redact-secret · Report · Detector
Apify API tokens
Format evidence
- Provider documentation apify/awesome-skills lint_references.py TOKEN_RE = apify_api_[A-Za-z0-9]{20,} (added in 4ba9177 by an Apify collaborator, 2026-08-12; ruling R2) and the apify_api_... docs placeholders (ruling R4) · observed 2026-09-28 · apify_api_ + at least 20 alphanumerics, open-ended; no separator or checksum
- trufflehog 3.97.4
- Reference 1
- Reference 2
- Reference 3
- Reference 4
- Reference 5
- Reference 6
- Reference 7
- Reference 8
- Reference 9
- Reference 10
- Reference 11
Arrival evidence (#436, product redact-secret#916; #860 handoff apify.md, READY with an open-ended body). T1: the prefix is the provider's docs placeholder apify_api_... (R4), and the alphabet and the 20-byte floor are the provider-authored leak linter TOKEN_RE = apify_api_[A-Za-z0-9]{20,} (R2; the handoff checked the author and that it matches no public scanner rule). No provider source states an exact width: trufflehog's exact 36 is T2, and the product's 128-byte cap is streaming policy, so positives carry 20, 36 and 128 and nothing asserts silence on a longer run. Excluded: apify_ui_ Console tokens (prefix T1 under R6 but no shape), Actor-run, integration and webhook-dispatch tokens (no public shape), the unprefixed proxy password, placeholders whose _ or . breaks the run below 20, and APIFY_API_ identifiers (the prefix is case-sensitive). Graduated to a registry detector at the 1127bf9 re-pin (redact-secret PR #938).
What the run recorded, by group
| Group | Fixtures | Leaked or false alarms | Near-twins | Outcomes | Other scanners, same cell |
|---|---|---|---|---|---|
| Must not flag · Tool-corroborated | 13 | False alarmsat most 22.8%0 of 13 controls flagged | 13 quiet · 0 flagged |
| |
| Must not flag · Project policy | 9 | False alarmsat most 29.9%0 of 9 controls flagged | 9 quiet · 0 flagged |
| |
| Must redact · Provider-documented | 16 | Secret spans left readableat most 19.4%0 of 16 spans | Near-twins told apartinsufficient-coverage7 of 7 pairs | 16 redacted · 0 too much · 0 partly exposed · 0 missed |
|
- Fixtures
- 38
- Left readable
- 0
- Redacted too much
- 0
- False alarms
- 0
Fixtures for this detector
| Fixture | Kind and evidence | redact-secret |
|---|---|---|
apify-api-token-bare-proseapify · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
apify-api-token-bearer-headerapify · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
apify-api-token-chat-pasteapify · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
apify-api-token-curl-bearerapify · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
apify-api-token-dotenvapify · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
apify-api-token-exportapify · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
apify-api-token-js-clientapify · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
apify-api-token-json-api-keyapify · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
apify-api-token-json-tokenapify · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
apify-api-token-key-shape-bareapify · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
apify-api-token-key-shape-quotedapify · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
apify-api-token-key-shape-unicode-crlfapify · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
apify-api-token-mcp-envapify · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
apify-api-token-python-positionalapify · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
apify-api-token-sdk-kwargapify · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
apify-api-token-trailing-hyphen-twinapify · boundary-violation | Must not flagT2 · Tool-corroborated · twin | Quiet |
apify-api-token-x-api-key-headerapify · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
apify-api-token-actions-secret-referenceapify · templated-reference | Must not flagT3 · Project policy | Quiet |
apify-api-token-body-19-twinapify · wrong-length | Must not flagT2 · Tool-corroborated · twin | Quiet |
apify-api-token-console-token-name-public-idapify · public-identifier | Must not flagT2 · Tool-corroborated | Quiet |
apify-api-token-ellipsis-placeholderapify · documentation-placeholder | Must not flagT3 · Project policy | Quiet |
apify-api-token-env-reference-referenceapify · templated-reference | Must not flagT3 · Project policy | Quiet |
apify-api-token-hyphen-prefix-twinapify · boundary-violation | Must not flagT2 · Tool-corroborated · twin | Quiet |
apify-api-token-identifiers-public-idapify · public-identifier | Must not flagT2 · Tool-corroborated | Quiet |
apify-api-token-label-proseapify · benign-lookalike | Must not flagT3 · Project policy | Quiet |
apify-api-token-leading-glue-twinapify · boundary-violation | Must not flagT2 · Tool-corroborated · twin | Quiet |
apify-api-token-maskapify · benign-lookalike | Must not flagT3 · Project policy | Quiet |
apify-api-token-prefix-at-eol-near-missapify · format-near-miss | Must not flagT2 · Tool-corroborated | Quiet |
apify-api-token-prefix-onlyapify · benign-lookalike | Must not flagT2 · Tool-corroborated | Quiet |
apify-api-token-referenceapify · benign-lookalike | Must not flagT3 · Project policy | Quiet |
apify-api-token-short-bodyapify · benign-lookalike | Must not flagT2 · Tool-corroborated | Quiet |
apify-api-token-short-body-near-missapify · format-near-miss | Must not flagT2 · Tool-corroborated | Quiet |
apify-api-token-test-names-placeholderapify · documentation-placeholder | Must not flagT3 · Project policy | Quiet |
apify-api-token-token-guidance-proseapify · prose-mention | Must not flagT3 · Project policy | Quiet |
apify-api-token-trailing-underscore-twinapify · boundary-violation | Must not flagT2 · Tool-corroborated · twin | Quiet |
apify-api-token-underscore-in-body-twinapify · wrong-alphabet | Must not flagT2 · Tool-corroborated · twin | Quiet |
apify-api-token-uppercase-prefix-twinapify · prefix-near-miss | Must not flagT2 · Tool-corroborated · twin | Quiet |
apify-api-token-your-token-placeholderapify · documentation-placeholder | Must not flagT3 · Project policy | Quiet |