TokenGuard

A zero-dependency pre-commit scanner for detecting API keys and credentials in staged Git changes.

Accidentally committed secrets are one of the most widespread security incidents, and cleanup after a push is costly and noisy.

Developers need a fast local gate that catches tokens, private keys and high-entropy strings before commit — without sending code anywhere.

TokenGuard scans staged changes with pattern rules plus Shannon entropy analysis, and lets teams suppress accepted test credentials through an explicit baseline file.

Pure Python standard library, zero external dependencies; results are emitted as OASIS SARIF v2.1.0 for GitHub Code Scanning integration.

Every finding carries a severity, masked value preview, entropy score and a concrete remediation action — no vague warnings.

Available on PyPI as tokenguard-cli. It scans staged changes, masks detected values in reports and supports pre-commit hooks and SARIF output. Pattern and entropy checks do not guarantee detection of every secret.

Security tooling gets adopted when it is fast, offline and explains exactly what to do next.