Skip to content
Benchmarks

redact-secret · Report · Detector

Mailgun API and HTTP signing keys

  • 43 fixtures
  • Format evidence: T2 · Tool-corroborated
  • Run 2026-10-07
  • Mode published · redact-secret 0.1.0-beta.14

Format evidence

Mailgun's own "Create a key" API reference (documentation.mailgun.com/docs/mailgun/api-reference/send/mailgun/keys/post-v1-keys, observed 2026-09-23) shows the created secret only as the placeholder "api-key-be-careful" and states no prefix, length or alphabet. Both pinned tools agree on a literal key- and a 32-byte body: gitleaks 8.30.1's mailgun-private-api-token rule (keyword- and assignment-gated) pins key-[a-f0-9]{32}, trufflehog 3.97.4's mailgun "Key-MailGun Token" pattern `\b(key-[a-z0-9]{32})\b` the wider lowercase-alphanumeric body with no keyword. This contract adopts trufflehog's wider alphabet, the reading the product froze from an independently observed real key whose body carries non-hex letters (redact-secret#314, PR #680), so a hex-only-alphabet twin is not constructible and gitleaks is an expected false negative on any body byte in g–z. The product's module doc cites Mailgun's account-management reference (GET/POST /v5/accounts/http_signing_key) as showing the identical key- + 32-byte shape for the HTTP webhook signing key; that page could not be re-fetched from this environment (its rendered reference returns 404 to a plain fetch), so the signing-key positive here rests on the product's citation plus the same tool corroboration, and no providerSource or twinSource is claimed. The superseded 32-8-8 hex triplet both tools still call a Mailgun signing key (gitleaks mailgun-signing-key; trufflehog "Hex MailGun Token") and trufflehog's 72-byte "Original MailGun Token" are known unsupported legacy variants with no contract. pubkey- (the public validation key gitleaks's mailgun-pub-key rule targets) is documented public and is the family's public-identifier control. Every positive carries the same-line mailgun keyword the product's Medium-confidence gate and gitleaks's rule require; a keyword-less key is an accepted product false negative not fixtured here, per the mailchimp-api-key precedent. Since 2026-09-24 (docs/decisions/2026-09-24-stop-asserting-provider-undecided-format-properties.md) whether a key- body may carry an uppercase letter is outside the claim: gitleaks and Nosey Parker are case-insensitive, trufflehog is not, no Mailgun source decides it, and no scored fixture asserts it either way.

What the run recorded, by group

Detector views overlap, so their groups are never summed across detectors. Other scanners are reference values on the same inputs, in run order.
Groups of Mailgun API and HTTP signing keys fixtures
GroupFixturesLeaked or false alarmsNear-twinsOutcomesOther scanners, same cell
Must not flag · Tool-corroborated16False alarmsat most 19.4%0 of 16 controls flagged16 quiet · 0 flagged
  • flare-redact at most 19.4%
  • gitleaks at most 19.4%
  • trufflehog at most 19.4%
Must not flag · Project policy8False alarmsat most 32.4%0 of 8 controls flagged8 quiet · 0 flagged
  • flare-redact at most 32.4%
  • gitleaks at most 47.1%
  • trufflehog at most 32.4%
Must redact · Tool-corroborated16Secret spans left readableat most 19.4%0 of 16 spansNear-twins told apartat least 67.6%8 of 8 pairs16 redacted · 0 too much · 0 partly exposed · 0 missed
  • flare-redact at most 100.0%
  • gitleaks at most 19.4%
  • trufflehog at most 19.4%
Pending review3UnscoredNot scoredInspect only: never scored until evidence existsNot scored
43 of 43 rows
Fixtures
43
Left readable
0
Redacted too much
0
False alarms
0

Fixtures for this detector

43 fixtures. Choose "Every scanner" to see each scanner's outcome for the same rows.
Fixtures in Mailgun API and HTTP signing keys
FixtureKind and evidenceredact-secret
mailgun-api-key-actions-envmailgun · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
mailgun-api-key-anymail-settingsmailgun · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
mailgun-api-key-compose-envmailgun · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
mailgun-api-key-curl-usermailgun · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
mailgun-api-key-debug-logmailgun · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
mailgun-api-key-docs-template-placeholdermailgun · documentation-placeholderMust not flagT3 · Project policyQuiet
mailgun-api-key-envmailgun · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
mailgun-api-key-heroku-configmailgun · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
mailgun-api-key-http-signing-key-baremailgun · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
mailgun-api-key-http-signing-key-quotedmailgun · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
mailgun-api-key-http-signing-key-unicode-crlfmailgun · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
mailgun-api-key-node-clientmailgun · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
mailgun-api-key-private-api-key-baremailgun · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
mailgun-api-key-private-api-key-quotedmailgun · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
mailgun-api-key-private-api-key-unicode-crlfmailgun · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
mailgun-api-key-settings-jsonmailgun · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
mailgun-api-key-shell-exportmailgun · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
mailgun-api-key-actions-secret-referencemailgun · templated-referenceMust not flagT3 · Project policyQuiet
mailgun-api-key-compose-delimiter-twinmailgun · boundary-violationMust not flagT2 · Tool-corroborated · twinQuiet
mailgun-api-key-compose-long-twinmailgun · wrong-lengthMust not flagT2 · Tool-corroborated · twinQuiet
mailgun-api-key-django-env-referencemailgun · templated-referenceMust not flagT3 · Project policyQuiet
mailgun-api-key-domain-and-message-id-public-idmailgun · public-identifierMust not flagT2 · Tool-corroboratedQuiet
mailgun-api-key-key-types-note-prosemailgun · prose-mentionMust not flagT3 · Project policyQuiet
mailgun-api-key-label-prosemailgun · benign-lookalikeMust not flagT3 · Project policyQuiet
mailgun-api-key-maskmailgun · benign-lookalikeMust not flagT3 · Project policyQuiet
mailgun-api-key-masked-dashboard-placeholdermailgun · documentation-placeholderMust not flagT3 · Project policyQuiet
mailgun-api-key-package-checksum-encoded-valuemailgun · benign-encoded-valueMust not flagT2 · Tool-corroboratedQuiet
mailgun-api-key-prefix-onlymailgun · benign-lookalikeMust not flagT2 · Tool-corroboratedQuiet
mailgun-api-key-private-api-key-alphabet-bare-twinmailgun · unsettled-evidence-inputPending reviewT0 · Pending · twinUnscored
mailgun-api-key-private-api-key-alphabet-quoted-twinmailgun · unsettled-evidence-inputPending reviewT0 · Pending · twinUnscored
mailgun-api-key-private-api-key-alphabet-unicode-crlf-twinmailgun · unsettled-evidence-inputPending reviewT0 · Pending · twinUnscored
mailgun-api-key-private-api-key-bare-twinmailgun · wrong-lengthMust not flagT2 · Tool-corroborated · twinQuiet
mailgun-api-key-private-api-key-prefix-bare-twinmailgun · prefix-near-missMust not flagT2 · Tool-corroborated · twinQuiet
mailgun-api-key-private-api-key-prefix-quoted-twinmailgun · prefix-near-missMust not flagT2 · Tool-corroborated · twinQuiet
mailgun-api-key-private-api-key-prefix-unicode-crlf-twinmailgun · prefix-near-missMust not flagT2 · Tool-corroborated · twinQuiet
mailgun-api-key-private-api-key-quoted-twinmailgun · wrong-lengthMust not flagT2 · Tool-corroborated · twinQuiet
mailgun-api-key-private-api-key-unicode-crlf-twinmailgun · wrong-lengthMust not flagT2 · Tool-corroborated · twinQuiet
mailgun-api-key-public-idmailgun · benign-lookalikeMust not flagT2 · Tool-corroboratedQuiet
mailgun-api-key-public-validation-key-public-idmailgun · public-identifierMust not flagT2 · Tool-corroboratedQuiet
mailgun-api-key-referencemailgun · benign-lookalikeMust not flagT3 · Project policyQuiet
mailgun-api-key-setting-name-near-missmailgun · format-near-missMust not flagT2 · Tool-corroboratedQuiet
mailgun-api-key-short-body-in-log-near-missmailgun · format-near-missMust not flagT2 · Tool-corroboratedQuiet
mailgun-api-key-short-body-in-prose-near-missmailgun · format-near-missMust not flagT2 · Tool-corroboratedQuiet