Skip to content
Benchmarks

redact-secret · Report · Detector

Travis CI API tokens

  • 48 fixtures
  • Format evidence: T2 · Tool-corroborated
  • Run 2026-10-07
  • Mode published · redact-secret 0.1.0-beta.14

Format evidence

  • gitleaks 8.30.1
  • trufflehog 3.97.4
  • Reference 1
  • Twin source Authorization: token header, token from travis token · observed 2026-09-24 · the provider documents the API token as generated by the travis CLI (travis token, travis token --pro) and sent in an Authorization: token header to api.travis-ci.org / api.travis-ci.com; the example is masked (xxxxxxxxxxxx) and no length or alphabet is stated. Context twins keep the token and remove the same-line Travis context, or rename the key to a Travis identifier name

Registry detector travisci-api-token since redact-secret#523 (#773, registry pinned at 3144bb3); authored under #259 directly as a context-gated registry contract. Travis CI states no token shape. Both pinned peers corroborate a 22-character alphanumeric token gated on a travis keyword: gitleaks 8.30.1 travisci-access-token (a case-insensitive travis keyword before an assignment operator, then [a-z0-9]{22} under (?i)) and trufflehog 3.97.4 travisci (a travis prefix within its keyword window, then \b[a-zA-Z0-9_]{22}\b). The contract freezes their intersection, [A-Za-z0-9]{22}, recognised only beside a same-line travis keyword, so positives score as policy. It also requires at least one letter and one digit, matching the product grammar; about 2% of uniformly random 22-character tokens have no digit and fall outside that claim. The underscore trufflehog admits is not claimed, and the underscore twin records that peer difference. Travis build, job and repository ids are numeric and commit SHAs are 40 hex characters, so they are public-id controls. .travis.yml secure: values are RSA ciphertext and are encoded-value controls.

What the run recorded, by group

Detector views overlap, so their groups are never summed across detectors. Other scanners are reference values on the same inputs, in run order.
Groups of Travis CI API tokens fixtures
GroupFixturesLeaked or false alarmsNear-twinsOutcomesOther scanners, same cell
Must not flag · Tool-corroborated11False alarmsat most 25.9%0 of 11 controls flagged11 quiet · 0 flagged
  • flare-redact at most 25.9%
  • gitleaks at most 37.7%
  • trufflehog at most 25.9%
Must not flag · Project policy18False alarmsat most 17.6%0 of 18 controls flagged18 quiet · 0 flagged
  • flare-redact at most 17.6%
  • gitleaks at most 45.2%
  • trufflehog at most 45.2%
Project policy · Project policy19Secret spans left readableat most 16.8%0 of 19 spansNear-twins told apartat least 77.2%13 of 13 pairs19 redacted · 0 too much · 0 partly exposed · 0 missed
  • flare-redact at most 100.0%
  • gitleaks at most 48.8%
  • trufflehog at most 24.6%
48 of 48 rows
Fixtures
48
Left readable
0
Redacted too much
0
False alarms
0

Fixtures for this detector

48 fixtures. Choose "Every scanner" to see each scanner's outcome for the same rows.
Fixtures in Travis CI API tokens
FixtureKind and evidenceredact-secret
travisci-api-token-actions-envtravis-ci · documented-format-literalProject policyT3 · Project policyRedacted
travisci-api-token-context-1-twintravis-ci · missing-context-markerMust not flagT3 · Project policy · twinQuiet
travisci-api-token-context-2-twintravis-ci · missing-context-markerMust not flagT3 · Project policy · twinQuiet
travisci-api-token-context-4-twintravis-ci · missing-context-markerMust not flagT3 · Project policy · twinQuiet
travisci-api-token-context-8-twintravis-ci · missing-context-markerMust not flagT3 · Project policy · twinQuiet
travisci-api-token-context-base-1travis-ci · documented-format-literalProject policyT3 · Project policyRedacted
travisci-api-token-context-base-2travis-ci · documented-format-literalProject policyT3 · Project policyRedacted
travisci-api-token-context-base-3travis-ci · documented-format-literalProject policyT3 · Project policyRedacted
travisci-api-token-context-base-4travis-ci · documented-format-literalProject policyT3 · Project policyRedacted
travisci-api-token-context-base-5travis-ci · documented-format-literalProject policyT3 · Project policyRedacted
travisci-api-token-context-base-6travis-ci · documented-format-literalProject policyT3 · Project policyRedacted
travisci-api-token-context-base-7travis-ci · documented-format-literalProject policyT3 · Project policyRedacted
travisci-api-token-context-base-8travis-ci · documented-format-literalProject policyT3 · Project policyRedacted
travisci-api-token-curl-authorizationtravis-ci · documented-format-literalProject policyT3 · Project policyRedacted
travisci-api-token-dotenvtravis-ci · documented-format-literalProject policyT3 · Project policyRedacted
travisci-api-token-exporttravis-ci · documented-format-literalProject policyT3 · Project policyRedacted
travisci-api-token-identifier-key-twintravis-ci · missing-context-markerMust not flagT3 · Project policy · twinQuiet
travisci-api-token-json-configtravis-ci · documented-format-literalProject policyT3 · Project policyRedacted
travisci-api-token-sync-logtravis-ci · documented-format-literalProject policyT3 · Project policyRedacted
travisci-api-token-token-shape-baretravis-ci · documented-format-literalProject policyT3 · Project policyRedacted
travisci-api-token-token-shape-quotedtravis-ci · documented-format-literalProject policyT3 · Project policyRedacted
travisci-api-token-token-shape-unicode-crlftravis-ci · documented-format-literalProject policyT3 · Project policyRedacted
travisci-api-token-travis-whoamitravis-ci · documented-format-literalProject policyT3 · Project policyRedacted
travisci-api-token-travispy-clienttravis-ci · documented-format-literalProject policyT3 · Project policyRedacted
travisci-api-token-underscore-body-twintravis-ci · wrong-alphabetMust not flagT2 · Tool-corroborated · twinQuiet
travisci-api-token-actions-secret-referencetravis-ci · templated-referenceMust not flagT3 · Project policyQuiet
travisci-api-token-artifact-digest-encoded-valuetravis-ci · benign-encoded-valueMust not flagT2 · Tool-corroboratedQuiet
travisci-api-token-build-env-public-idtravis-ci · public-identifierMust not flagT2 · Tool-corroboratedQuiet
travisci-api-token-build-url-public-idtravis-ci · public-identifierMust not flagT2 · Tool-corroboratedQuiet
travisci-api-token-commit-sha-public-idtravis-ci · public-identifierMust not flagT2 · Tool-corroboratedQuiet
travisci-api-token-context-3-twintravis-ci · missing-context-markerMust not flagT3 · Project policy · twinQuiet
travisci-api-token-context-5-twintravis-ci · missing-context-markerMust not flagT3 · Project policy · twinQuiet
travisci-api-token-context-6-twintravis-ci · missing-context-markerMust not flagT3 · Project policy · twinQuiet
travisci-api-token-context-7-twintravis-ci · missing-context-markerMust not flagT3 · Project policy · twinQuiet
travisci-api-token-docs-token-placeholdertravis-ci · documentation-placeholderMust not flagT3 · Project policyQuiet
travisci-api-token-env-example-placeholdertravis-ci · documentation-placeholderMust not flagT3 · Project policyQuiet
travisci-api-token-env-reference-referencetravis-ci · templated-referenceMust not flagT3 · Project policyQuiet
travisci-api-token-label-prosetravis-ci · benign-lookalikeMust not flagT3 · Project policyQuiet
travisci-api-token-letters-only-stage-near-misstravis-ci · format-near-missMust not flagT2 · Tool-corroboratedQuiet
travisci-api-token-long-token-twintravis-ci · wrong-lengthMust not flagT2 · Tool-corroborated · twinQuiet
travisci-api-token-masktravis-ci · benign-lookalikeMust not flagT3 · Project policyQuiet
travisci-api-token-missing-keywordtravis-ci · benign-lookalikeMust not flagT2 · Tool-corroboratedQuiet
travisci-api-token-no-travis-context-twintravis-ci · missing-context-markerMust not flagT3 · Project policy · twinQuiet
travisci-api-token-referencetravis-ci · benign-lookalikeMust not flagT3 · Project policyQuiet
travisci-api-token-short-in-prose-near-misstravis-ci · format-near-missMust not flagT2 · Tool-corroboratedQuiet
travisci-api-token-short-token-twintravis-ci · wrong-lengthMust not flagT2 · Tool-corroborated · twinQuiet
travisci-api-token-token-guidance-prosetravis-ci · prose-mentionMust not flagT3 · Project policyQuiet
travisci-api-token-travis-secure-encoded-valuetravis-ci · benign-encoded-valueMust not flagT2 · Tool-corroboratedQuiet