redact-secret · Report · Detector
Honeycomb API keys
Format evidence
- Provider documentation Honeycomb docs "Authentication": ingest key ids carry hc[x]ik_, "The character shown as [x] varies and is assigned at key creation", and "The key value is the Key ID and Secret concatenated with no separator" (58-byte placeholder body); honeycombio/libhoney-go libhoney.go (02e9dbf, 2026-04-14): classicIngestKeyRegex ^hc[a-z]ic_[a-z0-9]*$ applied when len(key) == 64, with 64-byte hcxik_/hcxic_ fixtures; honeycombio/libhoney-py client.py (11b5941): ^hc[a-z]ic_[a-z0-9]{58}$; re-checked 2026-09-29 · observed 2026-09-29 · hc + one [a-z] + ik_ (environment) or ic_ (classic) + exactly 58 [a-z0-9], 64 in all
- Reference 1
- Reference 2
- Reference 3
- Reference 4
- Reference 5
- Reference 6
- Reference 7
- Reference 8
- Reference 9
- Reference 10
- Reference 11
- Reference 12
- Reference 13
Arrival evidence (#528, product redact-secret#1034; #1014 handoff honeycomb.md, READY for ingest keys). An ingest key sends telemetry into an environment; a leak lets anyone write or spoof events and burn the quota, and ingest keys are routinely pasted into OpenTelemetry collector configs. T1: the prefix and the id-plus-secret concatenation are the docs; the 58-byte body is the docs placeholder, the libhoney-go 64-byte gate and its fixtures (R5); the alphabet is the SDK fixtures (R5) and the classic regex in two provider SDKs (R1). The whole 64 bytes are the span. Excluded: key ids alone (hc?ik_/hc?mk_ + 26, and hc?lk_ and hc?en_ ids; non-secret, shown in the UI and API), 22-character configuration keys and 32-hex classic keys (no distinctive shape; credentials that generic context covers, so authored neither way) and the management key (ISSUANCE-GATED on the alphabet of both segments; authored neither way). Neither pinned peer reads this shape: trufflehog 3.97.4 Honeycomb wants a 32-hex or 22-alphanumeric value near the keyword Honeycomb (classic and configuration keys), and gitleaks 8.30.1 has no rule. Graduated to a registry detector at the 4fb7882 re-pin (redact-secret PR #1039).
What the run recorded, by group
| Group | Fixtures | Leaked or false alarms | Near-twins | Outcomes | Other scanners, same cell |
|---|---|---|---|---|---|
| Must not flag · Tool-corroborated | 15 | False alarmsat most 20.4%0 of 15 controls flagged | 15 quiet · 0 flagged |
| |
| Must not flag · Project policy | 8 | False alarmsat most 32.4%0 of 8 controls flagged | 8 quiet · 0 flagged |
| |
| Must redact · Provider-documented | 16 | Secret spans left readableat most 19.4%0 of 16 spans | Near-twins told apartat least 70.1%9 of 9 pairs | 16 redacted · 0 too much · 0 partly exposed · 0 missed |
|
- Fixtures
- 39
- Left readable
- 0
- Redacted too much
- 0
- False alarms
- 0
Fixtures for this detector
| Fixture | Kind and evidence | redact-secret |
|---|---|---|
honeycomb-api-key-bare-prosehoneycomb · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
honeycomb-api-key-bearer-headerhoneycomb · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
honeycomb-api-key-chat-pastehoneycomb · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
honeycomb-api-key-collector-headershoneycomb · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
honeycomb-api-key-dotenvhoneycomb · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
honeycomb-api-key-exporthoneycomb · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
honeycomb-api-key-json-api-keyhoneycomb · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
honeycomb-api-key-json-tokenhoneycomb · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
honeycomb-api-key-key-shape-barehoneycomb · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
honeycomb-api-key-key-shape-quotedhoneycomb · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
honeycomb-api-key-key-shape-unicode-crlfhoneycomb · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
honeycomb-api-key-libhoney-go-confighoneycomb · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
honeycomb-api-key-otel-env-headershoneycomb · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
honeycomb-api-key-sdk-kwarghoneycomb · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
honeycomb-api-key-x-api-key-headerhoneycomb · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
honeycomb-api-key-x-honeycomb-team-headerhoneycomb · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
honeycomb-api-key-actions-secret-referencehoneycomb · templated-reference | Must not flagT3 · Project policy | Quiet |
honeycomb-api-key-angle-brackets-placeholderhoneycomb · documentation-placeholder | Must not flagT3 · Project policy | Quiet |
honeycomb-api-key-body-57-twinhoneycomb · wrong-length | Must not flagT2 · Tool-corroborated · twin | Quiet |
honeycomb-api-key-body-59-twinhoneycomb · wrong-length | Must not flagT2 · Tool-corroborated · twin | Quiet |
honeycomb-api-key-configuration-key-id-public-idhoneycomb · public-identifier | Must not flagT2 · Tool-corroborated | Quiet |
honeycomb-api-key-ellipsis-placeholderhoneycomb · documentation-placeholder | Must not flagT3 · Project policy | Quiet |
honeycomb-api-key-env-reference-referencehoneycomb · templated-reference | Must not flagT3 · Project policy | Quiet |
honeycomb-api-key-environment-id-public-idhoneycomb · public-identifier | Must not flagT2 · Tool-corroborated | Quiet |
honeycomb-api-key-hyphen-in-body-twinhoneycomb · wrong-alphabet | Must not flagT2 · Tool-corroborated · twin | Quiet |
honeycomb-api-key-ingest-key-id-public-idhoneycomb · public-identifier | Must not flagT2 · Tool-corroborated | Quiet |
honeycomb-api-key-key-guidance-prosehoneycomb · prose-mention | Must not flagT3 · Project policy | Quiet |
honeycomb-api-key-label-prosehoneycomb · benign-lookalike | Must not flagT3 · Project policy | Quiet |
honeycomb-api-key-leading-glue-twinhoneycomb · boundary-violation | Must not flagT2 · Tool-corroborated · twin | Quiet |
honeycomb-api-key-management-prefix-twinhoneycomb · prefix-near-miss | Must not flagT2 · Tool-corroborated · twin | Quiet |
honeycomb-api-key-maskhoneycomb · benign-lookalike | Must not flagT3 · Project policy | Quiet |
honeycomb-api-key-no-type-letter-twinhoneycomb · prefix-near-miss | Must not flagT2 · Tool-corroborated · twin | Quiet |
honeycomb-api-key-prefix-onlyhoneycomb · benign-lookalike | Must not flagT2 · Tool-corroborated | Quiet |
honeycomb-api-key-referencehoneycomb · benign-lookalike | Must not flagT3 · Project policy | Quiet |
honeycomb-api-key-short-bodyhoneycomb · benign-lookalike | Must not flagT2 · Tool-corroborated | Quiet |
honeycomb-api-key-trailing-underscore-twinhoneycomb · boundary-violation | Must not flagT2 · Tool-corroborated · twin | Quiet |
honeycomb-api-key-truncated-near-misshoneycomb · format-near-miss | Must not flagT2 · Tool-corroborated | Quiet |
honeycomb-api-key-uppercase-byte-twinhoneycomb · wrong-alphabet | Must not flagT2 · Tool-corroborated · twin | Quiet |
honeycomb-api-key-uppercase-type-letter-twinhoneycomb · prefix-near-miss | Must not flagT2 · Tool-corroborated · twin | Quiet |