redact-secret · Report · Detector
Netlify personal access tokens
Format evidence
- Provider documentation 2023-11-07 nf-prefixed token format · observed 2026-09-23 · Netlify's staff-authored announcement states "All Netlify authentication tokens will start with a nf prefix followed by a single identifying character" — nfp for personal access tokens (nfc/nfo/nfu/nfb for CLI, OAuth, app and build tokens) — and that token storage capacity must grow "to 40 characters"; the "_" delimiter and the [A-Za-z0-9_] body alphabet are tool-corroborated, not stated on the page
- trufflehog 3.97.4
- gitleaks 8.30.1
Netlify's API guide (docs.netlify.com/api-and-cli-guides/api-guides/get-started-with-api/) documents only how a personal access token is created and sent as a Bearer header; the prefix and 40-character total come from the provider's own token-format announcement, hosted on answers.netlify.com and written by Netlify staff. trufflehog 3.97.4's netlify/v2 detector pins exactly `\b(nfp_[a-zA-Z0-9_]{36})\b`, but only after a `netlify` keyword (PrefixRegex); gitleaks 8.30.1's netlify-access-token rule fixes no prefix at all — a keyword-plus-assignment-gated 40–46-byte body over [a-z0-9=_\-], matched case-insensitively — so it corroborates only that a 40-byte nfp_ token in a netlify assignment is recognized, never the prefix. This contract, like the product, needs no keyword: the provider-documented prefix and exact length are self-identifying, so a bare token is a positive here and an expected false negative for both peers; the keyword-context positive records what each peer does when the keyword is present. The announcement itself states pre-2023-11 unprefixed tokens "will be unaffected"; that legacy shape (trufflehog's keyword-gated netlify/v1, gitleaks's keyword-gated 40–46-byte body) is shared by every pre-change Netlify token class, so it has no contract here, and the other four prefixed classes (nfc_/nfo_/nfu_/nfb_) are separate credentials outside this personal-access-token family. Build-hook URLs and site/account/deploy ids are out of scope. redact-secret#311 (PR #666) froze the identical grammar on the product side.
What the run recorded, by group
| Group | Fixtures | Leaked or false alarms | Near-twins | Outcomes | Other scanners, same cell |
|---|---|---|---|---|---|
| Must not flag · Tool-corroborated | 10 | False alarmsat most 27.8%0 of 10 controls flagged | 10 quiet · 0 flagged |
| |
| Must not flag · Project policy | 4 | False alarmsinsufficient-evidence0 of 4 controls flagged | 4 quiet · 0 flagged |
| |
| Must redact · Provider-documented | 10 | Secret spans left readableat most 27.8%0 of 10 spans | Near-twins told apartat least 61.0%6 of 6 pairs | 10 redacted · 0 too much · 0 partly exposed · 0 missed |
|
- Fixtures
- 24
- Left readable
- 0
- Redacted too much
- 0
- False alarms
- 0
Fixtures for this detector
| Fixture | Kind and evidence | redact-secret |
|---|---|---|
netlify-token-api-bearer-headernetlify · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
netlify-token-js-api-clientnetlify · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
netlify-token-keyword-context-barenetlify · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
netlify-token-keyword-context-quotednetlify · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
netlify-token-keyword-context-unicode-crlfnetlify · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
netlify-token-netlify-deploy-auth-flagnetlify · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
netlify-token-pat-shape-barenetlify · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
netlify-token-pat-shape-quotednetlify · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
netlify-token-pat-shape-unicode-crlfnetlify · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
netlify-token-deploy-digest-encoded-valuenetlify · benign-encoded-value | Must not flagT2 · Tool-corroborated | Quiet |
netlify-token-github-actions-deploynetlify · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
netlify-token-label-prosenetlify · benign-lookalike | Must not flagT3 · Project policy | Quiet |
netlify-token-masknetlify · benign-lookalike | Must not flagT3 · Project policy | Quiet |
netlify-token-pat-shape-bare-twinnetlify · wrong-length | Must not flagT2 · Tool-corroborated · twin | Quiet |
netlify-token-pat-shape-prefix-bare-twinnetlify · prefix-near-miss | Must not flagT2 · Tool-corroborated · twin | Quiet |
netlify-token-pat-shape-prefix-quoted-twinnetlify · prefix-near-miss | Must not flagT2 · Tool-corroborated · twin | Quiet |
netlify-token-pat-shape-prefix-unicode-crlf-twinnetlify · prefix-near-miss | Must not flagT2 · Tool-corroborated · twin | Quiet |
netlify-token-pat-shape-quoted-twinnetlify · wrong-length | Must not flagT2 · Tool-corroborated · twin | Quiet |
netlify-token-pat-shape-unicode-crlf-twinnetlify · wrong-length | Must not flagT2 · Tool-corroborated · twin | Quiet |
netlify-token-prefix-onlynetlify · benign-lookalike | Must not flagT2 · Tool-corroborated | Quiet |
netlify-token-public-idnetlify · benign-lookalike | Must not flagT2 · Tool-corroborated | Quiet |
netlify-token-referencenetlify · benign-lookalike | Must not flagT3 · Project policy | Quiet |
netlify-token-short-bodynetlify · benign-lookalike | Must not flagT2 · Tool-corroborated | Quiet |
netlify-token-token-format-note-prosenetlify · prose-mention | Must not flagT3 · Project policy | Quiet |