Skip to content
Benchmarks

redact-secret · Report · Detector

Confluent Cloud API secrets

  • 31 fixtures
  • Format evidence: T1 · Provider-documented
  • Run 2026-10-07
  • Mode published · redact-secret 0.1.0-beta.14

Format evidence

  • Provider documentation cflt-prefixed API secret (created after 2025-07-30) · observed 2026-09-23 · the page states "API secrets created after July 30, 2025 have a cflt prefix followed by 60 characters consisting of A-Z, a-z, 0-9, + or /" and that "the final 6 characters contain a Base64-encoded CRC32 checksum of the prior 54 characters"; its own secret-detection snippet fixes the algorithm (CRC32 over the 54 characters after cflt, little-endian bytes, standard Base64, first 6 characters), so the checksum is recomputable and `validate` enforces it (#209, research #234)
  • trufflehog 3.97.4
  • gitleaks 8.30.1

Prefix, body length, alphabet and checksum are provider-documented on docs.confluent.io; the checksum's exact byte range, byte order and encoding come from the provider's own published snippet (provider code on the documentation page). Re-checked 2026-09-24 (#234): an earlier revision of this contract recorded the checksum as documented but outside the lexical contract, and the product source (confluent.rs) says the provider does not publish it precisely enough to recompute; both are superseded, since the snippet reproduces the page's own example exactly and fails it with big-endian bytes or with the prefix included. `pattern` keeps the lexical shape and `validate` adds the checksum, so a checksum-invalid 64-character value is outside the contract: the detector-coverage prefixed-shape positives, first generated before this correction as flat random bodies that failed the checksum, were regenerated with a valid checksum over their unchanged first 54 body characters (#213), and #209's beta8-209 positives are checksum-valid by construction. Neither pinned tool registers the cflt-prefixed shape itself: gitleaks 8.30.1's confluent-secret-key rule and trufflehog 3.97.4's confluent detector each match a keyword-gated bare 64-byte body (gitleaks over a case-insensitive [a-z0-9], so it misses any secret containing "+" or "/"; trufflehog over [a-zA-Z0-9+/], reporting only a key-ID and secret pair), so both are cited as corroboration of the 64-byte total width, not of the prefix or checksum, and a bare prefixed secret with no keyword is an expected peer false negative. Neither validates the checksum. The unprefixed pre-2025-07-30 generation is the separate confluent-cloud-api-secret-legacy contract. The API key ID — documented as "not considered secret information" (example shape: 16 upper-case letters and digits) — is the family's public-identifier control, never a positive. redact-secret#309 (PR #667) froze the prefix and length grammar on the product side without the checksum.

What the run recorded, by group

Detector views overlap, so their groups are never summed across detectors. Other scanners are reference values on the same inputs, in run order.
Groups of Confluent Cloud API secrets fixtures
GroupFixturesLeaked or false alarmsNear-twinsOutcomesOther scanners, same cell
Must not flag · Tool-corroborated14False alarmsat most 21.5%0 of 14 controls flagged14 quiet · 0 flagged
  • flare-redact at most 21.5%
  • gitleaks at most 39.9%
  • trufflehog at most 31.5%
Must not flag · Project policy4False alarmsinsufficient-evidence0 of 4 controls flagged4 quiet · 0 flagged
  • flare-redact insufficient-evidence
  • gitleaks insufficient-evidence
  • trufflehog insufficient-evidence
Must redact · Provider-documented13Secret spans left readableat most 22.8%0 of 13 spansNear-twins told apartat least 72.2%10 of 10 pairs13 redacted · 0 too much · 0 partly exposed · 0 missed
  • flare-redact at most 100.0%
  • gitleaks at most 57.6%
  • trufflehog at most 100.0%
31 of 31 rows
Fixtures
31
Left readable
0
Redacted too much
0
False alarms
0

Fixtures for this detector

31 fixtures. Choose "Every scanner" to see each scanner's outcome for the same rows.
Fixtures in Confluent Cloud API secrets
FixtureKind and evidenceredact-secret
confluent-cloud-api-secret-cli-api-key-create-jsonconfluent · documented-format-literalMust redactT1 · Provider-documentedRedacted
confluent-cloud-api-secret-confluent-api-key-storeconfluent · documented-format-literalMust redactT1 · Provider-documentedRedacted
confluent-cloud-api-secret-curl-basic-authconfluent · documented-format-literalMust redactT1 · Provider-documentedRedacted
confluent-cloud-api-secret-env-cloud-secretconfluent · documented-format-literalMust redactT1 · Provider-documentedRedacted
confluent-cloud-api-secret-env-cloud-secret-checksum-twinconfluent · invalid-checksumMust not flagT2 · Tool-corroborated · twinQuiet
confluent-cloud-api-secret-github-actions-connector-deployconfluent · documented-format-literalMust redactT1 · Provider-documentedRedacted
confluent-cloud-api-secret-k8s-secret-stringdataconfluent · documented-format-literalMust redactT1 · Provider-documentedRedacted
confluent-cloud-api-secret-kafka-client-propertiesconfluent · documented-format-literalMust redactT1 · Provider-documentedRedacted
confluent-cloud-api-secret-prefixed-shape-bareconfluent · documented-format-literalMust redactT1 · Provider-documentedRedacted
confluent-cloud-api-secret-prefixed-shape-quotedconfluent · documented-format-literalMust redactT1 · Provider-documentedRedacted
confluent-cloud-api-secret-prefixed-shape-unicode-crlfconfluent · documented-format-literalMust redactT1 · Provider-documentedRedacted
confluent-cloud-api-secret-public-idconfluent · benign-lookalikeMust not flagT2 · Tool-corroboratedQuiet
confluent-cloud-api-secret-python-producer-configconfluent · documented-format-literalMust redactT1 · Provider-documentedRedacted
confluent-cloud-api-secret-secrets-manager-jsonconfluent · documented-format-literalMust redactT1 · Provider-documentedRedacted
confluent-cloud-api-secret-shell-export-secretconfluent · documented-format-literalMust redactT1 · Provider-documentedRedacted
confluent-cloud-api-secret-cli-api-key-create-json-checksum-prefix-included-twinconfluent · invalid-checksumMust not flagT2 · Tool-corroborated · twinQuiet
confluent-cloud-api-secret-kafka-client-properties-checksum-byte-order-twinconfluent · invalid-checksumMust not flagT2 · Tool-corroborated · twinQuiet
confluent-cloud-api-secret-label-proseconfluent · benign-lookalikeMust not flagT3 · Project policyQuiet
confluent-cloud-api-secret-maskconfluent · benign-lookalikeMust not flagT3 · Project policyQuiet
confluent-cloud-api-secret-prefix-onlyconfluent · benign-lookalikeMust not flagT2 · Tool-corroboratedQuiet
confluent-cloud-api-secret-prefixed-shape-bare-twinconfluent · wrong-lengthMust not flagT2 · Tool-corroborated · twinQuiet
confluent-cloud-api-secret-prefixed-shape-prefix-bare-twinconfluent · prefix-near-missMust not flagT2 · Tool-corroborated · twinQuiet
confluent-cloud-api-secret-prefixed-shape-prefix-quoted-twinconfluent · prefix-near-missMust not flagT2 · Tool-corroborated · twinQuiet
confluent-cloud-api-secret-prefixed-shape-prefix-unicode-crlf-twinconfluent · prefix-near-missMust not flagT2 · Tool-corroborated · twinQuiet
confluent-cloud-api-secret-prefixed-shape-quoted-twinconfluent · wrong-lengthMust not flagT2 · Tool-corroborated · twinQuiet
confluent-cloud-api-secret-prefixed-shape-unicode-crlf-twinconfluent · wrong-lengthMust not flagT2 · Tool-corroborated · twinQuiet
confluent-cloud-api-secret-referenceconfluent · benign-lookalikeMust not flagT3 · Project policyQuiet
confluent-cloud-api-secret-sasl-username-only-public-idconfluent · public-identifierMust not flagT2 · Tool-corroboratedQuiet
confluent-cloud-api-secret-secrets-manager-json-alphabet-twinconfluent · wrong-alphabetMust not flagT2 · Tool-corroborated · twinQuiet
confluent-cloud-api-secret-short-bodyconfluent · benign-lookalikeMust not flagT2 · Tool-corroboratedQuiet
confluent-cloud-api-secret-ticker-note-proseconfluent · prose-mentionMust not flagT3 · Project policyQuiet