Skip to content
Benchmarks

redact-secret · Report · Detector

Okta API tokens

  • 40 fixtures
  • Format evidence: T2 · Tool-corroborated
  • Run 2026-10-07
  • Mode published · redact-secret 0.1.0-beta.14

Format evidence

  • gitleaks 8.30.1
  • trufflehog 3.97.4
  • Twin source SSWS authorization example · observed 2026-09-23 · the guide states "Authorization: SSWS 00QCjAl4MlV-WPXM...0HmjFx-vbGua", establishing the SSWS scheme and a value that begins with the literal 00. It backs a prefix twin only; the 40-byte body length and its alphabet stay tool-corroborated and the positive tier is unchanged

Okta's own "Create an API token" guide (developer.okta.com/docs/guides/create-an-api-token/main/, observed 2026-09-23) shows the token only in use — `Authorization: SSWS 00QCjAl4MlV-WPXM...0HmjFx-vbGua` — a provider-unique SSWS scheme and a value beginning 00, elided in the middle, with no stated length or alphabet. Both pinned tools pin the 00 prefix and a 40-byte body (42 bytes total): gitleaks 8.30.1's okta-access-token rule captures `00[\w=\-]{40}` after an okta keyword and an assignment operator, trufflehog 3.97.4's okta detector `\b00[a-zA-Z0-9_-]{40}\b` only when the same input also carries an Okta tenant domain (`*.okta.com`, `*.oktapreview.com`, `*.okta-emea.com`). They disagree only on "=" in the body; this contract, like the product, adopts trufflehog's narrower [A-Za-z0-9_-], so a body containing "=" is an intentional false negative and the family's alphabet twin records gitleaks's wider reading. A bare 00-prefixed value is not self-identifying: every positive here sits in one of the two contexts the product's gate recognizes — the SSWS authorization header (High) or a same-line okta keyword (Medium) — and a context-less value is an accepted product false negative not fixtured here. Tenant domains and OAuth client ids are the family's public-identifier control; Okta's JWT-shaped OAuth tokens belong to the jwt contract. redact-secret#315 (PR #681) froze the identical grammar on the product side.

What the run recorded, by group

Detector views overlap, so their groups are never summed across detectors. Other scanners are reference values on the same inputs, in run order.
Groups of Okta API tokens fixtures
GroupFixturesLeaked or false alarmsNear-twinsOutcomesOther scanners, same cell
Must not flag · Tool-corroborated16False alarmsat most 19.4%0 of 16 controls flagged16 quiet · 0 flagged
  • flare-redact at most 19.4%
  • gitleaks at most 43.0%
  • trufflehog at most 19.4%
Must not flag · Project policy8False alarmsat most 32.4%0 of 8 controls flagged8 quiet · 0 flagged
  • flare-redact at most 32.4%
  • gitleaks at most 32.4%
  • trufflehog at most 32.4%
Must redact · Tool-corroborated16Secret spans left readableat most 19.4%0 of 16 spansNear-twins told apartat least 70.1%9 of 9 pairs16 redacted · 0 too much · 0 partly exposed · 0 missed
  • flare-redact at most 100.0%
  • gitleaks at most 61.4%
  • trufflehog at most 89.8%
40 of 40 rows
Fixtures
40
Left readable
0
Redacted too much
0
False alarms
0

Fixtures for this detector

40 fixtures. Choose "Every scanner" to see each scanner's outcome for the same rows.
Fixtures in Okta API tokens
FixtureKind and evidenceredact-secret
okta-api-token-actions-envokta · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
okta-api-token-compose-envokta · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
okta-api-token-curl-sswsokta · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
okta-api-token-envokta · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
okta-api-token-keyword-context-bareokta · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
okta-api-token-keyword-context-bare-twinokta · wrong-alphabetMust not flagT2 · Tool-corroborated · twinQuiet
okta-api-token-keyword-context-quotedokta · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
okta-api-token-keyword-context-quoted-twinokta · wrong-alphabetMust not flagT2 · Tool-corroborated · twinQuiet
okta-api-token-keyword-context-unicode-crlfokta · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
okta-api-token-keyword-context-unicode-crlf-twinokta · wrong-alphabetMust not flagT2 · Tool-corroborated · twinQuiet
okta-api-token-node-clientokta · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
okta-api-token-raw-requestokta · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
okta-api-token-request-logokta · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
okta-api-token-settings-jsonokta · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
okta-api-token-shell-exportokta · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
okta-api-token-ssws-header-bareokta · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
okta-api-token-ssws-header-quotedokta · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
okta-api-token-ssws-header-unicode-crlfokta · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
okta-api-token-tfvarsokta · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
okta-api-token-actions-secret-referenceokta · templated-referenceMust not flagT3 · Project policyQuiet
okta-api-token-api-token-listing-public-idokta · public-identifierMust not flagT2 · Tool-corroboratedQuiet
okta-api-token-cli-checksum-encoded-valueokta · benign-encoded-valueMust not flagT2 · Tool-corroboratedQuiet
okta-api-token-docs-template-placeholderokta · documentation-placeholderMust not flagT3 · Project policyQuiet
okta-api-token-label-proseokta · benign-lookalikeMust not flagT3 · Project policyQuiet
okta-api-token-maskokta · benign-lookalikeMust not flagT3 · Project policyQuiet
okta-api-token-masked-console-placeholderokta · documentation-placeholderMust not flagT3 · Project policyQuiet
okta-api-token-postman-variable-referenceokta · templated-referenceMust not flagT3 · Project policyQuiet
okta-api-token-prefix-onlyokta · benign-lookalikeMust not flagT2 · Tool-corroboratedQuiet
okta-api-token-public-idokta · benign-lookalikeMust not flagT2 · Tool-corroboratedQuiet
okta-api-token-referenceokta · benign-lookalikeMust not flagT3 · Project policyQuiet
okta-api-token-rotation-note-proseokta · prose-mentionMust not flagT3 · Project policyQuiet
okta-api-token-short-bodyokta · benign-lookalikeMust not flagT2 · Tool-corroboratedQuiet
okta-api-token-short-token-near-missokta · format-near-missMust not flagT2 · Tool-corroboratedQuiet
okta-api-token-ssws-header-bare-twinokta · wrong-lengthMust not flagT2 · Tool-corroborated · twinQuiet
okta-api-token-ssws-header-prefix-bare-twinokta · prefix-near-missMust not flagT2 · Tool-corroborated · twinQuiet
okta-api-token-ssws-header-prefix-quoted-twinokta · prefix-near-missMust not flagT2 · Tool-corroborated · twinQuiet
okta-api-token-ssws-header-prefix-unicode-crlf-twinokta · prefix-near-missMust not flagT2 · Tool-corroborated · twinQuiet
okta-api-token-ssws-header-quoted-twinokta · wrong-lengthMust not flagT2 · Tool-corroborated · twinQuiet
okta-api-token-ssws-header-unicode-crlf-twinokta · wrong-lengthMust not flagT2 · Tool-corroborated · twinQuiet
okta-api-token-user-and-group-ids-public-idokta · public-identifierMust not flagT2 · Tool-corroboratedQuiet