redact-secret · Report · Detector
Docker tokens
Format evidence
- Provider documentation AI Governance API bearerAuth credential table (Format column: dckr_pat_*, dckr_oat_*) · observed 2026-09-23 · Docker's own API reference (docs.docker.com AI Governance API spec, bearerAuth credential table) states the Personal Access Token format as dckr_pat_* and the Organization Access Token format as dckr_oat_*, establishing both prefixes (the * is a glob, not a grammar). Body lengths and alphabet are not provider-stated, except that Docker's Hub API spec (createOrgAccessTokenResponse.token) shows an example OAT with a 27-character alphanumeric body, on example strength only. The 27-character dckr_pat_ body, the 32-character dckr_oat_ width and the [A-Za-z0-9_-] alphabet remain tool-corroborated
- trufflehog 3.97.4
- Reference 1
Re-tiered 2026-09-23 (#112, provider evidence redact-secret#647/#648; OAT width redact-secret#708). The dckr_oat_ branch accepts both exact widths: 27, the only width any Docker-authored artefact shows (the Hub API example; docker/portcullis rules.go, whose comment says it copies the PAT shape), and 32, which comes from TruffleHog 3.97.4 alone (trufflehog PR #4062); the scanners that state 32 trace back to it, so their count is not independent evidence. Each width is exact, so 28-31 and 33 still fail. The empirical measurement of a freshly issued OAT that would settle 27 versus 32 remains open (redact-secret#647); product main accepts both widths since redact-secret#708 (fix dc855b6; known gap product-708 fixed), and the published 0.1.0-beta.6 package still rejects the 27-byte body. The Hub spec's dckr_pat_ examples carry 15-character placeholder bodies and are not a width source. The taxonomy label docker:oauth-access-token says "OAuth", but Docker (and GitHub's docker_organization_access_token pattern) call it an Organization Access Token. Docker-owned scanner rules (docker/portcullis alphanumeric only, docker/mcp-gateway without "_") are narrower than this alphabet; they are code, not documentation, and public-string tallies contradict them.
What the run recorded, by group
| Group | Fixtures | Leaked or false alarms | Near-twins | Outcomes | Other scanners, same cell |
|---|---|---|---|---|---|
| Must not flag · Tool-corroborated | 22 | False alarmsat most 14.9%0 of 22 controls flagged | 22 quiet · 0 flagged |
| |
| Must not flag · Project policy | 2 | False alarmsinsufficient-evidence0 of 2 controls flagged | 2 quiet · 0 flagged |
| |
| Must redact · Provider-documented | 16 | Secret spans left readableat most 19.4%0 of 16 spans | Near-twins told apartat least 80.6%16 of 16 pairs | 16 redacted · 0 too much · 0 partly exposed · 0 missed |
|
- Fixtures
- 40
- Left readable
- 0
- Redacted too much
- 0
- False alarms
- 0
Fixtures for this detector
| Fixture | Kind and evidence | redact-secret |
|---|---|---|
docker-token-chat-handoffdocker · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
docker-token-ci-login-logdocker · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
docker-token-docker-login-stdindocker · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
docker-token-oat-27-baredocker · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
docker-token-oat-27-quoteddocker · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
docker-token-oat-27-unicode-crlfdocker · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
docker-token-oat-plaindocker · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
docker-token-oat-unicode-crlfdocker · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
docker-token-pat-plaindocker · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
docker-token-pat-unicode-crlfdocker · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
docker-token-shape-1-baredocker · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
docker-token-shape-1-quoteddocker · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
docker-token-shape-1-unicode-crlfdocker · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
docker-token-shape-2-baredocker · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
docker-token-shape-2-quoteddocker · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
docker-token-shape-2-unicode-crlfdocker · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
docker-token-access-token-listing-public-iddocker · public-identifier | Must not flagT2 · Tool-corroborated | Quiet |
docker-token-dash-identifier-embeddingdocker · benign-lookalike | Must not flagT2 · Tool-corroborated | Quiet |
docker-token-leading-identifier-embeddingdocker · benign-lookalike | Must not flagT2 · Tool-corroborated | Quiet |
docker-token-maskdocker · benign-lookalike | Must not flagT3 · Project policy | Quiet |
docker-token-oat-27-long-bare-twindocker · wrong-length | Must not flagT2 · Tool-corroborated · twin | Quiet |
docker-token-oat-27-long-quoted-twindocker · wrong-length | Must not flagT2 · Tool-corroborated · twin | Quiet |
docker-token-oat-27-long-unicode-crlf-twindocker · wrong-length | Must not flagT2 · Tool-corroborated · twin | Quiet |
docker-token-oat-27-prefix-bare-twindocker · prefix-near-miss | Must not flagT2 · Tool-corroborated · twin | Quiet |
docker-token-oat-27-prefix-quoted-twindocker · prefix-near-miss | Must not flagT2 · Tool-corroborated · twin | Quiet |
docker-token-oat-27-prefix-unicode-crlf-twindocker · prefix-near-miss | Must not flagT2 · Tool-corroborated · twin | Quiet |
docker-token-oat-27-short-bare-twindocker · wrong-length | Must not flagT2 · Tool-corroborated · twin | Quiet |
docker-token-oat-27-short-quoted-twindocker · wrong-length | Must not flagT2 · Tool-corroborated · twin | Quiet |
docker-token-oat-27-short-unicode-crlf-twindocker · wrong-length | Must not flagT2 · Tool-corroborated · twin | Quiet |
docker-token-oat-plain-twindocker · wrong-length | Must not flagT2 · Tool-corroborated · twin | Quiet |
docker-token-oat-unicode-crlf-twindocker · wrong-length | Must not flagT2 · Tool-corroborated · twin | Quiet |
docker-token-pat-plain-twindocker · wrong-length | Must not flagT2 · Tool-corroborated · twin | Quiet |
docker-token-pat-unicode-crlf-twindocker · wrong-length | Must not flagT2 · Tool-corroborated · twin | Quiet |
docker-token-prefix-onlydocker · benign-lookalike | Must not flagT2 · Tool-corroborated | Quiet |
docker-token-referencedocker · benign-lookalike | Must not flagT3 · Project policy | Quiet |
docker-token-shape-2-bare-twindocker · wrong-length | Must not flagT2 · Tool-corroborated · twin | Quiet |
docker-token-shape-2-quoted-twindocker · wrong-length | Must not flagT2 · Tool-corroborated · twin | Quiet |
docker-token-shape-2-unicode-crlf-twindocker · wrong-length | Must not flagT2 · Tool-corroborated · twin | Quiet |
docker-token-short-bodydocker · benign-lookalike | Must not flagT2 · Tool-corroborated | Quiet |
docker-token-trailing-identifier-embeddingdocker · benign-lookalike | Must not flagT2 · Tool-corroborated | Quiet |