---
title: "Token and Credential Formats"
description: "What Sentry credentials look like, the strings that appear near them, and the patterns that cause false positives in secret scanning."
url: https://docs.sentry.io/security-legal-pii/security/token-formats/
---

# Token and Credential Formats | Sentry Docs

Use this page to write secret scanning rules, or to identify a credential you found in logs or CI config. For what each token type is for, see [Auth Tokens](https://docs.sentry.io/account/auth-tokens.md).

## [Formats](https://docs.sentry.io/security-legal-pii/security/token-formats.md#formats)

| Format                                                | Credential                                                                                                                                                                                                                                                                                                   |
| ----------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| `sntryu_[a-f0-9]{64}`                                 | Personal auth token                                                                                                                                                                                                                                                                                          |
| `sntrys_[A-Za-z0-9+/=]+_[A-Za-z0-9+/]{43}`            | Organization auth token                                                                                                                                                                                                                                                                                      |
| `sntrya_[a-f0-9]{64}`, `sntryi_[a-f0-9]{64}`          | Reserved prefixes (user app, integration)                                                                                                                                                                                                                                                                    |
| `[a-f0-9]{64}`                                        | Legacy tokens, [internal integration](https://docs.sentry.io/integrations/integration-platform/internal-integration.md) tokens, OAuth client IDs and secrets, OAuth access and refresh tokens, device codes, [webhook](https://docs.sentry.io/integrations/integration-platform/webhooks.md) signing secrets |
| `[a-f0-9]{32}`                                        | Legacy API key                                                                                                                                                                                                                                                                                               |
| `[BCDFGHJKLMNPQRSTVWXZ]{4}-[BCDFGHJKLMNPQRSTVWXZ]{4}` | OAuth device user code                                                                                                                                                                                                                                                                                       |
| `[A-Za-z0-9_-]{43}`                                   | [Relay](https://docs.sentry.io/product/relay/getting-started.md) public or secret key                                                                                                                                                                                                                        |

Organization tokens run about 180 to 250 characters, since the payload contains the org slug. A fixed-length pattern may miss valid tokens.

Nothing issues the `sntrya_` or `sntryi_` prefixes today. They're reserved, so matching them now may cover tokens issued later.

## [Excluding DSNs](https://docs.sentry.io/security-legal-pii/security/token-formats.md#excluding-dsns)

DSNs aren't secrets, so leave them out of secret scanning rules. See [Data Source Name (DSN)](https://docs.sentry.io/concepts/key-terms/dsn-explainer.md).

Sentry SaaS:

```plaintext
https://[a-f0-9]{32}@o\d+\.ingest(\.[a-z]+)?\.sentry\.io/\d+
```

Self-hosted and Relay:

```plaintext
https?://[a-f0-9]{32}@[^/]+/\d+
```

## [Finding Credentials](https://docs.sentry.io/security-legal-pii/security/token-formats.md#finding-credentials)

A prefixed token identifies itself. A bare hex string doesn't, so surrounding context can help determine whether it's a credential.

Sentry's docs and tools use these names next to a 64-character hex string: `SENTRY_AUTH_TOKEN`, `authToken`, `auth.token`, `Authorization: Bearer`, and `client_secret`. A Relay key may appear as `secret_key` or `public_key`, often in `credentials.json`.

Other apps may rename variables, wrap values in their own config, or store tokens with none of these strings nearby, so treat this as a starting point.

## [Matching Caveats](https://docs.sentry.io/security-legal-pii/security/token-formats.md#matching-caveats)

These patterns may match strings that aren't Sentry credentials, and they may not tell two Sentry credentials apart:

* Any SHA-256 digest is 64 hex characters, so checksums, content hashes, cache keys, and image digests all match the unprefixed token pattern.
* The `Sentry-Hook-Signature` webhook header is an HMAC-SHA256 digest of the request body, not the secret that signed it.
* A DSN public key is 32 hex characters, the same as a legacy API key. One inside a URL is likely a DSN.
* A 43-character Base64 string is any 32 random bytes, so a Relay key may only be identifiable from nearby context.
