redact-secret · Report · Detector
anthropic-api01-key
Format evidence
- Provider documentation Key type table: Compliance Access Key (sk-ant-api01-...) · observed 2026-09-26 · the provider documents sk-ant-api01- as the prefix of a Claude Enterprise key and quotes "sk-ant-api01- is a Compliance Access Key"; it states no body length, alphabet or tail
- Reference 1
- Reference 2
- Reference 3
- Reference 4
Arrival evidence (#384, product redact-secret#862; research #776). T1 on the prefix only: two provider pages document sk-ant-api01- (compliance-api-access, admin-api-keys). The body is undocumented and no scanner rule exists for this prefix, so nothing here asserts a length, alphabet or AA tail: positives borrow the api03 93-character + AA shape, which the product accepts as a subset of its >= 20 byte run, and no twin is authored on the body. The prefix is the general Claude Enterprise organization key for any scope set; "Compliance" describes the scopes chosen at creation, which the value does not show, so a finding must not claim it. sk-ant-api03- and sk-ant-admin01- are different provider classes and back prefix twins.
What the run recorded, by group
| Group | Fixtures | Leaked or false alarms | Near-twins | Outcomes | Other scanners, same cell |
|---|---|---|---|---|---|
| Must not flag · Provider-documented | 4 | False alarmsinsufficient-evidence0 of 4 controls flagged | 4 quiet · 0 flagged |
| |
| Must not flag · Project policy | 18 | False alarmsat most 17.6%0 of 18 controls flagged | 18 quiet · 0 flagged |
| |
| Must redact · Provider-documented | 15 | Secret spans left readableat most 20.4%0 of 15 spans | Near-twins told apartinsufficient-coverage7 of 7 pairs | 15 redacted · 0 too much · 0 partly exposed · 0 missed |
|
- Fixtures
- 37
- Left readable
- 0
- Redacted too much
- 0
- False alarms
- 0
Fixtures for this detector
| Fixture | Kind and evidence | redact-secret |
|---|---|---|
anthropic-api01-key-admin01-prefix-twinanthropic · prefix-near-miss | Must not flagT1 · Provider-documented · twin | Quiet |
anthropic-api01-key-apl-letter-twinanthropic · prefix-near-miss | Must not flagT3 · Project policy · twin | Quiet |
anthropic-api01-key-buildkite-envanthropic · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
anthropic-api01-key-compliance-export-yamlanthropic · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
anthropic-api01-key-compose-envanthropic · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
anthropic-api01-key-curl-x-api-keyanthropic · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
anthropic-api01-key-dotenvanthropic · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
anthropic-api01-key-exportanthropic · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
anthropic-api01-key-go-const-longanthropic · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
anthropic-api01-key-httpx-clientanthropic · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
anthropic-api01-key-job-loganthropic · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
anthropic-api01-key-json-configanthropic · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
anthropic-api01-key-key-digest-encoded-valueanthropic · benign-encoded-value | Must not flagT3 · Project policy | Quiet |
anthropic-api01-key-pasted-keyanthropic · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
anthropic-api01-key-python-sdkanthropic · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
anthropic-api01-key-secretsmanager-getanthropic · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
anthropic-api01-key-ticket-parenanthropic · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
anthropic-api01-key-tool-callanthropic · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
anthropic-api01-key-underscore-delimiters-twinanthropic · boundary-violation | Must not flagT3 · Project policy · twin | Quiet |
anthropic-api01-key-actions-secret-referenceanthropic · templated-reference | Must not flagT3 · Project policy | Quiet |
anthropic-api01-key-activity-feed-public-idanthropic · public-identifier | Must not flagT3 · Project policy | Quiet |
anthropic-api01-key-activity-ids-public-idanthropic · public-identifier | Must not flagT3 · Project policy | Quiet |
anthropic-api01-key-allowlist-comment-near-missanthropic · format-near-miss | Must not flagT1 · Provider-documented | Quiet |
anthropic-api01-key-angle-key-placeholderanthropic · documentation-placeholder | Must not flagT3 · Project policy | Quiet |
anthropic-api01-key-api03-prefix-twinanthropic · prefix-near-miss | Must not flagT1 · Provider-documented · twin | Quiet |
anthropic-api01-key-body-only-twinanthropic · prefix-near-miss | Must not flagT3 · Project policy · twin | Quiet |
anthropic-api01-key-docs-ellipsis-placeholderanthropic · documentation-placeholder | Must not flagT3 · Project policy | Quiet |
anthropic-api01-key-embedded-leading-twinanthropic · boundary-violation | Must not flagT3 · Project policy · twin | Quiet |
anthropic-api01-key-env-reference-referenceanthropic · templated-reference | Must not flagT3 · Project policy | Quiet |
anthropic-api01-key-fingerprint-table-encoded-valueanthropic · benign-encoded-value | Must not flagT3 · Project policy | Quiet |
anthropic-api01-key-masked-display-placeholderanthropic · documentation-placeholder | Must not flagT3 · Project policy | Quiet |
anthropic-api01-key-prefix-guidance-proseanthropic · prose-mention | Must not flagT3 · Project policy | Quiet |
anthropic-api01-key-prefix-only-near-missanthropic · format-near-miss | Must not flagT1 · Provider-documented | Quiet |
anthropic-api01-key-procurement-note-proseanthropic · prose-mention | Must not flagT3 · Project policy | Quiet |
anthropic-api01-key-uppercase-prefix-twinanthropic · prefix-near-miss | Must not flagT3 · Project policy · twin | Quiet |
anthropic-api01-key-vault-path-referenceanthropic · templated-reference | Must not flagT3 · Project policy | Quiet |
anthropic-api01-key-version-and-org-public-idanthropic · public-identifier | Must not flagT3 · Project policy | Quiet |