redact-secret · Report · Detector
Heroku API tokens
Format evidence
- Provider documentation HRKU- prefixed OAuth access token (41-character 2024-04 and 65-character 2025-04 generations) · observed 2026-09-23 · the page states "Heroku OAuth access tokens are 65 characters long and prefixed with HRKU-" and shows a 65-character worked example beginning HRKU-AA (not reproduced here, since secret scanners classify it as a live token); its own response examples, changelog-items/2842 and changelog-items/3175 ("increasing from 41 characters to 65 characters") document the earlier 41-character HRKU-<uuid> generation. The literal AA after the dash is example- and tool-observed and the [A-Za-z0-9_-] body alphabet is tool-corroborated; neither is stated in prose
- gitleaks 8.30.1
- trufflehog 3.97.4
Re-checked 2026-09-24 (#235, consumed by #209). Heroku documents three generations of the OAuth access token, each "continue[s] to work … until they're regenerated": G0, a bare UUID granted before 2024-04-01 (changelog-items/2842), which is the separate context-gated heroku-api-key-legacy contract; G1, HRKU- plus a UUID, 41 characters, granted 2024-04-01 through 2025-04-22 (changelog-items/2842, 2800, 3175; the oauth article's own response examples and heroku/cli's generated types still show it); and G2, HRKU- plus 60 characters, 65 in total, granted from 2025-04-23 (changelog-items/3175, 3176). An earlier revision of this contract called G1 an "undocumented-width variant"; the provider names 41 as the previous length, so `pattern` now accepts both HRKU- generations. The two pinned tools cover only G2: gitleaks 8.30.1's heroku-api-key-v2 rule (`\b((HRKU-AA[0-9a-zA-Z_-]{58}))`, keyword hrku-aa, entropy 4, trailing delimiter) and trufflehog 3.97.4's heroku/v2 detector both match exactly HRKU-AA plus 58 bytes of [A-Za-z0-9_-]; a G1 token is an expected false negative for both (GitLab's rule, not pinned, covers G1 only). The AA start of G2 is kept in `pattern` as observed grammar (the provider's worked examples and both pinned tools), not as provider-stated grammar: trufflehog#4510 disputes it and osv-scalibr does not pin it, so no fixture asserts silence on a non-AA 65-character value. The authentication article's 40-character hex .netrc example is an undated fourth shape recorded unresolved. Refresh tokens, client secrets, grant codes and session tokens are bare UUIDs and secrets that no family claims; they are never benign controls here. redact-secret#312 (PR #675) froze the G2 grammar only on the product side.
What the run recorded, by group
| Group | Fixtures | Leaked or false alarms | Near-twins | Outcomes | Other scanners, same cell |
|---|---|---|---|---|---|
| Must not flag · Tool-corroborated | 12 | False alarmsat most 24.3%0 of 12 controls flagged | 12 quiet · 0 flagged |
| |
| Must not flag · Project policy | 5 | False alarmsat most 43.4%0 of 5 controls flagged | 5 quiet · 0 flagged |
| |
| Must redact · Provider-documented | 12 | Secret spans left readableat most 22.8%0 of 13 spans | Near-twins told apartat least 70.1%9 of 9 pairs | 13 redacted · 0 too much · 0 partly exposed · 0 missed |
|
- Fixtures
- 29
- Left readable
- 0
- Redacted too much
- 0
- False alarms
- 0
Fixtures for this detector
| Fixture | Kind and evidence | redact-secret |
|---|---|---|
heroku-api-key-authorization-ids-public-idheroku · public-identifier | Must not flagT2 · Tool-corroborated | Quiet |
heroku-api-key-authorizations-create-g1heroku · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
heroku-api-key-compose-envheroku · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
heroku-api-key-env-g1heroku · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
heroku-api-key-github-actions-deployheroku · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
heroku-api-key-netrc-g2heroku · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
heroku-api-key-prefixed-shape-bareheroku · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
heroku-api-key-prefixed-shape-quotedheroku · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
heroku-api-key-prefixed-shape-unicode-crlfheroku · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
heroku-api-key-python-heroku3-clientheroku · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
heroku-api-key-shell-export-api-keyheroku · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
heroku-api-key-terraform-providerheroku · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
heroku-api-key-authorizations-create-g1-separator-twinheroku · boundary-violation | Must not flagT2 · Tool-corroborated · twin | Quiet |
heroku-api-key-bearer-header-g2heroku · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
heroku-api-key-bearer-header-g2-prefix-case-twinheroku · prefix-near-miss | Must not flagT2 · Tool-corroborated · twin | Quiet |
heroku-api-key-env-g1-length-twinheroku · wrong-length | Must not flagT2 · Tool-corroborated · twin | Quiet |
heroku-api-key-generation-note-proseheroku · prose-mention | Must not flagT3 · Project policy | Quiet |
heroku-api-key-label-proseheroku · benign-lookalike | Must not flagT3 · Project policy | Quiet |
heroku-api-key-maskheroku · benign-lookalike | Must not flagT3 · Project policy | Quiet |
heroku-api-key-netrc-template-placeholderheroku · documentation-placeholder | Must not flagT3 · Project policy | Quiet |
heroku-api-key-prefix-onlyheroku · benign-lookalike | Must not flagT2 · Tool-corroborated | Quiet |
heroku-api-key-prefixed-shape-bare-twinheroku · wrong-length | Must not flagT2 · Tool-corroborated · twin | Quiet |
heroku-api-key-prefixed-shape-prefix-bare-twinheroku · prefix-near-miss | Must not flagT2 · Tool-corroborated · twin | Quiet |
heroku-api-key-prefixed-shape-prefix-quoted-twinheroku · prefix-near-miss | Must not flagT2 · Tool-corroborated · twin | Quiet |
heroku-api-key-prefixed-shape-prefix-unicode-crlf-twinheroku · prefix-near-miss | Must not flagT2 · Tool-corroborated · twin | Quiet |
heroku-api-key-prefixed-shape-quoted-twinheroku · wrong-length | Must not flagT2 · Tool-corroborated · twin | Quiet |
heroku-api-key-prefixed-shape-unicode-crlf-twinheroku · wrong-length | Must not flagT2 · Tool-corroborated · twin | Quiet |
heroku-api-key-referenceheroku · benign-lookalike | Must not flagT3 · Project policy | Quiet |
heroku-api-key-short-bodyheroku · benign-lookalike | Must not flagT2 · Tool-corroborated | Quiet |