Skip to content
Benchmarks

redact-secret · Report · Detector

Mailchimp Marketing API keys

  • 54 fixtures
  • Format evidence: T2 · Tool-corroborated
  • Run 2026-10-07
  • Mode published · redact-secret 0.1.0-beta.14

Format evidence

  • trufflehog 3.97.4
  • gitleaks 8.30.1
  • Twin source data-center suffix by example · observed 2026-09-23 · the page states "if your API key is 0123456789abcdef0123456789abcde-us6, then the data center subdomain is us6" and that the <dc> URL prefix "corresponds to the data center for your account" — establishing a literal us<N> data-center suffix after the dash. It backs a marker twin only; the 32-byte hex body stays tool-corroborated and the positive tier is unchanged

Mailchimp's own fundamentals page (mailchimp.com/developer/marketing/docs/fundamentals/, observed 2026-09-23) states the key shape only by example — "if your API key is 0123456789abcdef0123456789abcde-us6, then the data center subdomain is us6" — and that example body is 31 hex bytes, documentation noise against both pinned tools' 32: trufflehog 3.97.4's mailchimp detector matches [0-9a-f]{32}-us[0-9]{1,2} anywhere, gitleaks 8.30.1's mailchimp-api-key rule a keyword-plus-assignment-gated [a-f0-9]{32}-us\d\d with exactly two digits. This contract adopts the one-or-two-digit range the provider's own single-digit example corroborates, so a single-digit-datacenter key is an expected gitleaks false negative. The value has a grammar (unlike twilio-auth-token's bare hex) and is scored on it, but every positive carries the same-line mailchimp keyword gitleaks and the product both require; a keyword-less key is an accepted product false negative not fixtured here, per the new-relic-license-key precedent for keyword-gated grammars. Audience/list/campaign ids are far shorter than 32 hex bytes and a bare -us<N> suffix never matches without the body. redact-secret#313 (PR #678) froze the identical grammar on the product side. Since 2026-09-24 (docs/decisions/2026-09-24-stop-asserting-provider-undecided-format-properties.md) the claim covers us<N> data-center suffixes only: whether any other literal (keyhacks admits any [0-9a-z]{2,5}, e.g. eu6) is ever issued is not stated by Mailchimp, so no scored fixture asserts silence on it. Likewise whether the body may carry g-z letters (the 2009 staff regex and keyhacks admit [0-9a-z]; both provider examples are hex) is outside the claim: the pattern claims hex bodies only and no scored fixture asserts silence on a g-z byte.

What the run recorded, by group

Detector views overlap, so their groups are never summed across detectors. Other scanners are reference values on the same inputs, in run order.
Groups of Mailchimp Marketing API keys fixtures
GroupFixturesLeaked or false alarmsNear-twinsOutcomesOther scanners, same cell
Must not flag · Tool-corroborated17False alarmsat most 18.4%0 of 17 controls flagged17 quiet · 0 flagged
  • flare-redact at most 18.4%
  • gitleaks at most 18.4%
  • trufflehog at most 34.3%
Must not flag · Project policy9False alarmsat most 29.9%0 of 9 controls flagged9 quiet · 0 flagged
  • flare-redact at most 29.9%
  • gitleaks at most 29.9%
  • trufflehog at most 29.9%
Must redact · Tool-corroborated24Secret spans left readableat most 13.8%0 of 24 spansNear-twins told apartinsufficient-coverage10 of 10 pairs24 redacted · 0 too much · 0 partly exposed · 0 missed
  • flare-redact at most 97.7%
  • gitleaks at most 44.9%
  • trufflehog at most 13.8%
Pending review4UnscoredNot scoredInspect only: never scored until evidence existsNot scored
54 of 54 rows
Fixtures
54
Left readable
0
Redacted too much
0
False alarms
0

Fixtures for this detector

54 fixtures. Choose "Every scanner" to see each scanner's outcome for the same rows.
Fixtures in Mailchimp Marketing API keys
FixtureKind and evidenceredact-secret
mailchimp-api-key-actions-envmailchimp · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
mailchimp-api-key-client-logmailchimp · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
mailchimp-api-key-compose-envmailchimp · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
mailchimp-api-key-curl-bearermailchimp · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
mailchimp-api-key-curl-usermailchimp · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
mailchimp-api-key-debug-request-headersmailchimp · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
mailchimp-api-key-envmailchimp · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
mailchimp-api-key-handoff-notemailchimp · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
mailchimp-api-key-heroku-configmailchimp · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
mailchimp-api-key-long-twinmailchimp · wrong-lengthMust not flagT2 · Tool-corroborated · twinQuiet
mailchimp-api-key-marketing-clientmailchimp · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
mailchimp-api-key-node-setconfigmailchimp · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
mailchimp-api-key-python-requests-authmailchimp · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
mailchimp-api-key-settings-jsonmailchimp · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
mailchimp-api-key-sha1-width-twinmailchimp · wrong-lengthMust not flagT2 · Tool-corroborated · twinQuiet
mailchimp-api-key-shell-exportmailchimp · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
mailchimp-api-key-single-digit-datacenter-baremailchimp · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
mailchimp-api-key-single-digit-datacenter-quotedmailchimp · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
mailchimp-api-key-single-digit-datacenter-unicode-crlfmailchimp · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
mailchimp-api-key-tfvarsmailchimp · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
mailchimp-api-key-ticket-paragraphmailchimp · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
mailchimp-api-key-two-digit-datacenter-baremailchimp · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
mailchimp-api-key-two-digit-datacenter-quotedmailchimp · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
mailchimp-api-key-two-digit-datacenter-unicode-crlfmailchimp · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
mailchimp-api-key-userinfo-urlmailchimp · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
mailchimp-api-key-v1-apikey-querymailchimp · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
mailchimp-api-key-alphabet-twinmailchimp · unsettled-evidence-inputPending reviewT0 · Pending · twinUnscored
mailchimp-api-key-audience-and-campaign-public-idmailchimp · public-identifierMust not flagT2 · Tool-corroboratedQuiet
mailchimp-api-key-datacenter-move-prosemailchimp · prose-mentionMust not flagT3 · Project policyQuiet
mailchimp-api-key-datacenter-note-prosemailchimp · prose-mentionMust not flagT3 · Project policyQuiet
mailchimp-api-key-docs-template-placeholdermailchimp · documentation-placeholderMust not flagT3 · Project policyQuiet
mailchimp-api-key-label-prosemailchimp · benign-lookalikeMust not flagT3 · Project policyQuiet
mailchimp-api-key-list-and-web-id-public-idmailchimp · public-identifierMust not flagT2 · Tool-corroboratedQuiet
mailchimp-api-key-list-webhook-url-public-idmailchimp · public-identifierMust not flagT2 · Tool-corroboratedQuiet
mailchimp-api-key-maskmailchimp · benign-lookalikeMust not flagT3 · Project policyQuiet
mailchimp-api-key-no-separator-twinmailchimp · boundary-violationMust not flagT2 · Tool-corroborated · twinQuiet
mailchimp-api-key-process-env-referencemailchimp · templated-referenceMust not flagT3 · Project policyQuiet
mailchimp-api-key-public-idmailchimp · benign-lookalikeMust not flagT2 · Tool-corroboratedQuiet
mailchimp-api-key-referencemailchimp · benign-lookalikeMust not flagT3 · Project policyQuiet
mailchimp-api-key-s3-region-key-near-missmailchimp · format-near-missMust not flagT2 · Tool-corroboratedQuiet
mailchimp-api-key-separator-twinmailchimp · boundary-violationMust not flagT2 · Tool-corroborated · twinQuiet
mailchimp-api-key-short-twinmailchimp · wrong-lengthMust not flagT2 · Tool-corroborated · twinQuiet
mailchimp-api-key-single-digit-datacenter-bare-twinmailchimp · unsettled-evidence-inputPending reviewT0 · Pending · twinUnscored
mailchimp-api-key-single-digit-datacenter-quoted-twinmailchimp · unsettled-evidence-inputPending reviewT0 · Pending · twinUnscored
mailchimp-api-key-single-digit-datacenter-unicode-crlf-twinmailchimp · unsettled-evidence-inputPending reviewT0 · Pending · twinUnscored
mailchimp-api-key-subscriber-hash-encoded-valuemailchimp · benign-encoded-valueMust not flagT2 · Tool-corroboratedQuiet
mailchimp-api-key-subscriber-hash-path-encoded-valuemailchimp · benign-encoded-valueMust not flagT2 · Tool-corroboratedQuiet
mailchimp-api-key-suffix-removed-twinmailchimp · prefix-near-missMust not flagT2 · Tool-corroborated · twinQuiet
mailchimp-api-key-two-digit-datacenter-bare-twinmailchimp · wrong-lengthMust not flagT2 · Tool-corroborated · twinQuiet
mailchimp-api-key-two-digit-datacenter-quoted-twinmailchimp · wrong-lengthMust not flagT2 · Tool-corroborated · twinQuiet