redact-secret · Report · Detector
Axiom tokens
Format evidence
- Provider documentation axiomhq/axiom-go internal/config/token.go (ae983c9, 2023-09-19): IsAPIToken is strings.HasPrefix(token, "xaat-"); the Axiom docs response example has a lowercase-hex UUID body and the SDK fixtures use the UUID layout; re-checked 2026-09-29 · observed 2026-09-29 · xaat- + a lowercase-hex UUID (8-4-4-4-12), 41 in all
- Reference 1
- Reference 2
- Reference 3
- Reference 4
- Reference 5
- Reference 6
- Reference 7
- Reference 8
- Reference 9
- Reference 10
Arrival evidence (#528, product redact-secret#1035; #1014 handoff axiom.md, READY by R5). An API token is ingest-only or carries query and dataset-management rights; it is also the service-account password for Postgres-wire and Grafana access. T1: the prefix is the SDK runtime check (R6), the layout and lowercase hex a docs response example plus the SDK fixtures (R5). A bare UUID stays unclaimed; the prefix is load-bearing. Excluded: uppercase-hex bodies (not observed; accepted false negative), placeholders such as xaat-your-api-token, org ids and dataset names. Neither pinned peer has an Axiom rule. Graduated to a registry detector at the 4fb7882 re-pin (redact-secret PR #1039).
What the run recorded, by group
Detector views overlap, so their groups are never summed across detectors. Other scanners are reference values on the same inputs, in run order.
| Group | Fixtures | Leaked or false alarms | Near-twins | Outcomes | Other scanners, same cell |
|---|---|---|---|---|---|
| Must not flag · Tool-corroborated | 13 | False alarmsat most 22.8%0 of 13 controls flagged | 13 quiet · 0 flagged |
| |
| Must not flag · Project policy | 8 | False alarmsat most 32.4%0 of 8 controls flagged | 8 quiet · 0 flagged |
| |
| Must redact · Provider-documented | 16 | Secret spans left readableat most 19.4%0 of 16 spans | Near-twins told apartat least 67.6%8 of 8 pairs | 16 redacted · 0 too much · 0 partly exposed · 0 missed |
|
- Fixtures
- 37
- Left readable
- 0
- Redacted too much
- 0
- False alarms
- 0
Fixtures for this detector
37 fixtures. Choose "Every scanner" to see each scanner's outcome for the same rows.
| Fixture | Kind and evidence | redact-secret |
|---|---|---|
axiom-token-bare-proseaxiom · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
axiom-token-bearer-headeraxiom · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
axiom-token-chat-pasteaxiom · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
axiom-token-dotenvaxiom · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
axiom-token-exportaxiom · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
axiom-token-fluent-bit-outputaxiom · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
axiom-token-grafana-passwordaxiom · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
axiom-token-json-api-keyaxiom · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
axiom-token-json-tokenaxiom · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
axiom-token-key-shape-bareaxiom · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
axiom-token-key-shape-quotedaxiom · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
axiom-token-key-shape-unicode-crlfaxiom · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
axiom-token-otel-env-beareraxiom · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
axiom-token-sdk-kwargaxiom · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
axiom-token-vector-sinkaxiom · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
axiom-token-x-api-key-headeraxiom · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
axiom-token-bare-uuid-public-idaxiom · public-identifier | Must not flagT2 · Tool-corroborated | Quiet |
axiom-token-env-reference-referenceaxiom · templated-reference | Must not flagT3 · Project policy | Quiet |
axiom-token-label-proseaxiom · benign-lookalike | Must not flagT3 · Project policy | Quiet |
axiom-token-leading-glue-twinaxiom · boundary-violation | Must not flagT2 · Tool-corroborated · twin | Quiet |
axiom-token-long-last-group-twinaxiom · wrong-length | Must not flagT2 · Tool-corroborated · twin | Quiet |
axiom-token-maskaxiom · benign-lookalike | Must not flagT3 · Project policy | Quiet |
axiom-token-non-hex-letter-twinaxiom · wrong-alphabet | Must not flagT2 · Tool-corroborated · twin | Quiet |
axiom-token-org-and-dataset-public-idaxiom · public-identifier | Must not flagT2 · Tool-corroborated | Quiet |
axiom-token-prefix-onlyaxiom · benign-lookalike | Must not flagT2 · Tool-corroborated | Quiet |
axiom-token-referenceaxiom · benign-lookalike | Must not flagT3 · Project policy | Quiet |
axiom-token-short-bodyaxiom · benign-lookalike | Must not flagT2 · Tool-corroborated | Quiet |
axiom-token-short-first-group-twinaxiom · wrong-length | Must not flagT2 · Tool-corroborated · twin | Quiet |
axiom-token-token-guidance-proseaxiom · prose-mention | Must not flagT3 · Project policy | Quiet |
axiom-token-trailing-underscore-twinaxiom · boundary-violation | Must not flagT2 · Tool-corroborated · twin | Quiet |
axiom-token-truncated-near-missaxiom · format-near-miss | Must not flagT2 · Tool-corroborated | Quiet |
axiom-token-underscore-separator-twinaxiom · prefix-near-miss | Must not flagT2 · Tool-corroborated · twin | Quiet |
axiom-token-unknown-prefix-twinaxiom · prefix-near-miss | Must not flagT2 · Tool-corroborated · twin | Quiet |
axiom-token-uppercase-hex-byte-twinaxiom · wrong-alphabet | Must not flagT2 · Tool-corroborated · twin | Quiet |
axiom-token-vector-env-interpolation-referenceaxiom · templated-reference | Must not flagT3 · Project policy | Quiet |
axiom-token-x-filled-placeholderaxiom · documentation-placeholder | Must not flagT3 · Project policy | Quiet |
axiom-token-your-api-token-placeholderaxiom · documentation-placeholder | Must not flagT3 · Project policy | Quiet |