Notion
Scan Notion pages for exposed secrets
The Notion Integration in the Praetorian Guard Platform (PGP)
The Notion integration in PGP provides continuous scanning of your organization's Notion workspace to detect exposed secrets such as API keys, tokens, passwords, and other sensitive information. PGP connects to Notion using an internal integration token, discovers the pages the integration can access — including pages inside databases — and scans their content for security risks. On subsequent scans, PGP performs incremental checks — only re-scanning content that has changed since the last run.
Prerequisites
Before you begin, ensure you have:
- A Notion workspace
- Permission to create an internal integration in that workspace (workspace owner or admin)
- Access to your PGP account
Creating an Integration Token in Notion
- Sign in to Notion and go to My integrations
- Click New integration
- Give it a descriptive name (e.g., "PGP Integration"), select the associated workspace, and set the capabilities to Read content
- Click Save, then copy the Internal Integration Secret — it begins with
secret_orntn_ - Share the pages and databases you want scanned with the integration: open a page, click the ••• menu → Connections → Add connections, and select your integration. Sharing a parent page grants access to its child pages.
Note: Notion only exposes content that has been explicitly shared with the integration. Pages that are never connected to the integration cannot be scanned.
Configuring the Integration in PGP
- In PGP, navigate to the Integrations page
- Find and click on Notion under the "SaaS Security" section
- Provide the following details:
- Workspace — Your Notion workspace name or ID
- Integration Token — The Internal Integration Secret you created (
secret_…orntn_…)
- Click Connect to establish the integration
Once configured, PGP will discover all accessible Notion pages and scan their content for exposed secrets.
Verifying the Connection
To verify that your connection is working:
- Navigate to Assets in PGP
- Look for
notion:pageassets — each page the integration can access appears as an asset named after its page title - Check the Integrations page to confirm the Notion connection status
Remediating Exposed Secrets
Notion retains page history, so a secret that appears in a page may also exist in earlier versions of that page. Removing the secret from the current content does not guarantee it is gone from prior versions.
To fully eliminate the exposure:
- Remove the secret from the current version of the page
- Notion does not support deleting individual page versions — if the page history still contains the secret, duplicate the page (the copy carries no history) and delete the original
- Rotate the affected credential to invalidate any copies that may have already been captured
Until the secret is removed from all accessible content, it should be treated as compromised.
Troubleshooting
Common issues and solutions:
- Unable to Connect — Verify the integration token is correct and begins with
secret_orntn_ - Authentication Errors — Confirm the integration has not been revoked in My integrations
- No Pages Discovered — The integration only sees content shared with it. Connect the target pages/databases to the integration (page ••• → Connections)
- Workspace Mismatch — Ensure the Workspace value matches the workspace the token was created in
If you continue to experience issues, contact PGP Support.
Managing Your Connection
To manage your Notion connection:
- In PGP, navigate to the Integrations page
- Find your Notion connection
- Use the options menu (⋮) to update the stored credential (Refresh Token) or remove the connection (Disconnect)
Additional Resources
Need help? Contact our support team for assistance.