redact-secret · Report · Detector
Heroku API tokens (legacy UUID)
Format evidence
Heroku's 2024-03-07 changelog (devcenter.heroku.com/changelog-items/2842) shows the pre-prefix token as a bare 8-4-4-4-12 hex UUID and states such tokens remain valid until regenerated. Heroku documents three generations of this one credential class, all live until regenerated: the bare UUID (granted before 2024-04-01), HRKU-<uuid> (41 characters, changelog-items/3175) and HRKU-AA plus 58 characters (65); the 41- and 65-character generations are documented widths, not undocumented variants, and belong to the current OAuth family (heroku-api-key, #209), not this contract. A UUID carries no marker of its own: it is structurally identical to a Heroku app, release or request id or any unrelated UUID, and Heroku's OAuth client secret and refresh token are UUID-shaped secrets too. So, like twilio-auth-token and datadog-api-key, the value is scored as policy and only beside a same-line heroku keyword: gitleaks 8.30.1's heroku-api-key rule (a case-insensitive heroku keyword, then an assignment operator, then the exact UUID) and trufflehog 3.97.4's heroku/v1 detector (keyword-gated on heroku) both corroborate that policy and never report a bare UUID unconditionally. The length twin rests on both tools' exact 8-4-4-4-12 UUID rules. An identifier-keyed UUID on a heroku line (HEROKU_APP_ID=<uuid>) is a public identifier #312 requires to stay clean; both keyword-gated peer rules flag it, and the product has excluded identifier-shaped keys since redact-secret#714 (known gap product-714, fixed). Uppercase hex and the 40-hex token in devcenter's authentication article are recorded as unresolved, never asserted either way (#232), and no legacy token can be newly issued. redact-secret#312 (PR #675) froze the same keyword-gated Medium-confidence shape on the product side.
What the run recorded, by group
| Group | Fixtures | Leaked or false alarms | Near-twins | Outcomes | Other scanners, same cell |
|---|---|---|---|---|---|
| Must not flag · Tool-corroborated | 17 | False alarmsat most 18.4%0 of 17 controls flagged | 17 quiet · 0 flagged |
| |
| Must not flag · Project policy | 24 | False alarmsat most 13.8%0 of 24 controls flagged | 24 quiet · 0 flagged |
| |
| Project policy · Project policy | 21 | Secret spans left readableat most 15.5%0 of 21 spans | Near-twins told apartat least 81.6%17 of 17 pairs | 21 redacted · 0 too much · 0 partly exposed · 0 missed |
|
| Pending review | 1 | UnscoredNot scoredInspect only: never scored until evidence exists | Not scored |
- Fixtures
- 63
- Left readable
- 0
- Redacted too much
- 0
- False alarms
- 0
Fixtures for this detector
| Fixture | Kind and evidence | redact-secret |
|---|---|---|
heroku-api-key-legacy-app-url-path-public-idheroku · public-identifier | Must not flagT2 · Tool-corroborated | Quiet |
heroku-api-key-legacy-app-uuid-json-public-idheroku · public-identifier | Must not flagT2 · Tool-corroborated | Quiet |
heroku-api-key-legacy-apps-info-json-public-idheroku · public-identifier | Must not flagT2 · Tool-corroborated | Quiet |
heroku-api-key-legacy-auth-token-outputheroku · documented-format-literal | Project policyT3 · Project policy | Redacted |
heroku-api-key-legacy-authorizations-infoheroku · documented-format-literal | Project policyT3 · Project policy | Redacted |
heroku-api-key-legacy-authorizations-list-public-idheroku · public-identifier | Must not flagT2 · Tool-corroborated | Quiet |
heroku-api-key-legacy-ci-debug-echoheroku · documented-format-literal | Project policyT3 · Project policy | Redacted |
heroku-api-key-legacy-compose-envheroku · documented-format-literal | Project policyT3 · Project policy | Redacted |
heroku-api-key-legacy-deploy-actionheroku · documented-format-literal | Project policyT3 · Project policy | Redacted |
heroku-api-key-legacy-deploy-config-jsonheroku · documented-format-literal | Project policyT3 · Project policy | Redacted |
heroku-api-key-legacy-deploy-logheroku · documented-format-literal | Project policyT3 · Project policy | Redacted |
heroku-api-key-legacy-envheroku · documented-format-literal | Project policyT3 · Project policy | Redacted |
heroku-api-key-legacy-exportheroku · documented-format-literal | Project policyT3 · Project policy | Redacted |
heroku-api-key-legacy-git-config-remoteheroku · documented-format-literal | Project policyT3 · Project policy | Redacted |
heroku-api-key-legacy-git-remoteheroku · documented-format-literal | Project policyT3 · Project policy | Redacted |
heroku-api-key-legacy-git-remote-context-twinheroku · missing-context-marker | Must not flagT3 · Project policy · twin | Quiet |
heroku-api-key-legacy-handoff-noteheroku · documented-format-literal | Project policyT3 · Project policy | Redacted |
heroku-api-key-legacy-inline-envheroku · documented-format-literal | Project policyT3 · Project policy | Redacted |
heroku-api-key-legacy-keyword-context-bareheroku · documented-format-literal | Project policyT3 · Project policy | Redacted |
heroku-api-key-legacy-keyword-context-quotedheroku · documented-format-literal | Project policyT3 · Project policy | Redacted |
heroku-api-key-legacy-keyword-context-unicode-crlfheroku · documented-format-literal | Project policyT3 · Project policy | Redacted |
heroku-api-key-legacy-netrc-multi-lineheroku · documented-format-literal | Project policyT3 · Project policy | Redacted |
heroku-api-key-legacy-netrc-single-lineheroku · documented-format-literal | Project policyT3 · Project policy | Redacted |
heroku-api-key-legacy-oauth-client-id-public-idheroku · public-identifier | Must not flagT2 · Tool-corroborated | Quiet |
heroku-api-key-legacy-other-git-host-twinheroku · missing-context-marker | Must not flagT3 · Project policy · twin | Quiet |
heroku-api-key-legacy-platform-apiheroku · documented-format-literal | Project policyT3 · Project policy | Redacted |
heroku-api-key-legacy-platform-api-context-twinheroku · missing-context-marker | Must not flagT3 · Project policy · twin | Quiet |
heroku-api-key-legacy-platform-api-rubyheroku · documented-format-literal | Project policyT3 · Project policy | Redacted |
heroku-api-key-legacy-public-idheroku · benign-lookalike | Must not flagT2 · Tool-corroborated | Quiet |
heroku-api-key-legacy-release-id-public-idheroku · public-identifier | Must not flagT2 · Tool-corroborated | Quiet |
heroku-api-key-legacy-releases-path-near-missheroku · format-near-miss | Must not flagT2 · Tool-corroborated | Quiet |
heroku-api-key-legacy-router-request-id-public-idheroku · public-identifier | Must not flagT2 · Tool-corroborated | Quiet |
heroku-api-key-legacy-router-request-id-public-id-public-identifierheroku · public-identifier | Must not flagT2 · Tool-corroborated | Quiet |
heroku-api-key-legacy-terraform-providerheroku · documented-format-literal | Project policyT3 · Project policy | Redacted |
heroku-api-key-legacy-zero-uuid-placeholderheroku · documentation-placeholder | Must not flagT3 · Project policy | Quiet |
uuid-under-generic-api-key-nameauthored-prefixless-key-shape-discrimination · uuid-under-credential-name-without-provider-context | Pending reviewT0 · Pending | Unscored |
heroku-api-key-legacy-actions-secret-referenceheroku · templated-reference | Must not flagT3 · Project policy | Quiet |
heroku-api-key-legacy-buildpack-digest-encoded-valueheroku · benign-encoded-value | Must not flagT2 · Tool-corroborated | Quiet |
heroku-api-key-legacy-client-id-row-twinheroku · missing-context-marker | Must not flagT3 · Project policy · twin | Quiet |
heroku-api-key-legacy-command-substitution-referenceheroku · templated-reference | Must not flagT3 · Project policy | Quiet |
heroku-api-key-legacy-compose-context-twinheroku · missing-context-marker | Must not flagT3 · Project policy · twin | Quiet |
heroku-api-key-legacy-deploy-action-context-twinheroku · missing-context-marker | Must not flagT3 · Project policy · twin | Quiet |
heroku-api-key-legacy-deploy-log-context-twinheroku · missing-context-marker | Must not flagT3 · Project policy · twin | Quiet |
heroku-api-key-legacy-env-context-twinheroku · missing-context-marker | Must not flagT3 · Project policy · twin | Quiet |
heroku-api-key-legacy-export-context-twinheroku · missing-context-marker | Must not flagT3 · Project policy · twin | Quiet |
heroku-api-key-legacy-handoff-note-context-twinheroku · missing-context-marker | Must not flagT3 · Project policy · twin | Quiet |
heroku-api-key-legacy-hrku-migration-note-proseheroku · prose-mention | Must not flagT3 · Project policy | Quiet |
heroku-api-key-legacy-keyword-context-bare-twinheroku · wrong-length | Must not flagT2 · Tool-corroborated · twin | Quiet |
heroku-api-key-legacy-keyword-context-quoted-twinheroku · wrong-length | Must not flagT2 · Tool-corroborated · twin | Quiet |
heroku-api-key-legacy-keyword-context-unicode-crlf-twinheroku · wrong-length | Must not flagT2 · Tool-corroborated · twin | Quiet |