> ## Documentation Index
> Fetch the complete documentation index at: https://infisical.com/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Secret value search

> Find every project, environment, and path where a secret value is stored.

Secret value search finds every secret in your organization whose value exactly matches a value you enter, and shows the project, environment, and path of each match. It searches every [Secrets Management project](/docs/documentation/platform/secrets-mgmt/project) in the organization, including projects you aren't a member of. Infisical finds matches by comparing hashes of secret values, so it never stores or searches plain text values (see [how values are compared](#how-values-are-compared)).

Use it when a credential leaks. Paste the leaked value to see every place it's stored, so you can rotate or replace each copy instead of only the one you knew about.

## Prerequisites

* A plan that includes [Secret Insights](/docs/documentation/platform/insights), which secret value search is part of (on Infisical Cloud, the Pro and Enterprise plans)
* An organization role with the **Search All Secret Values** permission under **Secrets Management Insights**, such as the built-in **Admin** role (to grant it to another role, see [organization role-based access controls](/docs/documentation/platform/access-controls/role-based-access-controls#organization-level-access-controls))

## Search for a secret value

<Note>
  Secret value search is on by default. If your organization was created before it was released, someone with the permission needs to select **Enable** in the search panel once, and Infisical then indexes the organization's existing secrets.
</Note>

To search for a secret value:

<Steps>
  <Step>
    In your organization, go to **Secrets Management** > **Projects**.
  </Step>

  <Step>
    Select the search box, then select **Locate secrets by value**.

    <img src="https://mintlify.s3.us-west-1.amazonaws.com/infisical/images/platform/secret-value-search/open-search.png" alt="Locate secrets by value option" />
  </Step>

  <Step>
    Paste the full secret value, then press `Enter` or select **Search**. The search doesn't run as you type.

    The value stays masked while you type. To check what you pasted, select the eye icon beside the box. To add a line break to a multi-line value, press `Shift+Enter`.
  </Step>

  <Step>
    Review the matches. Each row shows the **Project**, **Secret Key**, **Environment**, and **Path** of a secret that holds the value.

    To open a match, hover over its row and select the arrow icon. The project's secrets overview opens at that path, filtered to that environment and secret key.

    If you aren't a member of the match's project, the arrow icon is disabled.

    <img src="https://mintlify.s3.us-west-1.amazonaws.com/infisical/images/platform/secret-value-search/results.png" alt="Search results" />
  </Step>
</Steps>

Closing the panel clears the value and the results.

## How values are compared

Infisical doesn't search plain text secret values. When a secret is created or changed, Infisical stores a hash of its value (a fixed-length fingerprint that can't be turned back into the value) next to the encrypted secret. When you search, Infisical hashes the value you enter the same way and looks for secrets with the same hash. The value you search for isn't stored.

The hash is keyed with your organization's encryption key, so the hashes stored in the database can't be matched against guessed values without access to that key.

Because Infisical compares hashes, a secret matches only if its value is identical to the value you enter:

* Part of a value doesn't match (searching `sk_live_abc` doesn't find `sk_live_abc123`)
* A value that differs in case or whitespace, including a trailing newline, doesn't match
* Only each secret's current value is searched, not its [previous versions](/docs/documentation/platform/secret-versioning)
* [Personal overrides](/docs/documentation/platform/secrets-mgmt/project#personal-overrides) aren't searched
* Secrets in projects or environments that are waiting to be deleted aren't searched

A search returns at most 1,000 matches. If a value has more matches than that, the panel says it's showing the first 1,000.

## Audit logs

Infisical records each search in the organization's [audit logs](/docs/documentation/platform/audit-logs) as a **Search Secrets by Value** event, with the number of matches. The event doesn't include the value you searched for.

## Next steps

<CardGroup cols={2}>
  <Card title="Insights" icon="chart-line" href="/docs/documentation/platform/insights">
    Find secrets that share a value across projects.
  </Card>

  <Card title="Secret rotation" icon="rotate" href="/docs/documentation/platform/secret-rotation/overview">
    Rotate a credential automatically on a schedule.
  </Card>
</CardGroup>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.