Skip to content
Benchmarks

redact-secret · Report · Detector

Docker tokens

  • 40 fixtures
  • Format evidence: T1 · Provider-documented
  • Run 2026-10-07
  • Mode published · redact-secret 0.1.0-beta.14

Format evidence

  • Provider documentation AI Governance API bearerAuth credential table (Format column: dckr_pat_*, dckr_oat_*) · observed 2026-09-23 · Docker's own API reference (docs.docker.com AI Governance API spec, bearerAuth credential table) states the Personal Access Token format as dckr_pat_* and the Organization Access Token format as dckr_oat_*, establishing both prefixes (the * is a glob, not a grammar). Body lengths and alphabet are not provider-stated, except that Docker's Hub API spec (createOrgAccessTokenResponse.token) shows an example OAT with a 27-character alphanumeric body, on example strength only. The 27-character dckr_pat_ body, the 32-character dckr_oat_ width and the [A-Za-z0-9_-] alphabet remain tool-corroborated
  • trufflehog 3.97.4
  • Reference 1

Re-tiered 2026-09-23 (#112, provider evidence redact-secret#647/#648; OAT width redact-secret#708). The dckr_oat_ branch accepts both exact widths: 27, the only width any Docker-authored artefact shows (the Hub API example; docker/portcullis rules.go, whose comment says it copies the PAT shape), and 32, which comes from TruffleHog 3.97.4 alone (trufflehog PR #4062); the scanners that state 32 trace back to it, so their count is not independent evidence. Each width is exact, so 28-31 and 33 still fail. The empirical measurement of a freshly issued OAT that would settle 27 versus 32 remains open (redact-secret#647); product main accepts both widths since redact-secret#708 (fix dc855b6; known gap product-708 fixed), and the published 0.1.0-beta.6 package still rejects the 27-byte body. The Hub spec's dckr_pat_ examples carry 15-character placeholder bodies and are not a width source. The taxonomy label docker:oauth-access-token says "OAuth", but Docker (and GitHub's docker_organization_access_token pattern) call it an Organization Access Token. Docker-owned scanner rules (docker/portcullis alphanumeric only, docker/mcp-gateway without "_") are narrower than this alphabet; they are code, not documentation, and public-string tallies contradict them.

What the run recorded, by group

Detector views overlap, so their groups are never summed across detectors. Other scanners are reference values on the same inputs, in run order.
Groups of Docker tokens fixtures
GroupFixturesLeaked or false alarmsNear-twinsOutcomesOther scanners, same cell
Must not flag · Tool-corroborated22False alarmsat most 14.9%0 of 22 controls flagged22 quiet · 0 flagged
  • flare-redact at most 14.9%
  • gitleaks at most 14.9%
  • trufflehog at most 14.9%
Must not flag · Project policy2False alarmsinsufficient-evidence0 of 2 controls flagged2 quiet · 0 flagged
  • flare-redact insufficient-evidence
  • gitleaks insufficient-evidence
  • trufflehog insufficient-evidence
Must redact · Provider-documented16Secret spans left readableat most 19.4%0 of 16 spansNear-twins told apartat least 80.6%16 of 16 pairs16 redacted · 0 too much · 0 partly exposed · 0 missed
  • flare-redact at most 100.0%
  • gitleaks at most 100.0%
  • trufflehog at most 43.0%
40 of 40 rows
Fixtures
40
Left readable
0
Redacted too much
0
False alarms
0

Fixtures for this detector

40 fixtures. Choose "Every scanner" to see each scanner's outcome for the same rows.
Fixtures in Docker tokens
FixtureKind and evidenceredact-secret
docker-token-chat-handoffdocker · documented-format-literalMust redactT1 · Provider-documentedRedacted
docker-token-ci-login-logdocker · documented-format-literalMust redactT1 · Provider-documentedRedacted
docker-token-docker-login-stdindocker · documented-format-literalMust redactT1 · Provider-documentedRedacted
docker-token-oat-27-baredocker · documented-format-literalMust redactT1 · Provider-documentedRedacted
docker-token-oat-27-quoteddocker · documented-format-literalMust redactT1 · Provider-documentedRedacted
docker-token-oat-27-unicode-crlfdocker · documented-format-literalMust redactT1 · Provider-documentedRedacted
docker-token-oat-plaindocker · documented-format-literalMust redactT1 · Provider-documentedRedacted
docker-token-oat-unicode-crlfdocker · documented-format-literalMust redactT1 · Provider-documentedRedacted
docker-token-pat-plaindocker · documented-format-literalMust redactT1 · Provider-documentedRedacted
docker-token-pat-unicode-crlfdocker · documented-format-literalMust redactT1 · Provider-documentedRedacted
docker-token-shape-1-baredocker · documented-format-literalMust redactT1 · Provider-documentedRedacted
docker-token-shape-1-quoteddocker · documented-format-literalMust redactT1 · Provider-documentedRedacted
docker-token-shape-1-unicode-crlfdocker · documented-format-literalMust redactT1 · Provider-documentedRedacted
docker-token-shape-2-baredocker · documented-format-literalMust redactT1 · Provider-documentedRedacted
docker-token-shape-2-quoteddocker · documented-format-literalMust redactT1 · Provider-documentedRedacted
docker-token-shape-2-unicode-crlfdocker · documented-format-literalMust redactT1 · Provider-documentedRedacted
docker-token-access-token-listing-public-iddocker · public-identifierMust not flagT2 · Tool-corroboratedQuiet
docker-token-dash-identifier-embeddingdocker · benign-lookalikeMust not flagT2 · Tool-corroboratedQuiet
docker-token-leading-identifier-embeddingdocker · benign-lookalikeMust not flagT2 · Tool-corroboratedQuiet
docker-token-maskdocker · benign-lookalikeMust not flagT3 · Project policyQuiet
docker-token-oat-27-long-bare-twindocker · wrong-lengthMust not flagT2 · Tool-corroborated · twinQuiet
docker-token-oat-27-long-quoted-twindocker · wrong-lengthMust not flagT2 · Tool-corroborated · twinQuiet
docker-token-oat-27-long-unicode-crlf-twindocker · wrong-lengthMust not flagT2 · Tool-corroborated · twinQuiet
docker-token-oat-27-prefix-bare-twindocker · prefix-near-missMust not flagT2 · Tool-corroborated · twinQuiet
docker-token-oat-27-prefix-quoted-twindocker · prefix-near-missMust not flagT2 · Tool-corroborated · twinQuiet
docker-token-oat-27-prefix-unicode-crlf-twindocker · prefix-near-missMust not flagT2 · Tool-corroborated · twinQuiet
docker-token-oat-27-short-bare-twindocker · wrong-lengthMust not flagT2 · Tool-corroborated · twinQuiet
docker-token-oat-27-short-quoted-twindocker · wrong-lengthMust not flagT2 · Tool-corroborated · twinQuiet
docker-token-oat-27-short-unicode-crlf-twindocker · wrong-lengthMust not flagT2 · Tool-corroborated · twinQuiet
docker-token-oat-plain-twindocker · wrong-lengthMust not flagT2 · Tool-corroborated · twinQuiet
docker-token-oat-unicode-crlf-twindocker · wrong-lengthMust not flagT2 · Tool-corroborated · twinQuiet
docker-token-pat-plain-twindocker · wrong-lengthMust not flagT2 · Tool-corroborated · twinQuiet
docker-token-pat-unicode-crlf-twindocker · wrong-lengthMust not flagT2 · Tool-corroborated · twinQuiet
docker-token-prefix-onlydocker · benign-lookalikeMust not flagT2 · Tool-corroboratedQuiet
docker-token-referencedocker · benign-lookalikeMust not flagT3 · Project policyQuiet
docker-token-shape-2-bare-twindocker · wrong-lengthMust not flagT2 · Tool-corroborated · twinQuiet
docker-token-shape-2-quoted-twindocker · wrong-lengthMust not flagT2 · Tool-corroborated · twinQuiet
docker-token-shape-2-unicode-crlf-twindocker · wrong-lengthMust not flagT2 · Tool-corroborated · twinQuiet
docker-token-short-bodydocker · benign-lookalikeMust not flagT2 · Tool-corroboratedQuiet
docker-token-trailing-identifier-embeddingdocker · benign-lookalikeMust not flagT2 · Tool-corroboratedQuiet