Skip to content
Benchmarks

redact-secret · Report · Detector

Supabase tokens

  • 30 fixtures
  • Format evidence: T1 · Provider-documented
  • Run 2026-10-07
  • Mode published · redact-secret 0.1.0-beta.14

Format evidence

  • Provider documentation opaque key: sb_secret_ + 22-character random part + _ + 8-character checksum · observed 2026-09-24 · the self-hosting page states that opaque keys are sb_secret_<22-char-random>_<8-char-checksum> and "use the same format as the platform", and supabase.com/docs/guides/api/api-keys documents the sb_secret_ prefix and sb_publishable_ as "safe to expose online"; the base64url body alphabet and the sha256 checksum construction are provider code (supabase/supabase docker/utils/add-new-auth-keys.sh), not documentation, and the hosted checksum input is unconfirmed
  • Reference 1
  • Reference 2

Re-reviewed 2026-09-24 (#207, research #231) against the documented grammar instead of the empirical route. The earlier T0 record (#127, following #45) waited for Supabase's own documentation to state one body grammar; the self-hosting page now does (22 + _ + 8, "the same format as the platform"). The detector-coverage shape-1 positives were first generated as sb_secret_ plus 40 alphanumeric characters (no inner _), before that grammar was documented, and so fell outside it; they were wrong fixtures rather than a support claim and were regenerated in the documented 22 + _ + 8 layout (#213). The pinned TruffleHog supabasetoken detector matches the separate sbp_ management-token prefix, not sb_secret_, and is no longer cited; neither pinned peer has an sb_secret_ rule (betterleaks and kingfisher ship sb_secret_[A-Za-z0-9_-]{31}, unpinned). The product's floor (at_least(20, is_alnum_dash), redact-secret#515) is looser than this grammar. Twins mutate only documented properties: the public sb_publishable_ prefix, the 22/8 segment widths and the positional _ delimiter. The checksum is provider code and not part of the pattern, so no checksum-only twin is scored; the CLI's public local-dev constants are never used as fixtures.

What the run recorded, by group

Detector views overlap, so their groups are never summed across detectors. Other scanners are reference values on the same inputs, in run order.
Groups of Supabase tokens fixtures
GroupFixturesLeaked or false alarmsNear-twinsOutcomesOther scanners, same cell
Must not flag · Provider-documented2False alarmsinsufficient-evidence0 of 2 controls flagged2 quiet · 0 flagged
  • flare-redact insufficient-evidence
  • gitleaks insufficient-evidence
  • trufflehog insufficient-evidence
Must not flag · Tool-corroborated10False alarmsat most 27.8%0 of 10 controls flagged10 quiet · 0 flagged
  • flare-redact at most 27.8%
  • gitleaks at most 51.0%
  • trufflehog at most 27.8%
Must not flag · Project policy7False alarmsat most 35.4%0 of 7 controls flagged7 quiet · 0 flagged
  • flare-redact at most 35.4%
  • gitleaks at most 35.4%
  • trufflehog at most 35.4%
Must redact · Provider-documented11Secret spans left readableat most 25.9%0 of 11 spansNear-twins told apartinsufficient-coverage5 of 5 pairs11 redacted · 0 too much · 0 partly exposed · 0 missed
  • flare-redact at most 100.0%
  • gitleaks at most 72.0%
  • trufflehog at most 100.0%
30 of 30 rows
Fixtures
30
Left readable
0
Redacted too much
0
False alarms
0

Fixtures for this detector

30 fixtures. Choose "Every scanner" to see each scanner's outcome for the same rows.
Fixtures in Supabase tokens
FixtureKind and evidenceredact-secret
supabase-token-actions-envsupabase · documented-format-literalMust redactT1 · Provider-documentedRedacted
supabase-token-apikey-headersupabase · documented-format-literalMust redactT1 · Provider-documentedRedacted
supabase-token-create-clientsupabase · documented-format-literalMust redactT1 · Provider-documentedRedacted
supabase-token-edge-keys-jsonsupabase · documented-format-literalMust redactT1 · Provider-documentedRedacted
supabase-token-envsupabase · documented-format-literalMust redactT1 · Provider-documentedRedacted
supabase-token-long-checksum-twinsupabase · wrong-lengthMust not flagT2 · Tool-corroborated · twinQuiet
supabase-token-publishable-key-public-idsupabase · public-identifierMust not flagT2 · Tool-corroboratedQuiet
supabase-token-self-hosted-composesupabase · documented-format-literalMust redactT1 · Provider-documentedRedacted
supabase-token-shape-1-baresupabase · documented-format-literalMust redactT1 · Provider-documentedRedacted
supabase-token-shape-1-quotedsupabase · documented-format-literalMust redactT1 · Provider-documentedRedacted
supabase-token-shape-1-unicode-crlfsupabase · documented-format-literalMust redactT1 · Provider-documentedRedacted
supabase-token-shell-exportsupabase · documented-format-literalMust redactT1 · Provider-documentedRedacted
supabase-token-status-envsupabase · documented-format-literalMust redactT1 · Provider-documentedRedacted
supabase-token-actions-secret-referencesupabase · templated-referenceMust not flagT3 · Project policyQuiet
supabase-token-dash-delimiter-twinsupabase · boundary-violationMust not flagT2 · Tool-corroborated · twinQuiet
supabase-token-docs-ellipsis-placeholdersupabase · documentation-placeholderMust not flagT3 · Project policyQuiet
supabase-token-key-hash-encoded-valuesupabase · benign-encoded-valueMust not flagT2 · Tool-corroboratedQuiet
supabase-token-label-prosesupabase · benign-lookalikeMust not flagT3 · Project policyQuiet
supabase-token-logged-six-characters-placeholdersupabase · documentation-placeholderMust not flagT3 · Project policyQuiet
supabase-token-masksupabase · benign-lookalikeMust not flagT3 · Project policyQuiet
supabase-token-plural-prefix-near-misssupabase · format-near-missMust not flagT2 · Tool-corroboratedQuiet
supabase-token-prefix-onlysupabase · benign-lookalikeMust not flagT2 · Tool-corroboratedQuiet
supabase-token-project-url-public-idsupabase · public-identifierMust not flagT2 · Tool-corroboratedQuiet
supabase-token-publishable-prefix-sdk-twinsupabase · public-sibling-prefixMust not flagT1 · Provider-documented · twinQuiet
supabase-token-publishable-prefix-twinsupabase · public-sibling-prefixMust not flagT1 · Provider-documented · twinQuiet
supabase-token-referencesupabase · benign-lookalikeMust not flagT3 · Project policyQuiet
supabase-token-rotation-note-prosesupabase · prose-mentionMust not flagT3 · Project policyQuiet
supabase-token-short-bodysupabase · benign-lookalikeMust not flagT2 · Tool-corroboratedQuiet
supabase-token-short-random-twinsupabase · wrong-lengthMust not flagT2 · Tool-corroborated · twinQuiet
supabase-token-unprefixed-body-near-misssupabase · format-near-missMust not flagT2 · Tool-corroboratedQuiet