | 1.3 MB | Details |
Built distributions (wheels)
| File | Reset | |||
|---|---|---|---|---|
| kingfisher_secret_scanner-1.0.1-cp310-abi3-win_arm64.whl | CPython 3.10 | abi3 | Windows ARM64 | Details |
| kingfisher_secret_scanner-1.0.1-cp310-abi3-win_amd64.whl | CPython 3.10 | abi3 | Windows x86-64 | Details |
| kingfisher_secret_scanner-1.0.1-cp310-abi3-manylinux_2_28_x86_64.whl | CPython 3.10 | abi3 | Linux glibc 2.28+ x86-64 | Details |
| kingfisher_secret_scanner-1.0.1-cp310-abi3-manylinux_2_28_aarch64.whl | CPython 3.10 | abi3 | Linux glibc 2.28+ ARM64 | Details |
| kingfisher_secret_scanner-1.0.1-cp310-abi3-macosx_11_0_x86_64.whl | CPython 3.10 | abi3 | macOS 11.0+ x86-64 | Details |
| kingfisher_secret_scanner-1.0.1-cp310-abi3-macosx_11_0_arm64.whl | CPython 3.10 | abi3 | macOS 11.0+ ARM64 | Details |
Total release size: 75.9 MB
Release files / kingfisher_secret_scanner-1.0.1.tar.gz
| Download URL | kingfisher_secret_scanner-1.0.1.tar.gz |
|---|---|
| Size | 1.3 MB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
3ca52c6a5cc5e8edd876fcc88b0f24cb0d86bf2bfb6abbfc3fd76c0bde1668a9
|
|
BLAKE2b-256 checksum How to use checksums |
9871145aa1e6985b0b3d68a7460842bd8154d4e6c1be27e199cf0ead2f0af3ea
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Oct 2, 2026.
Transparency logRelease files / kingfisher_secret_scanner-1.0.1-cp310-abi3-win_arm64.whl
| Download URL | kingfisher_secret_scanner-1.0.1-cp310-abi3-win_arm64.whl |
|---|---|
| Size | 10.1 MB |
| Tags | CPython 3.10 Windows ARM64 abi3 |
|
SHA-256 checksum How to use checksums |
f0b0ee0fc95ef568719298b145d17c75bdde0f1c01928d4e5f0c7e191ded1f1e
|
|
BLAKE2b-256 checksum How to use checksums |
f2ec982e8281d24c07f5f6c902d52d3ce8720886d594b744bfa78abf5bf820f0
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Oct 2, 2026.
Transparency logRelease files / kingfisher_secret_scanner-1.0.1-cp310-abi3-win_amd64.whl
| Download URL | kingfisher_secret_scanner-1.0.1-cp310-abi3-win_amd64.whl |
|---|---|
| Size | 21.2 MB |
| Tags | CPython 3.10 Windows x86-64 abi3 |
|
SHA-256 checksum How to use checksums |
d548d4ae7a1cfdb125c45cb83fa1c93ab4ad4fbdab8ca726e88ee70cff6e8f3c
|
|
BLAKE2b-256 checksum How to use checksums |
ae09cfd6bbc9b54fca60c8f1544b91fffb44ba271713941d4953641c8c9bd220
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Oct 2, 2026.
Transparency logRelease files / kingfisher_secret_scanner-1.0.1-cp310-abi3-manylinux_2_28_x86_64.whl
| Download URL | kingfisher_secret_scanner-1.0.1-cp310-abi3-manylinux_2_28_x86_64.whl |
|---|---|
| Size | 11.2 MB |
| Tags | CPython 3.10 Linux glibc 2.28+ x86-64 abi3 |
|
SHA-256 checksum How to use checksums |
84487f70e291b28cc567603687a5d9ee3b1d273245cc79af41b27114708efa72
|
|
BLAKE2b-256 checksum How to use checksums |
851c2d48120a17f3818b54597bcfd77e4cb67f332f2542a6be46fe5000dd5fe0
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Oct 2, 2026.
Transparency logRelease files / kingfisher_secret_scanner-1.0.1-cp310-abi3-manylinux_2_28_aarch64.whl
| Download URL | kingfisher_secret_scanner-1.0.1-cp310-abi3-manylinux_2_28_aarch64.whl |
|---|---|
| Size | 10.8 MB |
| Tags | CPython 3.10 Linux glibc 2.28+ ARM64 abi3 |
|
SHA-256 checksum How to use checksums |
e980fd0796c236ebec39d8c412e5ac5d4d6b9cda20ce6696b1764968a5e91a10
|
|
BLAKE2b-256 checksum How to use checksums |
1256c10a39ddc5eae8b24cfe759051c5cba44ae2a8f1e0b1949edda9a6a07343
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Oct 2, 2026.
Transparency logRelease files / kingfisher_secret_scanner-1.0.1-cp310-abi3-macosx_11_0_x86_64.whl
| Download URL | kingfisher_secret_scanner-1.0.1-cp310-abi3-macosx_11_0_x86_64.whl |
|---|---|
| Size | 10.8 MB |
| Tags | CPython 3.10 abi3 macOS 11.0+ x86-64 |
|
SHA-256 checksum How to use checksums |
f8e31865239d01fa2ad2e2bd71303a8d8eeb093dd47b4f330409fcfcc7c65697
|
|
BLAKE2b-256 checksum How to use checksums |
674db10320d418755deacfa29565f3766c848f3bf1bba3f233d93a38a28501ad
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Oct 2, 2026.
Transparency logRelease files / kingfisher_secret_scanner-1.0.1-cp310-abi3-macosx_11_0_arm64.whl
| Download URL | kingfisher_secret_scanner-1.0.1-cp310-abi3-macosx_11_0_arm64.whl |
|---|---|
| Size | 10.5 MB |
| Tags | CPython 3.10 abi3 macOS 11.0+ ARM64 |
|
SHA-256 checksum How to use checksums |
f4ee455717293fe8fa03745900527f12aa9cb4f6c7b4ae5b1d4e370d6732ce30
|
|
BLAKE2b-256 checksum How to use checksums |
46b3bf40d15b19e30bdd00402ae0e4b974587931f802305ef275395371631488
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Oct 2, 2026.
Transparency log