Skip to content
Benchmarks

redact-secret · Report · Detector

Postman collection access keys

  • 42 fixtures
  • Format evidence: T2 · Tool-corroborated
  • Run 2026-10-07
  • Mode published · redact-secret 0.1.0-beta.14

Format evidence

  • GitLab secret-detection-rules
  • Reference 1
  • Reference 2
  • Reference 3
  • Twin source masked PMAT- collection access key · observed 2026-09-24 · Postman documents the collection access key as a read-only credential for one collection's JSON (Share via API), valid for 60 days of inactivity, and renders it masked as PMAT- followed by asterisks and four trailing characters (26 in all). It states no alphabet. Twins mutate the prefix, its delimiter or the body length

Registry detector postman-collection-access-key since redact-secret#700 (#773, registry pinned at 3144bb3); authored under #259 directly as a registry contract. Postman documents the collection access key (Share via API: "Generate New Key to create a read-only collection access key. This key expires after 60 days of inactivity") and tells users to remove sensitive data before sharing one. Its API reference renders the key masked as PMAT- + asterisks + 4 characters, a 26-character body by count (provider example, not a grammar statement). GitLab's secret-detection rule PostmanCollectionAccessKey matches \bPMAT-[A-Z0-9]{26}\b and gates validation on a postman or pstmn.io context; its examples are ULID-shaped, which is recorded as unresolved; GitHub secret scanning lists postman_collection_key as a partner pattern without publishing the expression. The contract freezes GitLab's uppercase alphanumeric body. The product (redact-secret#700) also accepts lowercase, a looser reading. No lowercase twin is authored, because the case is stated by one tool only. Neither pinned peer has a PMAT- rule. The PMAK- API key is a different, secret credential and is never a control. The prefix twin swaps PMAT- for PMAK- with the same 26-character body, which fits neither contract.

What the run recorded, by group

Detector views overlap, so their groups are never summed across detectors. Other scanners are reference values on the same inputs, in run order.
Groups of Postman collection access keys fixtures
GroupFixturesLeaked or false alarmsNear-twinsOutcomesOther scanners, same cell
Must not flag · Tool-corroborated15False alarmsat most 20.4%0 of 15 controls flagged15 quiet · 0 flagged
  • flare-redact at most 20.4%
  • gitleaks at most 20.4%
  • trufflehog at most 20.4%
Must not flag · Project policy9False alarmsat most 29.9%0 of 9 controls flagged9 quiet · 0 flagged
  • flare-redact at most 29.9%
  • gitleaks at most 29.9%
  • trufflehog at most 29.9%
Must redact · Tool-corroborated18Secret spans left readableat most 17.6%0 of 18 spansNear-twins told apartinsufficient-coverage8 of 8 pairs18 redacted · 0 too much · 0 partly exposed · 0 missed
  • flare-redact at most 100.0%
  • gitleaks at most 45.2%
  • trufflehog at most 100.0%
42 of 42 rows
Fixtures
42
Left readable
0
Redacted too much
0
False alarms
0

Fixtures for this detector

42 fixtures. Choose "Every scanner" to see each scanner's outcome for the same rows.
Fixtures in Postman collection access keys
FixtureKind and evidenceredact-secret
postman-collection-access-key-actions-newmanpostman · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
postman-collection-access-key-chat-sharepostman · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
postman-collection-access-key-ci-logpostman · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
postman-collection-access-key-compose-envpostman · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
postman-collection-access-key-curl-collection-jsonpostman · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
postman-collection-access-key-dotenvpostman · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
postman-collection-access-key-exportpostman · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
postman-collection-access-key-key-shape-barepostman · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
postman-collection-access-key-key-shape-quotedpostman · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
postman-collection-access-key-key-shape-unicode-crlfpostman · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
postman-collection-access-key-newman-jsonpostman · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
postman-collection-access-key-newman-runpostman · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
postman-collection-access-key-share-configpostman · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
postman-collection-access-key-share-outputpostman · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
postman-collection-access-key-share-via-apipostman · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
postman-collection-access-key-twin-base-dotenvpostman · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
postman-collection-access-key-twin-base-exportpostman · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
postman-collection-access-key-twin-base-urlpostman · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
postman-collection-access-key-api-key-prefix-twinpostman · prefix-near-missMust not flagT2 · Tool-corroborated · twinQuiet
postman-collection-access-key-base64-uid-encoded-valuepostman · benign-encoded-valueMust not flagT2 · Tool-corroboratedQuiet
postman-collection-access-key-collection-uid-public-idpostman · public-identifierMust not flagT2 · Tool-corroboratedQuiet
postman-collection-access-key-docs-placeholder-placeholderpostman · documentation-placeholderMust not flagT3 · Project policyQuiet
postman-collection-access-key-document-code-near-misspostman · format-near-missMust not flagT2 · Tool-corroboratedQuiet
postman-collection-access-key-env-reference-referencepostman · templated-referenceMust not flagT3 · Project policyQuiet
postman-collection-access-key-key-guidance-prosepostman · prose-mentionMust not flagT3 · Project policyQuiet
postman-collection-access-key-label-prosepostman · benign-lookalikeMust not flagT3 · Project policyQuiet
postman-collection-access-key-long-body-twinpostman · wrong-lengthMust not flagT2 · Tool-corroborated · twinQuiet
postman-collection-access-key-long-body-twin-wrong-lengthpostman · wrong-lengthMust not flagT2 · Tool-corroborated · twinQuiet
postman-collection-access-key-lowercase-prefix-twinpostman · prefix-near-missMust not flagT2 · Tool-corroborated · twinQuiet
postman-collection-access-key-maskpostman · benign-lookalikeMust not flagT3 · Project policyQuiet
postman-collection-access-key-masked-key-list-placeholderpostman · documentation-placeholderMust not flagT3 · Project policyQuiet
postman-collection-access-key-postman-variable-referencepostman · templated-referenceMust not flagT3 · Project policyQuiet
postman-collection-access-key-prefix-onlypostman · benign-lookalikeMust not flagT2 · Tool-corroboratedQuiet
postman-collection-access-key-prefix-only-near-misspostman · format-near-missMust not flagT2 · Tool-corroboratedQuiet
postman-collection-access-key-public-share-link-public-idpostman · public-identifierMust not flagT2 · Tool-corroboratedQuiet
postman-collection-access-key-referencepostman · benign-lookalikeMust not flagT3 · Project policyQuiet
postman-collection-access-key-sharing-note-prosepostman · prose-mentionMust not flagT3 · Project policyQuiet
postman-collection-access-key-short-bodypostman · benign-lookalikeMust not flagT2 · Tool-corroboratedQuiet
postman-collection-access-key-short-body-twinpostman · wrong-lengthMust not flagT2 · Tool-corroborated · twinQuiet
postman-collection-access-key-short-body-twin-wrong-lengthpostman · wrong-lengthMust not flagT2 · Tool-corroborated · twinQuiet
postman-collection-access-key-underscore-delimiter-twinpostman · boundary-violationMust not flagT2 · Tool-corroborated · twinQuiet
postman-collection-access-key-underscore-delimiter-twin-boundary-violationpostman · boundary-violationMust not flagT2 · Tool-corroborated · twinQuiet