Skip to content
Benchmarks

redact-secret · Report · Detector

Heroku API tokens (legacy UUID)

  • 63 fixtures
  • Format evidence: T2 · Tool-corroborated
  • Run 2026-10-07
  • Mode published · redact-secret 0.1.0-beta.14

Format evidence

Heroku's 2024-03-07 changelog (devcenter.heroku.com/changelog-items/2842) shows the pre-prefix token as a bare 8-4-4-4-12 hex UUID and states such tokens remain valid until regenerated. Heroku documents three generations of this one credential class, all live until regenerated: the bare UUID (granted before 2024-04-01), HRKU-<uuid> (41 characters, changelog-items/3175) and HRKU-AA plus 58 characters (65); the 41- and 65-character generations are documented widths, not undocumented variants, and belong to the current OAuth family (heroku-api-key, #209), not this contract. A UUID carries no marker of its own: it is structurally identical to a Heroku app, release or request id or any unrelated UUID, and Heroku's OAuth client secret and refresh token are UUID-shaped secrets too. So, like twilio-auth-token and datadog-api-key, the value is scored as policy and only beside a same-line heroku keyword: gitleaks 8.30.1's heroku-api-key rule (a case-insensitive heroku keyword, then an assignment operator, then the exact UUID) and trufflehog 3.97.4's heroku/v1 detector (keyword-gated on heroku) both corroborate that policy and never report a bare UUID unconditionally. The length twin rests on both tools' exact 8-4-4-4-12 UUID rules. An identifier-keyed UUID on a heroku line (HEROKU_APP_ID=<uuid>) is a public identifier #312 requires to stay clean; both keyword-gated peer rules flag it, and the product has excluded identifier-shaped keys since redact-secret#714 (known gap product-714, fixed). Uppercase hex and the 40-hex token in devcenter's authentication article are recorded as unresolved, never asserted either way (#232), and no legacy token can be newly issued. redact-secret#312 (PR #675) froze the same keyword-gated Medium-confidence shape on the product side.

What the run recorded, by group

Detector views overlap, so their groups are never summed across detectors. Other scanners are reference values on the same inputs, in run order.
Groups of Heroku API tokens (legacy UUID) fixtures
GroupFixturesLeaked or false alarmsNear-twinsOutcomesOther scanners, same cell
Must not flag · Tool-corroborated17False alarmsat most 18.4%0 of 17 controls flagged17 quiet · 0 flagged
  • flare-redact at most 18.4%
  • gitleaks at most 58.7%
  • trufflehog at most 78.4%
Must not flag · Project policy24False alarmsat most 13.8%0 of 24 controls flagged24 quiet · 0 flagged
  • flare-redact at most 13.8%
  • gitleaks at most 25.8%
  • trufflehog at most 25.8%
Project policy · Project policy21Secret spans left readableat most 15.5%0 of 21 spansNear-twins told apartat least 81.6%17 of 17 pairs21 redacted · 0 too much · 0 partly exposed · 0 missed
  • flare-redact at most 99.2%
  • gitleaks at most 67.6%
  • trufflehog at most 34.6%
Pending review1UnscoredNot scoredInspect only: never scored until evidence existsNot scored
63 of 63 rows
Fixtures
63
Left readable
0
Redacted too much
0
False alarms
0

Fixtures for this detector

63 fixtures. Choose "Every scanner" to see each scanner's outcome for the same rows.
Fixtures in Heroku API tokens (legacy UUID)
FixtureKind and evidenceredact-secret
heroku-api-key-legacy-app-url-path-public-idheroku · public-identifierMust not flagT2 · Tool-corroboratedQuiet
heroku-api-key-legacy-app-uuid-json-public-idheroku · public-identifierMust not flagT2 · Tool-corroboratedQuiet
heroku-api-key-legacy-apps-info-json-public-idheroku · public-identifierMust not flagT2 · Tool-corroboratedQuiet
heroku-api-key-legacy-auth-token-outputheroku · documented-format-literalProject policyT3 · Project policyRedacted
heroku-api-key-legacy-authorizations-infoheroku · documented-format-literalProject policyT3 · Project policyRedacted
heroku-api-key-legacy-authorizations-list-public-idheroku · public-identifierMust not flagT2 · Tool-corroboratedQuiet
heroku-api-key-legacy-ci-debug-echoheroku · documented-format-literalProject policyT3 · Project policyRedacted
heroku-api-key-legacy-compose-envheroku · documented-format-literalProject policyT3 · Project policyRedacted
heroku-api-key-legacy-deploy-actionheroku · documented-format-literalProject policyT3 · Project policyRedacted
heroku-api-key-legacy-deploy-config-jsonheroku · documented-format-literalProject policyT3 · Project policyRedacted
heroku-api-key-legacy-deploy-logheroku · documented-format-literalProject policyT3 · Project policyRedacted
heroku-api-key-legacy-envheroku · documented-format-literalProject policyT3 · Project policyRedacted
heroku-api-key-legacy-exportheroku · documented-format-literalProject policyT3 · Project policyRedacted
heroku-api-key-legacy-git-config-remoteheroku · documented-format-literalProject policyT3 · Project policyRedacted
heroku-api-key-legacy-git-remoteheroku · documented-format-literalProject policyT3 · Project policyRedacted
heroku-api-key-legacy-git-remote-context-twinheroku · missing-context-markerMust not flagT3 · Project policy · twinQuiet
heroku-api-key-legacy-handoff-noteheroku · documented-format-literalProject policyT3 · Project policyRedacted
heroku-api-key-legacy-inline-envheroku · documented-format-literalProject policyT3 · Project policyRedacted
heroku-api-key-legacy-keyword-context-bareheroku · documented-format-literalProject policyT3 · Project policyRedacted
heroku-api-key-legacy-keyword-context-quotedheroku · documented-format-literalProject policyT3 · Project policyRedacted
heroku-api-key-legacy-keyword-context-unicode-crlfheroku · documented-format-literalProject policyT3 · Project policyRedacted
heroku-api-key-legacy-netrc-multi-lineheroku · documented-format-literalProject policyT3 · Project policyRedacted
heroku-api-key-legacy-netrc-single-lineheroku · documented-format-literalProject policyT3 · Project policyRedacted
heroku-api-key-legacy-oauth-client-id-public-idheroku · public-identifierMust not flagT2 · Tool-corroboratedQuiet
heroku-api-key-legacy-other-git-host-twinheroku · missing-context-markerMust not flagT3 · Project policy · twinQuiet
heroku-api-key-legacy-platform-apiheroku · documented-format-literalProject policyT3 · Project policyRedacted
heroku-api-key-legacy-platform-api-context-twinheroku · missing-context-markerMust not flagT3 · Project policy · twinQuiet
heroku-api-key-legacy-platform-api-rubyheroku · documented-format-literalProject policyT3 · Project policyRedacted
heroku-api-key-legacy-public-idheroku · benign-lookalikeMust not flagT2 · Tool-corroboratedQuiet
heroku-api-key-legacy-release-id-public-idheroku · public-identifierMust not flagT2 · Tool-corroboratedQuiet
heroku-api-key-legacy-releases-path-near-missheroku · format-near-missMust not flagT2 · Tool-corroboratedQuiet
heroku-api-key-legacy-router-request-id-public-idheroku · public-identifierMust not flagT2 · Tool-corroboratedQuiet
heroku-api-key-legacy-router-request-id-public-id-public-identifierheroku · public-identifierMust not flagT2 · Tool-corroboratedQuiet
heroku-api-key-legacy-terraform-providerheroku · documented-format-literalProject policyT3 · Project policyRedacted
heroku-api-key-legacy-zero-uuid-placeholderheroku · documentation-placeholderMust not flagT3 · Project policyQuiet
uuid-under-generic-api-key-nameauthored-prefixless-key-shape-discrimination · uuid-under-credential-name-without-provider-contextPending reviewT0 · PendingUnscored
heroku-api-key-legacy-actions-secret-referenceheroku · templated-referenceMust not flagT3 · Project policyQuiet
heroku-api-key-legacy-buildpack-digest-encoded-valueheroku · benign-encoded-valueMust not flagT2 · Tool-corroboratedQuiet
heroku-api-key-legacy-client-id-row-twinheroku · missing-context-markerMust not flagT3 · Project policy · twinQuiet
heroku-api-key-legacy-command-substitution-referenceheroku · templated-referenceMust not flagT3 · Project policyQuiet
heroku-api-key-legacy-compose-context-twinheroku · missing-context-markerMust not flagT3 · Project policy · twinQuiet
heroku-api-key-legacy-deploy-action-context-twinheroku · missing-context-markerMust not flagT3 · Project policy · twinQuiet
heroku-api-key-legacy-deploy-log-context-twinheroku · missing-context-markerMust not flagT3 · Project policy · twinQuiet
heroku-api-key-legacy-env-context-twinheroku · missing-context-markerMust not flagT3 · Project policy · twinQuiet
heroku-api-key-legacy-export-context-twinheroku · missing-context-markerMust not flagT3 · Project policy · twinQuiet
heroku-api-key-legacy-handoff-note-context-twinheroku · missing-context-markerMust not flagT3 · Project policy · twinQuiet
heroku-api-key-legacy-hrku-migration-note-proseheroku · prose-mentionMust not flagT3 · Project policyQuiet
heroku-api-key-legacy-keyword-context-bare-twinheroku · wrong-lengthMust not flagT2 · Tool-corroborated · twinQuiet
heroku-api-key-legacy-keyword-context-quoted-twinheroku · wrong-lengthMust not flagT2 · Tool-corroborated · twinQuiet
heroku-api-key-legacy-keyword-context-unicode-crlf-twinheroku · wrong-lengthMust not flagT2 · Tool-corroborated · twinQuiet