Linear (Secrets Scanning)

Scan Linear issues and comments for exposed secrets

The Linear (Secrets Scanning) Integration in the Praetorian Guard Platform (PGP)

The Linear (Secrets Scanning) integration in PGP provides continuous scanning of your organization's Linear workspace to detect exposed secrets such as API keys, tokens, passwords, and other sensitive information. PGP connects to Linear using a personal API key, discovers the issues in your workspace, and scans each issue's title, description, and comments for security risks. On subsequent scans, PGP performs incremental checks — only re-scanning content that has changed since the last run.

Note: This is the secret-scanning Linear integration. It is separate from the Linear integration used for issue/ticket notifications and ITSM sync — connecting one does not affect the other.

Prerequisites

Before you begin, ensure you have:

  • A Linear account with access to the target workspace
  • Access to your PGP account

Creating an API Key in Linear

  1. Sign in to Linear and go to SettingsSecurity & accessPersonal API keys
  2. Click New API key
  3. Give the key a descriptive label (e.g., "PGP Integration") and create it
  4. Copy the key immediately — it begins with lin_api_ and will not be shown again

Note: The key inherits the permissions of the account that created it. Use an account with read access to the issues you want scanned.

Configuring the Integration in PGP

  1. In PGP, navigate to the Integrations page
  2. Find and click on Linear (Secrets Scanning) under the "SaaS Security" section
  3. Provide the following details:
    • Workspace — Your Linear workspace URL key or ID
    • API Key — The personal API key you created (lin_api_…)
  4. Click Connect to establish the integration

Once configured, PGP will discover the issues in your workspace and scan their content for exposed secrets.

Verifying the Connection

To verify that your connection is working:

  1. Navigate to Assets in PGP
  2. Look for linear:issue assets — each discovered issue appears as an asset named after its issue identifier (e.g., ENG-123)
  3. Check the Integrations page to confirm the Linear connection status

Remediating Exposed Secrets

To fully eliminate an exposure surfaced in Linear:

  1. Remove the secret from the issue title, description, or comment where it appears
  2. Rotate the affected credential to invalidate any copies that may have already been captured

Because issue content and comments are visible to everyone with access to the issue's team — and Linear keeps a record of description and comment edits in the issue's activity history — treat any surfaced secret as compromised until it has been rotated.

Troubleshooting

Common issues and solutions:

  • Unable to Connect — Verify the API key is correct and begins with lin_api_
  • Authentication Errors — Confirm the key has not been revoked in Settings → Security & access
  • Workspace Mismatch — Ensure the Workspace value matches the workspace URL key or ID the key belongs to
  • No Issues Discovered — Confirm the account has read access to the target teams/issues

If you continue to experience issues, contact PGP Support.

Managing Your Connection

To manage your Linear connection:

  1. In PGP, navigate to the Integrations page
  2. Find your Linear (Secrets Scanning) connection
  3. Use the options menu (⋮) to update the stored credential (Refresh Token) or remove the connection (Disconnect)

Additional Resources

Need help? Contact our support team for assistance.