Skip to content
Benchmarks

redact-secret · Report · Detector

Netlify personal access tokens

  • 24 fixtures
  • Format evidence: T1 · Provider-documented
  • Run 2026-10-07
  • Mode published · redact-secret 0.1.0-beta.14

Format evidence

  • Provider documentation 2023-11-07 nf-prefixed token format · observed 2026-09-23 · Netlify's staff-authored announcement states "All Netlify authentication tokens will start with a nf prefix followed by a single identifying character" — nfp for personal access tokens (nfc/nfo/nfu/nfb for CLI, OAuth, app and build tokens) — and that token storage capacity must grow "to 40 characters"; the "_" delimiter and the [A-Za-z0-9_] body alphabet are tool-corroborated, not stated on the page
  • trufflehog 3.97.4
  • gitleaks 8.30.1

Netlify's API guide (docs.netlify.com/api-and-cli-guides/api-guides/get-started-with-api/) documents only how a personal access token is created and sent as a Bearer header; the prefix and 40-character total come from the provider's own token-format announcement, hosted on answers.netlify.com and written by Netlify staff. trufflehog 3.97.4's netlify/v2 detector pins exactly `\b(nfp_[a-zA-Z0-9_]{36})\b`, but only after a `netlify` keyword (PrefixRegex); gitleaks 8.30.1's netlify-access-token rule fixes no prefix at all — a keyword-plus-assignment-gated 40–46-byte body over [a-z0-9=_\-], matched case-insensitively — so it corroborates only that a 40-byte nfp_ token in a netlify assignment is recognized, never the prefix. This contract, like the product, needs no keyword: the provider-documented prefix and exact length are self-identifying, so a bare token is a positive here and an expected false negative for both peers; the keyword-context positive records what each peer does when the keyword is present. The announcement itself states pre-2023-11 unprefixed tokens "will be unaffected"; that legacy shape (trufflehog's keyword-gated netlify/v1, gitleaks's keyword-gated 40–46-byte body) is shared by every pre-change Netlify token class, so it has no contract here, and the other four prefixed classes (nfc_/nfo_/nfu_/nfb_) are separate credentials outside this personal-access-token family. Build-hook URLs and site/account/deploy ids are out of scope. redact-secret#311 (PR #666) froze the identical grammar on the product side.

What the run recorded, by group

Detector views overlap, so their groups are never summed across detectors. Other scanners are reference values on the same inputs, in run order.
Groups of Netlify personal access tokens fixtures
GroupFixturesLeaked or false alarmsNear-twinsOutcomesOther scanners, same cell
Must not flag · Tool-corroborated10False alarmsat most 27.8%0 of 10 controls flagged10 quiet · 0 flagged
  • flare-redact at most 27.8%
  • gitleaks at most 27.8%
  • trufflehog at most 27.8%
Must not flag · Project policy4False alarmsinsufficient-evidence0 of 4 controls flagged4 quiet · 0 flagged
  • flare-redact insufficient-evidence
  • gitleaks insufficient-evidence
  • trufflehog insufficient-evidence
Must redact · Provider-documented10Secret spans left readableat most 27.8%0 of 10 spansNear-twins told apartat least 61.0%6 of 6 pairs10 redacted · 0 too much · 0 partly exposed · 0 missed
  • flare-redact at most 83.2%
  • gitleaks at most 83.2%
  • trufflehog at most 68.7%
24 of 24 rows
Fixtures
24
Left readable
0
Redacted too much
0
False alarms
0

Fixtures for this detector

24 fixtures. Choose "Every scanner" to see each scanner's outcome for the same rows.
Fixtures in Netlify personal access tokens
FixtureKind and evidenceredact-secret
netlify-token-api-bearer-headernetlify · documented-format-literalMust redactT1 · Provider-documentedRedacted
netlify-token-js-api-clientnetlify · documented-format-literalMust redactT1 · Provider-documentedRedacted
netlify-token-keyword-context-barenetlify · documented-format-literalMust redactT1 · Provider-documentedRedacted
netlify-token-keyword-context-quotednetlify · documented-format-literalMust redactT1 · Provider-documentedRedacted
netlify-token-keyword-context-unicode-crlfnetlify · documented-format-literalMust redactT1 · Provider-documentedRedacted
netlify-token-netlify-deploy-auth-flagnetlify · documented-format-literalMust redactT1 · Provider-documentedRedacted
netlify-token-pat-shape-barenetlify · documented-format-literalMust redactT1 · Provider-documentedRedacted
netlify-token-pat-shape-quotednetlify · documented-format-literalMust redactT1 · Provider-documentedRedacted
netlify-token-pat-shape-unicode-crlfnetlify · documented-format-literalMust redactT1 · Provider-documentedRedacted
netlify-token-deploy-digest-encoded-valuenetlify · benign-encoded-valueMust not flagT2 · Tool-corroboratedQuiet
netlify-token-github-actions-deploynetlify · documented-format-literalMust redactT1 · Provider-documentedRedacted
netlify-token-label-prosenetlify · benign-lookalikeMust not flagT3 · Project policyQuiet
netlify-token-masknetlify · benign-lookalikeMust not flagT3 · Project policyQuiet
netlify-token-pat-shape-bare-twinnetlify · wrong-lengthMust not flagT2 · Tool-corroborated · twinQuiet
netlify-token-pat-shape-prefix-bare-twinnetlify · prefix-near-missMust not flagT2 · Tool-corroborated · twinQuiet
netlify-token-pat-shape-prefix-quoted-twinnetlify · prefix-near-missMust not flagT2 · Tool-corroborated · twinQuiet
netlify-token-pat-shape-prefix-unicode-crlf-twinnetlify · prefix-near-missMust not flagT2 · Tool-corroborated · twinQuiet
netlify-token-pat-shape-quoted-twinnetlify · wrong-lengthMust not flagT2 · Tool-corroborated · twinQuiet
netlify-token-pat-shape-unicode-crlf-twinnetlify · wrong-lengthMust not flagT2 · Tool-corroborated · twinQuiet
netlify-token-prefix-onlynetlify · benign-lookalikeMust not flagT2 · Tool-corroboratedQuiet
netlify-token-public-idnetlify · benign-lookalikeMust not flagT2 · Tool-corroboratedQuiet
netlify-token-referencenetlify · benign-lookalikeMust not flagT3 · Project policyQuiet
netlify-token-short-bodynetlify · benign-lookalikeMust not flagT2 · Tool-corroboratedQuiet
netlify-token-token-format-note-prosenetlify · prose-mentionMust not flagT3 · Project policyQuiet