Skip to content
Benchmarks

EVALUATION METHOD

Twin

Each case is an authored pair: a value that should be redacted, and the same text with one authored change that makes it not a secret. A scanner has to treat the two sides differently.

  • Run 6183a594 · 2026-10-10
  • redact-secret 0.1.0-beta.14 · Published npm package · default detectors
  • Accounting v1.1

1 · How it runs

Does the scanner tell a secret from its harmless twin?

  1. InputAn authored pair: a positive text and its negative twin.
  2. ChangeOne authored change turns the secret into something that is not one.
  3. CheckThe positive side is detected within its expected envelope, the twin is left alone, and the pair flips between the two.
Pairs
1,528
Texts
3,056
Suites
66

2 · Recorded now

Do the pairs come apart?

One row for the pair and one for each side, per scanner.
Twin: checks that did not hold, per scanner
Checkredact-secret0.1.0-beta.14gitleaks8.30.1trufflehog3.97.4flare-redact1.6.1
Pair told apartThe positive is detected and its twin is left alone2 of 1,472559 of 1,472976 of 1,4721,140 of 1,472
Positive sideDetected within its expected envelope2 of 1,525479 of 1,525946 of 1,5251,135 of 1,525
Negative twinLeft alone0 of 1,47298 of 1,47266 of 1,47253 of 1,472

Checks that did not hold, of those scored for that scanner.

A count opens the checks behind it: the ones that did not hold, from this run only. "Needs review" opens the checks that wait for a person. A zero has none to open, and a scanner that did not run has none to list.

Needs review

56 pairs have a side whose expected outcome is unresolved (tier T0). They are counted in no row above.

3 · How to read it

Reading twin

  • The first row is the pair as a whole. The next two are its sides, so a pair that was not told apart shows up in at least one of them.
  • A pair with a side whose expected outcome is unresolved (tier T0) is counted apart and in none of these rows.

4 · Exact inputs

Where the cases come from

1,528 pairs read by this method. Synthetic content only.

Suites

Every case comes from a published suite. Open a suite to read its fixtures.

Show the 66 suites
Suites the cases come from
SuitePairs
Reviewed credential formatscommon-formats92
GitHub token contextstoken-contexts4
Credential formatscredential-formats15
Context & boundariescontext-edges57
SendGrid regressionssendgrid-regressions11
Detector coveragedetector-coverage234
Beta.8 low-coverage hardening (#207)beta8-20799
Beta.8 documented-stable hardening (#209)beta8-20920
Beta.8 AI inference arrival evidence (#208)beta8-20824
Beta.8 · LangSmith and Langfuse arrival evidencebeta8-21010
Beta.8 developer credential arrival evidence (#211)beta8-21126
Beta.8 second-wave arrival evidence (#212)beta8-21239
Beta.8 empirical-route fixture debt (#213, 213d)beta8-213d9
Beta.8 context-twin debt for the legacy Datadog application key (#213, 213e)beta8-213e8
Beta.8 replacement fixtures for provider-undecided properties (#213, 213f)beta8-213f11
Beta.8 evidence for Travis CI, Neon, Postman collection access keys and the Mailgun key triplet (#259)beta8-25929
Beta.8 empirical fixture-floor raise for ten T2 families (#263)beta8-26331
Beta.10 evidence for the Anthropic api01/admin01 prefixes and the OpenAI admin key (#384, slice a)beta8-384a21
Beta.10 evidence for the Amazon Bedrock long-term and short-term API keys (#384, slice b)beta8-384b12
Beta.10 evidence for the ElevenLabs API key (#384, slice c)beta8-384c10
Beta.10 evidence for the Together AI and Tavily API keys (#384, slice d)beta8-384d16
Beta.10 evidence for keyword-gated Mistral, Cohere, Deepgram, AI21 and Exa keys (#384, slice e)beta8-384e64
Beta.11 independent family evidence for fifteen selected credential families (#379)beta8-37938
Beta.11 evidence for Convex deployment and admin keys with a hex body (#436, slice a)beta8-436a10
Beta.11 evidence for the 1Password service-account token (#436, slice b)beta8-436b9
Beta.11 evidence for the Inngest signing key (#436, slice c)beta8-436c9
Beta.11 evidence for the Resend API key (#436, slice d)beta8-436d11
Beta.11 evidence for the Apify API token (#436, slice e)beta8-436e7
Beta.11 evidence for the Weights & Biases wandb_v1_ API key (#436, slice f)beta8-436f6
Beta.11 evidence for Doppler tokens (#434, slice a)beta8-434a88
Beta.11 evidence for the Trigger.dev secret key and PAT (#434, slice b)beta8-434b24
Beta.11 evidence for the E2B API key (#434, slice c)beta8-434c11
Beta.11 evidence for the PostHog personal and project secret API keys (#434, slice d)beta8-434d22
Beta.11 evidence for the Helicone read-write and write-only keys (#434, slice e)beta8-434e28
Beta.11 evidence for the Firecrawl API key (#434, slice f)beta8-434f14
Beta.11 evidence for the Composio project, org and user API keys (#434, slice g)beta8-434g34
Beta.12 evidence for the Daytona API key (#464, slice a)beta8-464a10
Beta.12 evidence for the ClickHouse Cloud API key secret (#464, slice b)beta8-464b10
Beta.12 evidence for the NVIDIA API key (#464, slice c)beta8-464c6
Beta.12 evidence for the Browserbase API key (bb_live_) (#464, slice d)beta8-464d7
Beta.12 evidence for the Cerebras inference API key (#464, slice e)beta8-464e8
Beta.12 evidence for the RunPod API key (#464, slice f)beta8-464f7
Beta.12 evidence for the Bitwarden Secrets Manager access token (#528, slice a)beta8-528a14
Beta.12 evidence for Polar organization access tokens and API credentials (#528, slice b)beta8-528b15
Beta.12 evidence for SonarQube user and analysis tokens (#528, slice c)beta8-528c16
Beta.12 evidence for the RubyGems.org API key (#528, slice d)beta8-528d9
Beta.12 evidence for the Clojars deploy token (#528, slice e)beta8-528e8
Beta.12 evidence for crates.io API and trusted-publishing tokens (#528, slice f)beta8-528f15
Beta.12 evidence for Dynatrace access and platform tokens (#528, slice g)beta8-528g11
Beta.12 evidence for the Paddle Billing API key (#528, slice h)beta8-528h12
Beta.12 evidence for Honeycomb ingest keys (#528, slice i)beta8-528i9
Beta.12 evidence for Axiom API and personal tokens (#528, slice j)beta8-528j14
Beta.12 evidence for the AWS IAM user secret access key (#528, #1012 slice a)beta8-1012a17
Beta.12 evidence for the Google OAuth client secret (#528, #1012 slice b)beta8-1012b8
Beta.12 evidence for the routable GitLab personal access token (#528, #1012 slice c)beta8-1012c8
Beta.12 evidence for the AWS STS temporary access key id (#528, #1012 slice d)beta8-1012d6
Beta.12 evidence for Vercel personal, app access and app refresh tokens (#528, #1012 slice e)beta8-1012e24
Beta.14 evidence for the Square access token and OAuth application secret (#583, slice a)beta8-583a25
Beta.14 evidence for the Xata API key (#583, slice b)beta8-583b13
Beta.14 evidence for the Sourcegraph access token (#583, slice c)beta8-583c13
Beta.14 evidence for the Unkey root key (#583, slice d)beta8-583d24
Beta.14 evidence for the Buildkite token (#583, slice e)beta8-583e17
Beta.14 evidence for the Pydantic Logfire token (#583, slice f)beta8-583f20
Beta.14 evidence for the Mapbox secret access token (#583, slice g)beta8-583g13
Beta.14 evidence for the Fly.io access token (#583, slice h)beta8-583h12
Public policy qualification controls for bounded T3 credentials (#365)policy-qualified-credentials4