redact-secret · Report · Detector
stripe-webhook-signing-secret
Format evidence
- Provider documentation whsec_ webhook endpoint signing secret · observed 2026-09-24 · the whsec_ prefix and the per-endpoint configuration context; no body length or alphabet
- Reference 1
- Reference 2
- Reference 3
- Reference 4
- Reference 5
Arrival contract (#211, research #224, observed 2026-09-24). Context-constrained and provisional, per #211: Stripe documents the whsec_ prefix and where the secret is configured, never a body length or alphabet; its only full-length example has 32 alphanumerics, its own CLI scrubber admits base64 + / =, its canary sanitizer does not, and Svix/Standard Webhooks issue whsec_ too. Positives therefore score as policy beside a same-line Stripe context, use alphanumeric 32- or 64-character bodies that satisfy every candidate rule, and no twin mutates width or introduces + / =. Neither pinned peer (gitleaks 8.30.1, trufflehog 3.97.4) registers a whsec_ rule. Stripe-Signature digests, we_/ed_/evt_ ids and pk_ publishable keys are public controls. The public-prefix twin swaps whsec_ for pk_live_, which docs.stripe.com/keys documents as safe to expose.
What the run recorded, by group
| Group | Fixtures | Leaked or false alarms | Near-twins | Outcomes | Other scanners, same cell |
|---|---|---|---|---|---|
| Must not flag · Provider-documented | 1 | False alarmsinsufficient-evidence0 of 1 controls flagged | 1 quiet · 0 flagged |
| |
| Must not flag · Tool-corroborated | 9 | False alarmsat most 29.9%0 of 9 controls flagged | 9 quiet · 0 flagged |
| |
| Must not flag · Project policy | 5 | False alarmsat most 43.4%0 of 5 controls flagged | 5 quiet · 0 flagged |
| |
| Project policy · Project policy | 11 | Secret spans left readableat most 24.3%0 of 12 spans | Near-twins told apartat least 56.6%5 of 5 pairs | 12 redacted · 0 too much · 0 partly exposed · 0 missed |
|
| Pending review | 3 | UnscoredNot scoredInspect only: never scored until evidence exists | Not scored |
- Fixtures
- 29
- Left readable
- 0
- Redacted too much
- 0
- False alarms
- 0
Fixtures for this detector
| Fixture | Kind and evidence | redact-secret |
|---|---|---|
stripe-webhook-signing-secret-actions-envstripe · documented-format-literal | Project policyT3 · Project policy | Redacted |
stripe-webhook-signing-secret-compose-webhook-secretstripe · documented-format-literal | Project policyT3 · Project policy | Redacted |
stripe-webhook-signing-secret-dotenv-webhook-secretstripe · documented-format-literal | Project policyT3 · Project policy | Redacted |
stripe-webhook-signing-secret-endpoint-create-responsestripe · documented-format-literal | Project policyT3 · Project policy | Redacted |
stripe-webhook-signing-secret-event-destination-create-responsestripe · documented-format-literal | Project policyT3 · Project policy | Redacted |
stripe-webhook-signing-secret-export-webhook-secretstripe · documented-format-literal | Project policyT3 · Project policy | Redacted |
stripe-webhook-signing-secret-node-construct-event-widestripe · documented-format-literal | Project policyT3 · Project policy | Redacted |
stripe-webhook-signing-secret-publishable-key-public-idstripe · public-identifier | Must not flagT2 · Tool-corroborated | Quiet |
stripe-webhook-signing-secret-python-construct-eventstripe · documented-format-literal | Project policyT3 · Project policy | Redacted |
stripe-webhook-signing-secret-rails-credentials-rollingstripe · documented-format-literal | Project policyT3 · Project policy | Redacted |
stripe-webhook-signing-secret-stripe-listen-readystripe · documented-format-literal | Project policyT3 · Project policy | Redacted |
stripe-webhook-signing-secret-webhook-verifier-logstripe · documented-format-literal | Project policyT3 · Project policy | Redacted |
stripe-token-shape-6-barestripe · unsettled-evidence-input | Pending reviewT0 · Pending | Unscored |
stripe-token-shape-6-quotedstripe · unsettled-evidence-input | Pending reviewT0 · Pending | Unscored |
stripe-token-shape-6-unicode-crlfstripe · unsettled-evidence-input | Pending reviewT0 · Pending | Unscored |
stripe-webhook-signing-secret-docs-sentence-prosestripe · prose-mention | Must not flagT3 · Project policy | Quiet |
stripe-webhook-signing-secret-dotenv-webhook-secret-public-prefix-twinstripe · public-sibling-prefix | Must not flagT1 · Provider-documented · twin | Quiet |
stripe-webhook-signing-secret-ellipsis-placeholderstripe · documentation-placeholder | Must not flagT3 · Project policy | Quiet |
stripe-webhook-signing-secret-endpoint-create-response-boundary-twinstripe · boundary-violation | Must not flagT2 · Tool-corroborated · twin | Quiet |
stripe-webhook-signing-secret-endpoint-object-public-idstripe · public-identifier | Must not flagT2 · Tool-corroborated | Quiet |
stripe-webhook-signing-secret-event-destination-log-public-idstripe · public-identifier | Must not flagT2 · Tool-corroborated | Quiet |
stripe-webhook-signing-secret-export-webhook-secret-case-twinstripe · prefix-near-miss | Must not flagT2 · Tool-corroborated · twin | Quiet |
stripe-webhook-signing-secret-fill-in-placeholderstripe · documentation-placeholder | Must not flagT3 · Project policy | Quiet |
stripe-webhook-signing-secret-masked-placeholderstripe · documentation-placeholder | Must not flagT3 · Project policy | Quiet |
stripe-webhook-signing-secret-prefix-only-near-missstripe · format-near-miss | Must not flagT2 · Tool-corroborated | Quiet |
stripe-webhook-signing-secret-print-secret-substitution-referencestripe · templated-reference | Must not flagT3 · Project policy | Quiet |
stripe-webhook-signing-secret-python-construct-event-separator-twinstripe · prefix-near-miss | Must not flagT2 · Tool-corroborated · twin | Quiet |
stripe-webhook-signing-secret-stripe-signature-header-encoded-valuestripe · benign-encoded-value | Must not flagT2 · Tool-corroborated | Quiet |
stripe-webhook-signing-secret-webhook-verifier-log-alphabet-twinstripe · wrong-alphabet | Must not flagT2 · Tool-corroborated · twin | Quiet |