redact-secret · Report · Detector
Confluent Cloud API secrets
Format evidence
- Provider documentation cflt-prefixed API secret (created after 2025-07-30) · observed 2026-09-23 · the page states "API secrets created after July 30, 2025 have a cflt prefix followed by 60 characters consisting of A-Z, a-z, 0-9, + or /" and that "the final 6 characters contain a Base64-encoded CRC32 checksum of the prior 54 characters"; its own secret-detection snippet fixes the algorithm (CRC32 over the 54 characters after cflt, little-endian bytes, standard Base64, first 6 characters), so the checksum is recomputable and `validate` enforces it (#209, research #234)
- trufflehog 3.97.4
- gitleaks 8.30.1
Prefix, body length, alphabet and checksum are provider-documented on docs.confluent.io; the checksum's exact byte range, byte order and encoding come from the provider's own published snippet (provider code on the documentation page). Re-checked 2026-09-24 (#234): an earlier revision of this contract recorded the checksum as documented but outside the lexical contract, and the product source (confluent.rs) says the provider does not publish it precisely enough to recompute; both are superseded, since the snippet reproduces the page's own example exactly and fails it with big-endian bytes or with the prefix included. `pattern` keeps the lexical shape and `validate` adds the checksum, so a checksum-invalid 64-character value is outside the contract: the detector-coverage prefixed-shape positives, first generated before this correction as flat random bodies that failed the checksum, were regenerated with a valid checksum over their unchanged first 54 body characters (#213), and #209's beta8-209 positives are checksum-valid by construction. Neither pinned tool registers the cflt-prefixed shape itself: gitleaks 8.30.1's confluent-secret-key rule and trufflehog 3.97.4's confluent detector each match a keyword-gated bare 64-byte body (gitleaks over a case-insensitive [a-z0-9], so it misses any secret containing "+" or "/"; trufflehog over [a-zA-Z0-9+/], reporting only a key-ID and secret pair), so both are cited as corroboration of the 64-byte total width, not of the prefix or checksum, and a bare prefixed secret with no keyword is an expected peer false negative. Neither validates the checksum. The unprefixed pre-2025-07-30 generation is the separate confluent-cloud-api-secret-legacy contract. The API key ID — documented as "not considered secret information" (example shape: 16 upper-case letters and digits) — is the family's public-identifier control, never a positive. redact-secret#309 (PR #667) froze the prefix and length grammar on the product side without the checksum.
What the run recorded, by group
| Group | Fixtures | Leaked or false alarms | Near-twins | Outcomes | Other scanners, same cell |
|---|---|---|---|---|---|
| Must not flag · Tool-corroborated | 14 | False alarmsat most 21.5%0 of 14 controls flagged | 14 quiet · 0 flagged |
| |
| Must not flag · Project policy | 4 | False alarmsinsufficient-evidence0 of 4 controls flagged | 4 quiet · 0 flagged |
| |
| Must redact · Provider-documented | 13 | Secret spans left readableat most 22.8%0 of 13 spans | Near-twins told apartat least 72.2%10 of 10 pairs | 13 redacted · 0 too much · 0 partly exposed · 0 missed |
|
- Fixtures
- 31
- Left readable
- 0
- Redacted too much
- 0
- False alarms
- 0
Fixtures for this detector
| Fixture | Kind and evidence | redact-secret |
|---|---|---|
confluent-cloud-api-secret-cli-api-key-create-jsonconfluent · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
confluent-cloud-api-secret-confluent-api-key-storeconfluent · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
confluent-cloud-api-secret-curl-basic-authconfluent · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
confluent-cloud-api-secret-env-cloud-secretconfluent · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
confluent-cloud-api-secret-env-cloud-secret-checksum-twinconfluent · invalid-checksum | Must not flagT2 · Tool-corroborated · twin | Quiet |
confluent-cloud-api-secret-github-actions-connector-deployconfluent · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
confluent-cloud-api-secret-k8s-secret-stringdataconfluent · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
confluent-cloud-api-secret-kafka-client-propertiesconfluent · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
confluent-cloud-api-secret-prefixed-shape-bareconfluent · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
confluent-cloud-api-secret-prefixed-shape-quotedconfluent · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
confluent-cloud-api-secret-prefixed-shape-unicode-crlfconfluent · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
confluent-cloud-api-secret-public-idconfluent · benign-lookalike | Must not flagT2 · Tool-corroborated | Quiet |
confluent-cloud-api-secret-python-producer-configconfluent · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
confluent-cloud-api-secret-secrets-manager-jsonconfluent · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
confluent-cloud-api-secret-shell-export-secretconfluent · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
confluent-cloud-api-secret-cli-api-key-create-json-checksum-prefix-included-twinconfluent · invalid-checksum | Must not flagT2 · Tool-corroborated · twin | Quiet |
confluent-cloud-api-secret-kafka-client-properties-checksum-byte-order-twinconfluent · invalid-checksum | Must not flagT2 · Tool-corroborated · twin | Quiet |
confluent-cloud-api-secret-label-proseconfluent · benign-lookalike | Must not flagT3 · Project policy | Quiet |
confluent-cloud-api-secret-maskconfluent · benign-lookalike | Must not flagT3 · Project policy | Quiet |
confluent-cloud-api-secret-prefix-onlyconfluent · benign-lookalike | Must not flagT2 · Tool-corroborated | Quiet |
confluent-cloud-api-secret-prefixed-shape-bare-twinconfluent · wrong-length | Must not flagT2 · Tool-corroborated · twin | Quiet |
confluent-cloud-api-secret-prefixed-shape-prefix-bare-twinconfluent · prefix-near-miss | Must not flagT2 · Tool-corroborated · twin | Quiet |
confluent-cloud-api-secret-prefixed-shape-prefix-quoted-twinconfluent · prefix-near-miss | Must not flagT2 · Tool-corroborated · twin | Quiet |
confluent-cloud-api-secret-prefixed-shape-prefix-unicode-crlf-twinconfluent · prefix-near-miss | Must not flagT2 · Tool-corroborated · twin | Quiet |
confluent-cloud-api-secret-prefixed-shape-quoted-twinconfluent · wrong-length | Must not flagT2 · Tool-corroborated · twin | Quiet |
confluent-cloud-api-secret-prefixed-shape-unicode-crlf-twinconfluent · wrong-length | Must not flagT2 · Tool-corroborated · twin | Quiet |
confluent-cloud-api-secret-referenceconfluent · benign-lookalike | Must not flagT3 · Project policy | Quiet |
confluent-cloud-api-secret-sasl-username-only-public-idconfluent · public-identifier | Must not flagT2 · Tool-corroborated | Quiet |
confluent-cloud-api-secret-secrets-manager-json-alphabet-twinconfluent · wrong-alphabet | Must not flagT2 · Tool-corroborated · twin | Quiet |
confluent-cloud-api-secret-short-bodyconfluent · benign-lookalike | Must not flagT2 · Tool-corroborated | Quiet |
confluent-cloud-api-secret-ticker-note-proseconfluent · prose-mention | Must not flagT3 · Project policy | Quiet |