redact-secret · Report · Detector
RunPod API keys
Format evidence
- Provider documentation runpod/runpod-mcp src/alp/scrub.ts (added 2026-09-16, a provider-authored scrubber; R2): \brpa_[A-Za-z0-9]{16,}\b; the RunPod blog on scoped keys (2024-11): "Any new keys will be created with an rpa_ prefix"; re-checked 2026-09-28 · observed 2026-09-29 · rpa_ + [A-Za-z0-9], open-ended, provider floor 16; the contract floor 31 is policy under R10; no separator or checksum
- betterleaks (unpinned)
- Reference 1
- Reference 2
- Reference 3
- Reference 4
- Reference 5
- Reference 6
- Reference 7
- Reference 8
- Reference 9
- Reference 10
- Reference 11
- Reference 12
- Reference 13
Arrival evidence (#464, product redact-secret#974; #860 handoff runpod.md, READY with an open-ended body by ruling R10). T1: the prefix is the provider blog and the alphabet and provider floor of 16 are a provider-authored scrubber (R2). POLICY under R10, not T1: a floor of 16 would claim Redirect.pizza's rpa_ + 30 tokens, so project policy raises it to 31, the first width above that shape, and every RunPod width seen (46 empirical; a withdrawn 48-character docs example) is above it; the 128-byte upper bound is policy too (a bounded run for streaming; rejected whole, never truncated). The alphabet stays the provider's [A-Za-z0-9]. The contract pattern therefore carries the policy floor and the twin at 30 says POLICY; a body of 16-30 is an accepted false negative (none known), positives reach 128 and nothing asserts silence on 129. The 46-byte body and the 40-upper-plus-6-mixed layout are tool and empirical facts, so positives are authored with and without that layout. Excluded: Redirect.pizza rpa_ + 30 (another issuer), RunPod S3-compatible rps_ secrets and access keys (another credential), legacy unprefixed keys, and rpa_..., rpa_xxxx, rpa_your_key placeholders. A Redirect.pizza token of 31 or more bytes, if one exists, would read as RunPod: misattributed, still redacted. Graduated to a registry detector at the 4fb7882 re-pin (redact-secret PR #1037).
What the run recorded, by group
| Group | Fixtures | Leaked or false alarms | Near-twins | Outcomes | Other scanners, same cell |
|---|---|---|---|---|---|
| Must not flag · Tool-corroborated | 11 | False alarmsat most 25.9%0 of 11 controls flagged | 11 quiet · 0 flagged |
| |
| Must not flag · Project policy | 9 | False alarmsat most 29.9%0 of 9 controls flagged | 9 quiet · 0 flagged |
| |
| Must redact · Provider-documented | 16 | Secret spans left readableat most 19.4%0 of 16 spans | Near-twins told apartinsufficient-coverage7 of 7 pairs | 16 redacted · 0 too much · 0 partly exposed · 0 missed |
|
- Fixtures
- 36
- Left readable
- 0
- Redacted too much
- 0
- False alarms
- 0
Fixtures for this detector
| Fixture | Kind and evidence | redact-secret |
|---|---|---|
runpod-api-key-bare-proserunpod · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
runpod-api-key-bearer-headerrunpod · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
runpod-api-key-chat-pasterunpod · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
runpod-api-key-curl-graphql-bearerrunpod · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
runpod-api-key-dotenvrunpod · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
runpod-api-key-exportrunpod · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
runpod-api-key-json-api-keyrunpod · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
runpod-api-key-json-tokenrunpod · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
runpod-api-key-key-shape-barerunpod · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
runpod-api-key-key-shape-quotedrunpod · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
runpod-api-key-key-shape-unicode-crlfrunpod · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
runpod-api-key-mcp-envrunpod · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
runpod-api-key-python-modulerunpod · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
runpod-api-key-runpodctl-configrunpod · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
runpod-api-key-sdk-kwargrunpod · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
runpod-api-key-x-api-key-headerrunpod · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
runpod-api-key-actions-secret-referencerunpod · templated-reference | Must not flagT3 · Project policy | Quiet |
runpod-api-key-body-30-policy-floor-twinrunpod · wrong-length | Must not flagT2 · Tool-corroborated · twin | Quiet |
runpod-api-key-ellipsis-placeholderrunpod · documentation-placeholder | Must not flagT3 · Project policy | Quiet |
runpod-api-key-env-reference-referencerunpod · templated-reference | Must not flagT3 · Project policy | Quiet |
runpod-api-key-hyphen-prefix-twinrunpod · boundary-violation | Must not flagT2 · Tool-corroborated · twin | Quiet |
runpod-api-key-key-guidance-proserunpod · prose-mention | Must not flagT3 · Project policy | Quiet |
runpod-api-key-label-proserunpod · benign-lookalike | Must not flagT3 · Project policy | Quiet |
runpod-api-key-leading-glue-twinrunpod · boundary-violation | Must not flagT2 · Tool-corroborated · twin | Quiet |
runpod-api-key-leading-underscore-twinrunpod · boundary-violation | Must not flagT2 · Tool-corroborated · twin | Quiet |
runpod-api-key-maskrunpod · benign-lookalike | Must not flagT3 · Project policy | Quiet |
runpod-api-key-prefix-at-eol-near-missrunpod · format-near-miss | Must not flagT2 · Tool-corroborated | Quiet |
runpod-api-key-prefix-onlyrunpod · benign-lookalike | Must not flagT2 · Tool-corroborated | Quiet |
runpod-api-key-referencerunpod · benign-lookalike | Must not flagT3 · Project policy | Quiet |
runpod-api-key-short-bodyrunpod · benign-lookalike | Must not flagT2 · Tool-corroborated | Quiet |
runpod-api-key-trailing-hyphen-twinrunpod · boundary-violation | Must not flagT2 · Tool-corroborated · twin | Quiet |
runpod-api-key-trailing-underscore-twinrunpod · boundary-violation | Must not flagT2 · Tool-corroborated · twin | Quiet |
runpod-api-key-truncated-near-missrunpod · format-near-miss | Must not flagT2 · Tool-corroborated | Quiet |
runpod-api-key-uppercase-prefix-twinrunpod · prefix-near-miss | Must not flagT2 · Tool-corroborated · twin | Quiet |
runpod-api-key-word-fixture-placeholderrunpod · documentation-placeholder | Must not flagT3 · Project policy | Quiet |
runpod-api-key-x-run-placeholderrunpod · documentation-placeholder | Must not flagT3 · Project policy | Quiet |