Detects leaked secrets (API keys, tokens, private keys) in source code.
A local secret scanner for source code. Trestle finds API keys, access tokens, passwords, private keys, and certificates before commiting them by mistake, and keeps them from leaving your machine.
This is the Community edition. Open source under Apache-2.0, and a mirror of the version distributed at trestlescan.com.
.gitignore and your own skip rules.A recent stable Rust toolchain is the only prerequisite.
cargo build --release
This builds two binaries: trestle, which does not make network requests, and
trestle-net, which can check whether found secrets are still live.
In any project directory:
trestle install # adds a pre-commit hook and AI instructions
trestle scan # scans the current directory
Other commands:
trestle watch keeps scanning as files change.trestle lsp starts the language server.trestle mcp starts the MCP server.trestle uninstall removes the integration from a project.The default trestle binary does not make network requests. The separate
trestle-net binary adds an optional check that contacts each detected
secret's provider to confirm whether the credential is still valid:
trestle-net scan --validate
Each finding is then labeled (active), (inactive), or (could not verify). This check runs only in trestle-net, so the trestle binary
remains fully offline.
The full documentation is available at trestlescan.com/documentation.
Use the official GitHub Action to scan every push and pull request:
name: Secret scan
on:
push:
pull_request:
jobs:
trestle:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- uses: toro-guapo/trestle-action@v1
See toro-guapo/trestle-action for inputs, outputs, SARIF upload to the GitHub Security tab, and supported runners.
Trestle is open core.
.env, and per-platform
rotation guides for AWS, GitHub Actions, Vercel, Netlify, Kubernetes,
Doppler, and other targets. Distributed under a commercial license.Pro is available at trestlescan.com.
This is a read-only mirror, refreshed on every Community release. Development happens in a private repository.
Issues and discussion are welcome on GitHub. Pull requests are not accepted through this mirror. If you have a fix or an idea, please open an issue.
Apache License 2.0. See LICENSE.
Source-derived launch command. Check the maintainer’s required arguments and credentials before running:
npx -y @trestlescan/mcpMerge this template into ~/Library/Application Support/Claude/claude_desktop_config.json. Keep existing servers. Add any arguments, credentials, and permissions required by the maintainer; this template has not been install-tested.
{
"mcpServers": {
"com-trestlescan-trestle": {
"command": "npx",
"args": [
"-y",
"@trestlescan/mcp"
]
}
}
}Restart Claude Desktop completely for changes to take effect. Confirm the server appears connected in the client’s tool list, then try a read-only example from its documentation.
Claude Desktop setup reference@trestlescan/mcpnpmTrestle works with any MCP-compatible client. Copy the config snippet from the Configuration section above and add it to the file shown for your client, then restart the application.
~/Library/Application Support/Claude/claude_desktop_config.jsonRestart Claude Desktop completely for changes to take effect.~/.cursor/mcp.jsonRestart Cursor for changes to take effect..vscode/mcp.jsonReload VS Code window for changes to take effect.~/.codeium/windsurf/mcp_config.jsonRestart Windsurf for changes to take effect..mcp.jsonSave at the project root, then start Claude Code in that project and review the MCP server approval prompt. Keep real credentials out of shared files.