redact-secret · Report · Detector
Hugging Face tokens
Format evidence
- Provider documentation @huggingface/hub SDK reference AccessToken type (hf_${string}) · observed 2026-09-23 · Hugging Face's SDK reference on huggingface.co types the user access token as hf_${string}, establishing the hf_ prefix; the provider's Hub OpenAPI spec (/.well-known/openapi.json, POST /api/credentials/revoke) gives a raw access-token example of hf_ followed by 34 placeholder characters, which establishes the 34-character body length on example strength only. The [A-Za-z0-9] body alphabet is not provider-stated and remains a support-policy union of the tool alphabets (gitleaks letters only, TruffleHog alphanumeric); the api_org_ variant is not covered by this provider source
- trufflehog 3.97.4
- gitleaks 8.30.1
- Reference 1
Re-tiered 2026-09-23 (#112, provider evidence redact-secret#654). The prefix source is a TypeScript type annotation rendered in the provider's SDK reference on huggingface.co, not a prose paragraph; accepting an SDK-reference source for the prefix is a maintainer ruling, on the same footing as the google-api-key example precedent, not a change to the T1 bar. The 34-character length rests on a single OpenAPI example whose placeholder is one repeated letter (schema bounds are only minLength 1 / maxLength 200), so it is example-strength, and the example says nothing about the alphabet. Re-verified 2026-09-20 (#45) against the pinned source: TruffleHog's huggingface detector matches `\b(?:hf_|api_org_)[a-zA-Z0-9]{34}\b`, alphanumeric; gitleaks's huggingface-access-token rule matches `\b(hf_(?i:[a-z]{34}))...`, letters-only, so gitleaks would not flag a digit-bearing instance. A retired provider-hosted Space validator used hf_[a-zA-Z0-9]{34}, but that is application code, not documentation. api_org_ stays outside this contract's pattern: only a 2021 archived provider page shows an api_org_ placeholder, and the current SDK rejects org tokens. The provider also documents hf_oauth_/hf_jwt_ tokens in the same hf_ namespace; they are uncovered here, so no delimiter twin is authored (a post-prefix "_" is not provably non-Hugging Face).
What the run recorded, by group
| Group | Fixtures | Leaked or false alarms | Near-twins | Outcomes | Other scanners, same cell |
|---|---|---|---|---|---|
| Must not flag · Tool-corroborated | 13 | False alarmsat most 22.8%0 of 13 controls flagged | 13 quiet · 0 flagged |
| |
| Must not flag · Project policy | 2 | False alarmsinsufficient-evidence0 of 2 controls flagged | 2 quiet · 0 flagged |
| |
| Must redact · Provider-documented | 11 | Secret spans left readableat most 25.9%0 of 11 spans | Near-twins told apartat least 64.6%7 of 7 pairs | 11 redacted · 0 too much · 0 partly exposed · 0 missed |
|
- Fixtures
- 26
- Left readable
- 0
- Redacted too much
- 0
- False alarms
- 0
Fixtures for this detector
| Fixture | Kind and evidence | redact-secret |
|---|---|---|
huggingface-token-dash-identifier-embeddinghuggingface · benign-lookalike | Must not flagT2 · Tool-corroborated | Quiet |
huggingface-token-hf-auth-loginhuggingface · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
huggingface-token-inference-bearer-headerhuggingface · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
huggingface-token-shape-1-barehuggingface · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
huggingface-token-shape-1-quotedhuggingface · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
huggingface-token-shape-1-unicode-crlfhuggingface · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
huggingface-token-user-plain-twinhuggingface · wrong-length | Must not flagT2 · Tool-corroborated · twin | Quiet |
huggingface-token-user-unicode-crlf-twinhuggingface · wrong-length | Must not flagT2 · Tool-corroborated · twin | Quiet |
huggingface-token-actions-sync-to-hubhuggingface · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
huggingface-token-hf-token-envhuggingface · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
huggingface-token-inference-clienthuggingface · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
huggingface-token-leading-identifier-embeddinghuggingface · benign-lookalike | Must not flagT2 · Tool-corroborated | Quiet |
huggingface-token-maskhuggingface · benign-lookalike | Must not flagT3 · Project policy | Quiet |
huggingface-token-model-repo-and-revision-public-idhuggingface · public-identifier | Must not flagT2 · Tool-corroborated | Quiet |
huggingface-token-prefix-onlyhuggingface · benign-lookalike | Must not flagT2 · Tool-corroborated | Quiet |
huggingface-token-referencehuggingface · benign-lookalike | Must not flagT3 · Project policy | Quiet |
huggingface-token-shape-1-prefix-bare-twinhuggingface · prefix-near-miss | Must not flagT2 · Tool-corroborated · twin | Quiet |
huggingface-token-shape-1-prefix-quoted-twinhuggingface · prefix-near-miss | Must not flagT2 · Tool-corroborated · twin | Quiet |
huggingface-token-shape-1-prefix-unicode-crlf-twinhuggingface · prefix-near-miss | Must not flagT2 · Tool-corroborated · twin | Quiet |
huggingface-token-short-bodyhuggingface · benign-lookalike | Must not flagT2 · Tool-corroborated | Quiet |
huggingface-token-stored-tokens-inihuggingface · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
huggingface-token-trailing-identifier-embeddinghuggingface · benign-lookalike | Must not flagT2 · Tool-corroborated | Quiet |
huggingface-token-user-plainhuggingface · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
huggingface-token-user-prefix-plain-twinhuggingface · prefix-near-miss | Must not flagT2 · Tool-corroborated · twin | Quiet |
huggingface-token-user-prefix-unicode-crlf-twinhuggingface · prefix-near-miss | Must not flagT2 · Tool-corroborated · twin | Quiet |
huggingface-token-user-unicode-crlfhuggingface · documented-format-literal | Must redactT1 · Provider-documented | Redacted |