redact-secret · Report · Detector
axiom-personal-token
Format evidence
- Provider documentation axiomhq/axiom-go internal/config/token.go (ae983c9): IsPersonalToken is strings.HasPrefix(token, "xapt-"); the docs state a personal access token "starts with xapt-"; the SDK fixtures use the same UUID layout for both kinds; re-checked 2026-09-29 · observed 2026-09-29 · xapt- + a lowercase-hex UUID (8-4-4-4-12), 41 in all
- Reference 1
- Reference 2
- Reference 3
- Reference 4
- Reference 5
- Reference 6
- Reference 7
- Reference 8
- Reference 9
- Reference 10
Arrival evidence (#528, product redact-secret#1035; #1014 handoff axiom.md, READY by R5). A personal access token, used with an org id, has the user's full access to the Axiom console and API, including queries over every ingested log, so it is its own finding type. T1 on the prefix (R6, docs); the body layout is the shared SDK fixture layout and the xaat- docs example (R5), the weaker leg of this contract, which the recommended issuance check would settle. Neither pinned peer has an Axiom rule.
What the run recorded, by group
Detector views overlap, so their groups are never summed across detectors. Other scanners are reference values on the same inputs, in run order.
| Group | Fixtures | Leaked or false alarms | Near-twins | Outcomes | Other scanners, same cell |
|---|---|---|---|---|---|
| Must not flag · Tool-corroborated | 9 | False alarmsat most 29.9%0 of 9 controls flagged | 9 quiet · 0 flagged |
| |
| Must not flag · Project policy | 5 | False alarmsat most 43.4%0 of 5 controls flagged | 5 quiet · 0 flagged |
| |
| Must redact · Provider-documented | 11 | Secret spans left readableat most 25.9%0 of 11 spans | Near-twins told apartat least 61.0%6 of 6 pairs | 11 redacted · 0 too much · 0 partly exposed · 0 missed |
|
- Fixtures
- 25
- Left readable
- 0
- Redacted too much
- 0
- False alarms
- 0
Fixtures for this detector
25 fixtures. Choose "Every scanner" to see each scanner's outcome for the same rows.
| Fixture | Kind and evidence | redact-secret |
|---|---|---|
axiom-personal-token-bare-proseaxiom · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
axiom-personal-token-bearer-headeraxiom · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
axiom-personal-token-chat-pasteaxiom · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
axiom-personal-token-cli-configaxiom · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
axiom-personal-token-dotenvaxiom · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
axiom-personal-token-exportaxiom · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
axiom-personal-token-json-api-keyaxiom · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
axiom-personal-token-json-tokenaxiom · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
axiom-personal-token-org-id-pairaxiom · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
axiom-personal-token-sdk-kwargaxiom · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
axiom-personal-token-x-api-key-headeraxiom · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
axiom-personal-token-actions-secret-referenceaxiom · templated-reference | Must not flagT3 · Project policy | Quiet |
axiom-personal-token-ellipsis-placeholderaxiom · documentation-placeholder | Must not flagT3 · Project policy | Quiet |
axiom-personal-token-env-reference-referenceaxiom · templated-reference | Must not flagT3 · Project policy | Quiet |
axiom-personal-token-leading-glue-twinaxiom · boundary-violation | Must not flagT2 · Tool-corroborated · twin | Quiet |
axiom-personal-token-long-last-group-twinaxiom · wrong-length | Must not flagT2 · Tool-corroborated · twin | Quiet |
axiom-personal-token-missing-hyphen-twinaxiom · wrong-length | Must not flagT2 · Tool-corroborated · twin | Quiet |
axiom-personal-token-org-id-header-public-idaxiom · public-identifier | Must not flagT2 · Tool-corroborated | Quiet |
axiom-personal-token-token-guidance-proseaxiom · prose-mention | Must not flagT3 · Project policy | Quiet |
axiom-personal-token-trace-id-uuid-public-idaxiom · public-identifier | Must not flagT2 · Tool-corroborated | Quiet |
axiom-personal-token-trailing-hyphen-twinaxiom · boundary-violation | Must not flagT2 · Tool-corroborated · twin | Quiet |
axiom-personal-token-truncated-near-missaxiom · format-near-miss | Must not flagT2 · Tool-corroborated | Quiet |
axiom-personal-token-underscore-separator-twinaxiom · prefix-near-miss | Must not flagT2 · Tool-corroborated · twin | Quiet |
axiom-personal-token-uppercase-hex-byte-twinaxiom · wrong-alphabet | Must not flagT2 · Tool-corroborated · twin | Quiet |
axiom-personal-token-your-personal-token-placeholderaxiom · documentation-placeholder | Must not flagT3 · Project policy | Quiet |