Confluence
Confluence
Edition: Enterprise only
The Confluence integration scans pages, attachments, and comments in Atlassian Confluence for credentials and other sensitive data.
Configuration
The Confluence integration can be configured in TruffleHog under Integrations, or via a local configuration file (below). Setup requires the ability to create a token in your Confluence instance.
Web configuration
Configure this integration from the Integrations page in TruffleHog. You'll need credentials appropriate to your Confluence deployment — see the local configuration section below for the supported authentication methods.
Local configuration
Local configuration supports two authentication methods, depending on your Confluence deployment:
- Basic authentication — supported by both Confluence Cloud and Confluence Data Center / Server.
- Bearer token — supported by Confluence Data Center / Server only.
Confluence Cloud (basic auth)
Use this for Confluence Cloud. The username must be the email address attached to your Atlassian account, and the password must be a Confluence Cloud API token. The endpoint for Cloud must contain atlassian.net.
Spaces are enumerated automatically unless spaces is set to a specific list. Use ignoreSpaces to skip specific spaces. The spacesScope field controls which space types are scanned (ALL, GLOBAL, or PERSONAL); it defaults to ALL.
You can find all available Space Names in your Atlassian account under Confluence home > Spaces > View all spaces.
Confluence Data Center / Server (basic auth)
Use this for on-premises Confluence with username and password authentication. The endpoint for Data Center / Server cannot contain atlassian.net.
The spaces and ignoreSpaces keys expect Space Names — note that Space Name differs from Space Key.
Confluence Data Center / Server (bearer token)
Use this for on-premises Confluence with a personal access token (PAT).
Configuration options
Field | Type | Required | Description |
|---|---|---|---|
endpoint | string | Yes | The target Confluence endpoint URI. Must contain atlassian.net for Cloud; cannot contain it for Data Center / Server. |
spaces | list | No | Explicit list of Space Names to scan. Omit to enumerate instead. |
ignoreSpaces | list | No | Space Names to skip during scanning. |
spacesScope | string | No | Which space types to scan: ALL, GLOBAL, or PERSONAL. Defaults to ALL. When combined with the spaces list, both must use the same scope unless spacesScope is ALL. |
includeAttachments | boolean | No | Include attachments during scanning. |
skipHistory | boolean | No | Skip retrieval of historical page versions. |
insecureSkipVerifyTls | boolean | No | Skip TLS/SSL verification. Setting this to true may pose security issues. |
Capabilities
Feature | Supported |
|---|---|
Scan pages | ✅ |
Scan attachments | ✅ |
Scan comments | ✅ |
Scan archive files | ✅ |
Scan base64-encoded data | ✅ |
Scan binaries | ✅ |
Scan version history | ✅ |
Include / exclude filters | ✅ |
Auto-resume | ✅ |
Notes
- Attachment scanning is opt-in. Set includeAttachments: true to scan attachments.
- Version history scanning is opt-out. Set skipHistory: true to skip historical page versions.