Skip to content
Benchmarks

redact-secret · Report · Detector

OTP authentication URIs

  • 24 fixtures
  • Format evidence: T3 · Project policy
  • Run 2026-10-07
  • Mode published · redact-secret 0.1.0-beta.14

Format evidence

  • Reference 1
  • Twin source Key URI format, secret parameter · observed 2026-09-20 · secret is REQUIRED and Base32 per RFC 3548 with padding omitted; no length is stated

The seed is the inner span; the whole otpauth URI is the authored envelope.

What the run recorded, by group

Detector views overlap, so their groups are never summed across detectors. Other scanners are reference values on the same inputs, in run order.
Groups of OTP authentication URIs fixtures
GroupFixturesLeaked or false alarmsNear-twinsOutcomesOther scanners, same cell
Must not flag · Provider-documented8False alarmsat most 32.4%0 of 8 controls flagged8 quiet · 0 flagged
  • flare-redact at most 32.4%
  • gitleaks at most 32.4%
  • trufflehog at most 32.4%
Must not flag · Project policy7False alarmsat most 35.4%0 of 7 controls flagged7 quiet · 0 flagged
  • flare-redact at most 35.4%
  • gitleaks at most 35.4%
  • trufflehog at most 35.4%
Project policy · Project policy9Secret spans left readableat most 29.9%0 of 9 spansNear-twins told apartat least 64.6%7 of 7 pairs9 redacted · 0 too much · 0 partly exposed · 0 missed
  • flare-redact at most 100.0%
  • gitleaks at most 100.0%
  • trufflehog at most 100.0%
24 of 24 rows
Fixtures
24
Left readable
0
Redacted too much
0
False alarms
0

Fixtures for this detector

24 fixtures. Choose "Every scanner" to see each scanner's outcome for the same rows.
Fixtures in OTP authentication URIs
FixtureKind and evidenceredact-secret
otpauth-uri-hotp-baregeneric · documented-format-literalProject policyT3 · Project policyRedacted
otpauth-uri-hotp-quotedgeneric · documented-format-literalProject policyT3 · Project policyRedacted
otpauth-uri-hotp-unicode-crlfgeneric · documented-format-literalProject policyT3 · Project policyRedacted
otpauth-uri-query-ordergeneric · otp-seeds-in-otpauth-urisProject policyT3 · Project policyRedacted
otpauth-uri-quoted-configgeneric · otp-seeds-in-otpauth-urisProject policyT3 · Project policyRedacted
otpauth-uri-totp-baregeneric · documented-format-literalProject policyT3 · Project policyRedacted
otpauth-uri-totp-quotedgeneric · documented-format-literalProject policyT3 · Project policyRedacted
otpauth-uri-totp-unicode-crlfgeneric · documented-format-literalProject policyT3 · Project policyRedacted
otpauth-uri-unicode-crlfgeneric · otp-seeds-in-otpauth-urisProject policyT3 · Project policyRedacted
otpauth-uri-duplicate-first-controlgeneric · otpauth-seed-lookalikesMust not flagT3 · Project policyQuiet
otpauth-uri-hotp-bare-twingeneric · wrong-alphabetMust not flagT1 · Provider-documented · twinQuiet
otpauth-uri-hotp-quoted-twingeneric · wrong-alphabetMust not flagT1 · Provider-documented · twinQuiet
otpauth-uri-hotp-unicode-crlf-twingeneric · wrong-alphabetMust not flagT1 · Provider-documented · twinQuiet
otpauth-uri-label-prosegeneric · benign-lookalikeMust not flagT3 · Project policyQuiet
otpauth-uri-lowercase-controlgeneric · otpauth-seed-lookalikesMust not flagT3 · Project policyQuiet
otpauth-uri-maskgeneric · benign-lookalikeMust not flagT3 · Project policyQuiet
otpauth-uri-missing-secretgeneric · benign-lookalikeMust not flagT1 · Provider-documentedQuiet
otpauth-uri-query-order-twingeneric · wrong-alphabetMust not flagT1 · Provider-documented · twinQuiet
otpauth-uri-referencegeneric · benign-lookalikeMust not flagT3 · Project policyQuiet
otpauth-uri-reference-controlgeneric · otpauth-seed-lookalikesMust not flagT3 · Project policyQuiet
otpauth-uri-short-secretgeneric · benign-lookalikeMust not flagT3 · Project policyQuiet
otpauth-uri-totp-bare-twingeneric · wrong-alphabetMust not flagT1 · Provider-documented · twinQuiet
otpauth-uri-totp-quoted-twingeneric · wrong-alphabetMust not flagT1 · Provider-documented · twinQuiet
otpauth-uri-totp-unicode-crlf-twingeneric · wrong-alphabetMust not flagT1 · Provider-documented · twinQuiet