Skip to content
Benchmarks

redact-secret · Report · Detector

Apify API tokens

  • 38 fixtures
  • Format evidence: T1 · Provider-documented
  • Run 2026-10-07
  • Mode published · redact-secret 0.1.0-beta.14

Format evidence

Arrival evidence (#436, product redact-secret#916; #860 handoff apify.md, READY with an open-ended body). T1: the prefix is the provider's docs placeholder apify_api_... (R4), and the alphabet and the 20-byte floor are the provider-authored leak linter TOKEN_RE = apify_api_[A-Za-z0-9]{20,} (R2; the handoff checked the author and that it matches no public scanner rule). No provider source states an exact width: trufflehog's exact 36 is T2, and the product's 128-byte cap is streaming policy, so positives carry 20, 36 and 128 and nothing asserts silence on a longer run. Excluded: apify_ui_ Console tokens (prefix T1 under R6 but no shape), Actor-run, integration and webhook-dispatch tokens (no public shape), the unprefixed proxy password, placeholders whose _ or . breaks the run below 20, and APIFY_API_ identifiers (the prefix is case-sensitive). Graduated to a registry detector at the 1127bf9 re-pin (redact-secret PR #938).

What the run recorded, by group

Detector views overlap, so their groups are never summed across detectors. Other scanners are reference values on the same inputs, in run order.
Groups of Apify API tokens fixtures
GroupFixturesLeaked or false alarmsNear-twinsOutcomesOther scanners, same cell
Must not flag · Tool-corroborated13False alarmsat most 22.8%0 of 13 controls flagged13 quiet · 0 flagged
  • flare-redact at most 22.8%
  • gitleaks at most 22.8%
  • trufflehog at most 33.3%
Must not flag · Project policy9False alarmsat most 29.9%0 of 9 controls flagged9 quiet · 0 flagged
  • flare-redact at most 29.9%
  • gitleaks at most 29.9%
  • trufflehog at most 29.9%
Must redact · Provider-documented16Secret spans left readableat most 19.4%0 of 16 spansNear-twins told apartinsufficient-coverage7 of 7 pairs16 redacted · 0 too much · 0 partly exposed · 0 missed
  • flare-redact at most 96.5%
  • gitleaks at most 66.8%
  • trufflehog at most 36.0%
38 of 38 rows
Fixtures
38
Left readable
0
Redacted too much
0
False alarms
0

Fixtures for this detector

38 fixtures. Choose "Every scanner" to see each scanner's outcome for the same rows.
Fixtures in Apify API tokens
FixtureKind and evidenceredact-secret
apify-api-token-bare-proseapify · documented-format-literalMust redactT1 · Provider-documentedRedacted
apify-api-token-bearer-headerapify · documented-format-literalMust redactT1 · Provider-documentedRedacted
apify-api-token-chat-pasteapify · documented-format-literalMust redactT1 · Provider-documentedRedacted
apify-api-token-curl-bearerapify · documented-format-literalMust redactT1 · Provider-documentedRedacted
apify-api-token-dotenvapify · documented-format-literalMust redactT1 · Provider-documentedRedacted
apify-api-token-exportapify · documented-format-literalMust redactT1 · Provider-documentedRedacted
apify-api-token-js-clientapify · documented-format-literalMust redactT1 · Provider-documentedRedacted
apify-api-token-json-api-keyapify · documented-format-literalMust redactT1 · Provider-documentedRedacted
apify-api-token-json-tokenapify · documented-format-literalMust redactT1 · Provider-documentedRedacted
apify-api-token-key-shape-bareapify · documented-format-literalMust redactT1 · Provider-documentedRedacted
apify-api-token-key-shape-quotedapify · documented-format-literalMust redactT1 · Provider-documentedRedacted
apify-api-token-key-shape-unicode-crlfapify · documented-format-literalMust redactT1 · Provider-documentedRedacted
apify-api-token-mcp-envapify · documented-format-literalMust redactT1 · Provider-documentedRedacted
apify-api-token-python-positionalapify · documented-format-literalMust redactT1 · Provider-documentedRedacted
apify-api-token-sdk-kwargapify · documented-format-literalMust redactT1 · Provider-documentedRedacted
apify-api-token-trailing-hyphen-twinapify · boundary-violationMust not flagT2 · Tool-corroborated · twinQuiet
apify-api-token-x-api-key-headerapify · documented-format-literalMust redactT1 · Provider-documentedRedacted
apify-api-token-actions-secret-referenceapify · templated-referenceMust not flagT3 · Project policyQuiet
apify-api-token-body-19-twinapify · wrong-lengthMust not flagT2 · Tool-corroborated · twinQuiet
apify-api-token-console-token-name-public-idapify · public-identifierMust not flagT2 · Tool-corroboratedQuiet
apify-api-token-ellipsis-placeholderapify · documentation-placeholderMust not flagT3 · Project policyQuiet
apify-api-token-env-reference-referenceapify · templated-referenceMust not flagT3 · Project policyQuiet
apify-api-token-hyphen-prefix-twinapify · boundary-violationMust not flagT2 · Tool-corroborated · twinQuiet
apify-api-token-identifiers-public-idapify · public-identifierMust not flagT2 · Tool-corroboratedQuiet
apify-api-token-label-proseapify · benign-lookalikeMust not flagT3 · Project policyQuiet
apify-api-token-leading-glue-twinapify · boundary-violationMust not flagT2 · Tool-corroborated · twinQuiet
apify-api-token-maskapify · benign-lookalikeMust not flagT3 · Project policyQuiet
apify-api-token-prefix-at-eol-near-missapify · format-near-missMust not flagT2 · Tool-corroboratedQuiet
apify-api-token-prefix-onlyapify · benign-lookalikeMust not flagT2 · Tool-corroboratedQuiet
apify-api-token-referenceapify · benign-lookalikeMust not flagT3 · Project policyQuiet
apify-api-token-short-bodyapify · benign-lookalikeMust not flagT2 · Tool-corroboratedQuiet
apify-api-token-short-body-near-missapify · format-near-missMust not flagT2 · Tool-corroboratedQuiet
apify-api-token-test-names-placeholderapify · documentation-placeholderMust not flagT3 · Project policyQuiet
apify-api-token-token-guidance-proseapify · prose-mentionMust not flagT3 · Project policyQuiet
apify-api-token-trailing-underscore-twinapify · boundary-violationMust not flagT2 · Tool-corroborated · twinQuiet
apify-api-token-underscore-in-body-twinapify · wrong-alphabetMust not flagT2 · Tool-corroborated · twinQuiet
apify-api-token-uppercase-prefix-twinapify · prefix-near-missMust not flagT2 · Tool-corroborated · twinQuiet
apify-api-token-your-token-placeholderapify · documentation-placeholderMust not flagT3 · Project policyQuiet