Skip to content
Benchmarks

redact-secret · Report · Detector

Amazon Bedrock short-term API keys

  • 34 fixtures
  • Format evidence: T1 · Provider-documented
  • Run 2026-10-07
  • Mode published · redact-secret 0.1.0-beta.14

Format evidence

  • Provider documentation AUTH_PREFIX = "bedrock-api-key-" in AWS's Python, JS and Java token generators · observed 2026-09-26 · AWS-authored generators (aws-bedrock-token-generator, Python, JS and Java) build the short-term key as bedrock-api-key- followed by the standard padded Base64 of a SigV4-presigned CallWithBearerToken URL plus &Version=1, and the AWS Security Blog prints the fixed 133-character Base64 head. Provider code and a provider blog are not a documentation page; the maintainer ruling of 2026-09-27 (redact-secret#779) accepts them as T1 evidence for the prefix, the fixed 133-character head and the standard padded Base64 alphabet only. Total length and the session-token part of the body stay T2
  • gitleaks 8.30.1
  • awslabs/git-secrets
  • Reference 1
  • Reference 2
  • Reference 3
  • Reference 4
  • Reference 5
  • Reference 6
  • Reference 7

Arrival evidence (#384, product redact-secret#864; research #779), T1 by maintainer ruling of 2026-09-27 for the prefix, the fixed head and the standard padded Base64 alphabet, graduated to a registry detector at cfe2aec: three AWS-authored token generators fix the bedrock-api-key- prefix, the &Version=1 suffix and standard padded Base64, and the AWS Security Blog prints a fixed 133-character head, but no AWS page documents the key as a format. gitleaks 8.30.1 and awslabs/git-secrets match only the prefix plus a 28-character head (the Base64 of bedrock.amazonaws.com), a weaker anchor than the blog's. The head is the Base64 of the fixed pre-signed URL head, so the generator derives it from that text. The body after the head has no documented width: about 500 characters without a session token, over 1000 with one. No length or ceiling twin is authored. The decoded pre-signed URL is a different lexical form of the same secret and a separate ruling; it is not authored.

What the run recorded, by group

Detector views overlap, so their groups are never summed across detectors. Other scanners are reference values on the same inputs, in run order.
Groups of Amazon Bedrock short-term API keys fixtures
GroupFixturesLeaked or false alarmsNear-twinsOutcomesOther scanners, same cell
Must not flag · Tool-corroborated13False alarmsat most 22.8%0 of 13 controls flagged13 quiet · 0 flagged
  • flare-redact at most 22.8%
  • gitleaks at most 76.8%
  • trufflehog at most 22.8%
Must not flag · Project policy8False alarmsat most 32.4%0 of 8 controls flagged8 quiet · 0 flagged
  • flare-redact at most 32.4%
  • gitleaks at most 32.4%
  • trufflehog at most 32.4%
Must redact · Provider-documented13Secret spans left readableat most 22.8%0 of 13 spansNear-twins told apartinsufficient-coverage6 of 6 pairs13 redacted · 0 too much · 0 partly exposed · 0 missed
  • flare-redact at most 98.6%
  • gitleaks at most 98.6%
  • trufflehog at most 100.0%
34 of 34 rows
Fixtures
34
Left readable
0
Redacted too much
0
False alarms
0

Fixtures for this detector

34 fixtures. Choose "Every scanner" to see each scanner's outcome for the same rows.
Fixtures in Amazon Bedrock short-term API keys
FixtureKind and evidenceredact-secret
aws-bedrock-short-term-api-key-actions-envaws-bedrock · documented-format-literalMust redactT1 · Provider-documentedRedacted
aws-bedrock-short-term-api-key-agent-settingsaws-bedrock · documented-format-literalMust redactT1 · Provider-documentedRedacted
aws-bedrock-short-term-api-key-curl-beareraws-bedrock · documented-format-literalMust redactT1 · Provider-documentedRedacted
aws-bedrock-short-term-api-key-dotenvaws-bedrock · documented-format-literalMust redactT1 · Provider-documentedRedacted
aws-bedrock-short-term-api-key-embedded-leading-twinaws-bedrock · boundary-violationMust not flagT2 · Tool-corroborated · twinQuiet
aws-bedrock-short-term-api-key-export-with-sessionaws-bedrock · documented-format-literalMust redactT1 · Provider-documentedRedacted
aws-bedrock-short-term-api-key-head-only-twinaws-bedrock · wrong-lengthMust not flagT2 · Tool-corroborated · twinQuiet
aws-bedrock-short-term-api-key-key-shape-bareaws-bedrock · documented-format-literalMust redactT1 · Provider-documentedRedacted
aws-bedrock-short-term-api-key-key-shape-quotedaws-bedrock · documented-format-literalMust redactT1 · Provider-documentedRedacted
aws-bedrock-short-term-api-key-key-shape-unicode-crlfaws-bedrock · documented-format-literalMust redactT1 · Provider-documentedRedacted
aws-bedrock-short-term-api-key-openai-sdk-mantleaws-bedrock · documented-format-literalMust redactT1 · Provider-documentedRedacted
aws-bedrock-short-term-api-key-pasted-keyaws-bedrock · documented-format-literalMust redactT1 · Provider-documentedRedacted
aws-bedrock-short-term-api-key-plural-prefix-twinaws-bedrock · prefix-near-missMust not flagT2 · Tool-corroborated · twinQuiet
aws-bedrock-short-term-api-key-proxy-logaws-bedrock · documented-format-literalMust redactT1 · Provider-documentedRedacted
aws-bedrock-short-term-api-key-python-environaws-bedrock · documented-format-literalMust redactT1 · Provider-documentedRedacted
aws-bedrock-short-term-api-key-rule-with-body-class-near-missaws-bedrock · format-near-missMust not flagT2 · Tool-corroboratedQuiet
aws-bedrock-short-term-api-key-scanner-rule-anchor-near-missaws-bedrock · format-near-missMust not flagT2 · Tool-corroboratedQuiet
aws-bedrock-short-term-api-key-short-bodyaws-bedrock · benign-lookalikeMust not flagT2 · Tool-corroboratedQuiet
aws-bedrock-short-term-api-key-tool-callaws-bedrock · documented-format-literalMust redactT1 · Provider-documentedRedacted
aws-bedrock-short-term-api-key-urlsafe-body-twinaws-bedrock · wrong-alphabetMust not flagT2 · Tool-corroborated · twinQuiet
aws-bedrock-short-term-api-key-capitalized-prefix-twinaws-bedrock · prefix-near-missMust not flagT2 · Tool-corroborated · twinQuiet
aws-bedrock-short-term-api-key-decoded-host-only-encoded-valueaws-bedrock · benign-encoded-valueMust not flagT2 · Tool-corroboratedQuiet
aws-bedrock-short-term-api-key-docs-angle-placeholderaws-bedrock · documentation-placeholderMust not flagT3 · Project policyQuiet
aws-bedrock-short-term-api-key-env-reference-referenceaws-bedrock · templated-referenceMust not flagT3 · Project policyQuiet
aws-bedrock-short-term-api-key-head-one-char-off-twinaws-bedrock · prefix-near-missMust not flagT2 · Tool-corroborated · twinQuiet
aws-bedrock-short-term-api-key-iam-action-and-arn-public-idaws-bedrock · public-identifierMust not flagT2 · Tool-corroboratedQuiet
aws-bedrock-short-term-api-key-key-guidance-proseaws-bedrock · prose-mentionMust not flagT3 · Project policyQuiet
aws-bedrock-short-term-api-key-label-proseaws-bedrock · benign-lookalikeMust not flagT3 · Project policyQuiet
aws-bedrock-short-term-api-key-maskaws-bedrock · benign-lookalikeMust not flagT3 · Project policyQuiet
aws-bedrock-short-term-api-key-prefix-onlyaws-bedrock · benign-lookalikeMust not flagT2 · Tool-corroboratedQuiet
aws-bedrock-short-term-api-key-python-getenv-referenceaws-bedrock · templated-referenceMust not flagT3 · Project policyQuiet
aws-bedrock-short-term-api-key-referenceaws-bedrock · benign-lookalikeMust not flagT3 · Project policyQuiet
aws-bedrock-short-term-api-key-unrelated-base64-encoded-valueaws-bedrock · benign-encoded-valueMust not flagT2 · Tool-corroboratedQuiet
aws-bedrock-short-term-api-key-your-key-here-placeholderaws-bedrock · documentation-placeholderMust not flagT3 · Project policyQuiet