redact-secret · Report
Admin API key (sk-ant-admin01-)
sk-ant-admin01- prefixed full-access Admin API key created by organization admins in the Claude Console.
Research record
4 events in the review history: 3 observed, 1 reviewed. Latest: observed on 2026-10-03 by automation, project maintainer. Project-maintained review is not independent validation. The family record at this release.
Format
What it looks like
- Descriptive pattern
^sk-ant-admin01-[A-Za-z0-9_-]{93}AA$
Parts are shown as recorded. Evidence classes belong to the facts below; no class is assigned to a part.
Format facts
Provider documented ·
provider-source· current · observed 2026-09-26Key prefix table: sk-ant-admin01-... (Console Admin API key): the provider documents sk-ant-admin01- as the Admin API key prefix, created by organization admins and shown once; the 93-character body and AA tail are tool-corroborated
- platform.claude.com/docs/en/manage-claude/admin-api-keysprovider-documentation · last read 2026-10-03 · latest outcome read · supports the provider documents sk-ant-admin01- as the Admin API key prefix, created by organization admins and shown once; the 93-character body and AA tail are tool-corroborated
Tool corroborated ·
tool-corroboration· current · observed 2026-09-26Pinned scanner rules are consistent with the contract grammar (3 artifacts: betterleaks; gitleaks 8.30.1; trufflehog 3.97.4).
- betterleaks/betterleaks @ main: cmd/generate/config/rules/anthropic.goscanner-rule-source · last read 2026-09-26 · latest outcome read · supports betterleaks: anthropic-admin-api-key (a gitleaks fork, not independent of gitleaks)
- gitleaks/gitleaks @ v8.30.1: config/gitleaks.tomlscanner-rule-source · last read 2026-10-04 · latest outcome read · supports gitleaks 8.30.1: gitleaks.toml
- trufflesecurity/trufflehog @ v3.97.4: pkg/detectors/anthropic/anthropic.goscanner-rule-source · last read 2026-09-26 · latest outcome read · supports trufflehog 3.97.4: Anthropic: \b(sk-ant-(?:admin01|api03)-[\w\-]{93}AA)\b
Provider documented ·
field-prefix· current · observed 2026-09-26prefix: sk-ant-admin01-
- platform.claude.com/docs/en/manage-claude/admin-api-keysprovider-documentation · last read 2026-10-03 · latest outcome read · supports "starting with sk-ant-admin01-"
- platform.claude.com/docs/en/manage-claude/admin-apiprovider-documentation · last read 2026-09-27 · latest outcome read · supports written sk-ant-admin... without the version digit
Tool corroborated ·
field-body· current · observed 2026-09-26body: 93 characters of [A-Za-z0-9_-] then a literal AA tail (110 in all) (No provider page states a length, alphabet or tail. The product accepts a >= 20 byte superset, so no length, alphabet or tail twin is authored.)
- betterleaks/betterleaks @ main: cmd/generate/config/rules/anthropic.goscanner-rule-source · last read 2026-09-26 · latest outcome read · supports gitleaks lineage
- gitleaks/gitleaks @ v8.30.1: config/gitleaks.tomlscanner-rule-source · last read 2026-10-04 · latest outcome read · supports anthropic-admin-api-key
- trufflesecurity/trufflehog @ v3.97.4: pkg/detectors/anthropic/anthropic.goscanner-rule-source · last read 2026-09-26 · latest outcome read · supports body: 93 characters of [A-Za-z0-9_-] then a literal AA tail (110 in all)
Provider documented ·
field-header· current · observed 2026-09-26header: sent as x-api-key (the Admin API page); Bearer appears for the OAuth org:admin token
- platform.claude.com/docs/en/manage-claude/admin-apiprovider-documentation · last read 2026-09-27 · latest outcome read · supports header: sent as x-api-key (the Admin API page); Bearer appears for the OAuth org:admin token
- platform.claude.com/docs/en/manage-claude/authenticationprovider-documentation · last read 2026-10-04 · latest outcome read · supports header: sent as x-api-key (the Admin API page); Bearer appears for the OAuth org:admin token
Unresolved ·
field-version· current · observed 2026-09-26version: admin01 is the only documented version; admin02 and an unversioned sk-ant-admin- have no source (No fixture asserts silence on admin02 or on the unversioned spelling.)
- platform.claude.com/docs/en/manage-claude/admin-api-keysprovider-documentation · last read 2026-10-03 · latest outcome read · supports version: admin01 is the only documented version; admin02 and an unversioned sk-ant-admin- have no source
- platform.claude.com/docs/en/manage-claude/admin-apiprovider-documentation · last read 2026-09-27 · latest outcome read · supports the unversioned spelling appears here
Provider documented ·
field-sibling-classes· current · observed 2026-09-26sibling-classes: sk-ant-api03- (Claude API key) and sk-ant-api01- (Enterprise organization key) are different classes (Real secrets of other classes: used only as scoped prefix twins, never as benign controls.)
- platform.claude.com/docs/en/manage-claude/compliance-api-accessprovider-documentation · last read 2026-10-04 · latest outcome read · supports sibling-classes: sk-ant-api03- (Claude API key) and sk-ant-api01- (Enterprise organization key) are different classes
- platform.claude.com/docs/en/manage-claude/admin-api-keysprovider-documentation · last read 2026-10-03 · latest outcome read · supports sibling-classes: sk-ant-api03- (Claude API key) and sk-ant-api01- (Enterprise organization key) are different classes
Unresolved ·
field-encoded-form· current · observed 2026-09-26encoded-form: GitHub does not support Base64 detection for anthropic_admin_api_key (A GitHub capability, not a format fact. No Base64 fixture is authored.)
- docs.github.com/en/code-security/secret-scanning/introduction/supported-secret-scanning-patternsprovider-documentation · last read 2026-10-05 · latest outcome read · supports encoded-form: GitHub does not support Base64 detection for anthropic_admin_api_key
Unresolved ·
listed-references· current · observed 2026-09-26The legacy contract lists 6 references without stating which property each supports.
- docs.github.com/en/code-security/secret-scanning/introduction/supported-secret-scanning-patternsprovider-documentation · last read 2026-10-05 · latest outcome read · supports Listed as a reference by the legacy contract
- github.com/redact-secret/redact-secret/issues/775issue-or-discussion · last read 2026-09-26 · latest outcome read · supports Listed as a reference by the legacy contract
- github.com/redact-secret/redact-secret/issues/862issue-or-discussion · last read 2026-09-26 · latest outcome read · supports Listed as a reference by the legacy contract
- github.com/trufflesecurity/trufflehog/pull/3969issue-or-discussion · last read 2026-09-26 · latest outcome read · supports Listed as a reference by the legacy contract
- platform.claude.com/docs/en/manage-claude/admin-apiprovider-documentation · last read 2026-09-27 · latest outcome read · supports Listed as a reference by the legacy contract
- platform.claude.com/docs/en/manage-claude/authenticationprovider-documentation · last read 2026-10-04 · latest outcome read · supports Listed as a reference by the legacy contract
Provider documented ·
dossier-research· current · observed 2026-09-27Legacy dossier research (verdict ready, tier T1) cited 3 sources; the dossier does not attribute sources to individual properties.
- platform.claude.com/docs/en/manage-claude/compliance-api-accessprovider-documentation · last read 2026-10-04 · latest outcome read · supports Cited by the legacy dossier research for this family
- platform.claude.com/docs/en/manage-claude/admin-api-keysprovider-documentation · last read 2026-10-03 · latest outcome read · supports Cited by the legacy dossier research for this family
- platform.claude.com/docs/en/manage-claude/admin-apiprovider-documentation · last read 2026-09-27 · latest outcome read · supports Cited by the legacy dossier research for this family
Provider documented ·
taxonomy-sources· current · observed 2026-09-27The legacy taxonomy lists 2 sources for this family. The taxonomy records no date; the dossier researchedAt is used as the observed-at date.
- platform.claude.com/docs/en/manage-claude/admin-api-keysprovider-documentation · last read 2026-10-03 · latest outcome read · supports Listed as a source for this family in the legacy taxonomy
- platform.claude.com/docs/en/manage-claude/admin-apiprovider-documentation · last read 2026-09-27 · latest outcome read · supports Listed as a source for this family in the legacy taxonomy
Open questions
No open question is recorded for this revision.
Benchmark dossier notes
- Shape
- prefix
sk-ant-admin01-, created in Claude Console > Settings > Admin keys by an organization admin, shown once, with a selectable expiration. Console admin keys carry full access to every endpoint that accepts an Admin API key. Body: 93 characters from letters, digits, underscore and hyphen, thenAA(110 in all), stated only by scanner rules (gitleaks, its fork betterleaks, trufflehog). The provider states no length. - Basis
- T1 for the prefix (two provider pages; one writes it
sk-ant-admin...without the version segment). Body: T2, with trufflehog the only corroboration independent of the gitleaks lineage. No staff statement and no provider SDK source constrains the body. - Issuance
- not attempted. A Console organization admin can mint one with a short expiry and revoke it; the checklist is in the #775 discovery comment.
- Contract in core
- detector-families.md.
In this benchmark
- Fixtures
- 39
- Left readable
- 0
- Redacted too much
- 0
- False alarms
- 0
39 fixtures: 15 expect a redaction, 24 must stay quiet. See every row
| Evidence level | Fixtures | Left readable | Too much | False alarms |
|---|---|---|---|---|
| T1Provider-documented | 15 | 0 | 0 | 0 |
| T2Tool-corroborated | 15 | 0 | 0 | 0 |
| T3Project policy | 9 | 0 | 0 | 0 |
Every scanner on the same fixtures
In run order. Counts are what each scanner recorded on this family's fixtures, whichever rules it has; a scanner with no rule for the family has nothing to report on it.
| Scanner | Fixtures | Left readable | Too much | False alarms |
|---|---|---|---|---|
| flare-redactRuntime library · 1.6.1 · Published npm package · secrets-only (pii, generic_assignment disabled) · JavaScript engine1 rule targets it | 39 | 0 | 0 | 2 |
| gitleaksRepository scanner · 8.30.1 · Directory scan · default rules1 rule targets it | 39 | 0 | 0 | 2 |
| redact-secretProduct measured here · 0.1.0-beta.14 · Published npm package · default detectors1 detector mapped | 39 | 0 | 0 | 0 |
| trufflehogRepository scanner · 3.97.4 · Filesystem scan · verification disabled1 rule targets it | 39 | 0 | 0 | 0 |
Benchmark dossier questions
- Open caveat
- Body grammar is scanner-corroborated only (T2); confirming it needs one issued Console admin key (checklist in #775).
Looks like it, but isn't
- Collisions
sk-ant-api01-andsk-ant-api03-differ by one segment. The Admin API also accepts an OAuth bearer token and other key shapes, so an admin key is not the only credential seen in that API's headers. A GitHub secret-scanning type and several other scanners list it separately.
Scanner rules for this family
| Scanner | Rule | What the rule matches |
|---|---|---|
| flare-redact · rules 1.6.1 | anthropic_key | sk-ant- + 24-160 characters |
| gitleaks · rules 8.30.1 | anthropic-admin-api-key | sk-ant-admin01- + 93 chars + AA |
| trufflehog · rules 3.97.4 | anthropic | sk-ant-api03- or sk-ant-admin01- + 93 characters + AA |
No rule maps to this family in openredaction.
Fixtures in this family
| Fixture | Kind and evidence | redact-secret |
|---|---|---|
anthropic-admin01-key-admim-letter-twinanthropic · prefix-near-miss | Must not flagT2 · Tool-corroborated · twin | Quiet |
anthropic-admin01-key-key-digest-encoded-valueanthropic · benign-encoded-value | Must not flagT2 · Tool-corroborated | Quiet |
anthropic-admin01-key-underscore-after-version-twinanthropic · prefix-near-miss | Must not flagT2 · Tool-corroborated · twin | Quiet |
anthropic-admin01-key-underscore-delimiters-twinanthropic · boundary-violation | Must not flagT2 · Tool-corroborated · twin | Quiet |
anthropic-admin01-key-actions-secret-referenceanthropic · templated-reference | Must not flagT3 · Project policy | Quiet |
anthropic-admin01-key-admin-api-ids-public-idanthropic · public-identifier | Must not flagT2 · Tool-corroborated | Quiet |
anthropic-admin01-key-angle-comment-placeholderanthropic · documentation-placeholder | Must not flagT3 · Project policy | Quiet |
anthropic-admin01-key-angle-key-placeholderanthropic · documentation-placeholder | Must not flagT3 · Project policy | Quiet |
anthropic-admin01-key-api-keys-listing-public-idanthropic · public-identifier | Must not flagT2 · Tool-corroborated | Quiet |
anthropic-admin01-key-api01-prefix-twinanthropic · prefix-near-miss | Must not flagT2 · Tool-corroborated · twin | Quiet |
anthropic-admin01-key-api03-prefix-twinanthropic · prefix-near-miss | Must not flagT2 · Tool-corroborated · twin | Quiet |
anthropic-admin01-key-audit-stderr-headersanthropic · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
anthropic-admin01-key-body-only-twinanthropic · prefix-near-miss | Must not flagT2 · Tool-corroborated · twin | Quiet |
anthropic-admin01-key-circleci-environmentanthropic · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
anthropic-admin01-key-compose-envanthropic · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
anthropic-admin01-key-curl-x-api-keyanthropic · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
anthropic-admin01-key-docs-ellipsis-placeholderanthropic · documentation-placeholder | Must not flagT3 · Project policy | Quiet |
anthropic-admin01-key-dotenvanthropic · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
anthropic-admin01-key-embedded-leading-twinanthropic · boundary-violation | Must not flagT2 · Tool-corroborated · twin | Quiet |
anthropic-admin01-key-env-reference-referenceanthropic · templated-reference | Must not flagT3 · Project policy | Quiet |
anthropic-admin01-key-exportanthropic · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
anthropic-admin01-key-fish-set-gxanthropic · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
anthropic-admin01-key-httpie-admin-apianthropic · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
anthropic-admin01-key-job-loganthropic · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
anthropic-admin01-key-json-configanthropic · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
anthropic-admin01-key-markdown-table-ellipsis-placeholderanthropic · documentation-placeholder | Must not flagT3 · Project policy | Quiet |
anthropic-admin01-key-masked-console-public-idanthropic · public-identifier | Must not flagT2 · Tool-corroborated | Quiet |
anthropic-admin01-key-one-password-ref-referenceanthropic · templated-reference | Must not flagT3 · Project policy | Quiet |
anthropic-admin01-key-org-admin-provider-blockanthropic · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
anthropic-admin01-key-pasted-keyanthropic · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
anthropic-admin01-key-prefix-constant-near-missanthropic · format-near-miss | Must not flagT2 · Tool-corroborated | Quiet |
anthropic-admin01-key-prefix-guidance-proseanthropic · prose-mention | Must not flagT3 · Project policy | Quiet |
anthropic-admin01-key-prefix-only-near-missanthropic · format-near-miss | Must not flagT2 · Tool-corroborated | Quiet |
anthropic-admin01-key-python-sdkanthropic · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
anthropic-admin01-key-rotation-policy-proseanthropic · prose-mention | Must not flagT3 · Project policy | Quiet |
anthropic-admin01-key-tool-callanthropic · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
anthropic-admin01-key-ts-fetch-literalanthropic · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
anthropic-admin01-key-uppercase-prefix-twinanthropic · prefix-near-miss | Must not flagT2 · Tool-corroborated · twin | Quiet |
anthropic-admin01-key-version-and-org-public-idanthropic · public-identifier | Must not flagT2 · Tool-corroborated | Quiet |
Sources
Documentation and code
- platform.claude.com/docs/en/manage-claude/admin-api-keys
- platform.claude.com/docs/en/manage-claude/admin-api
- platform.claude.com/docs/en/manage-claude/compliance-api-access
Research log
- redact-secret/redact-secret#774Research issue
- redact-secret/redact-secret#775Research issue
- redact-secret/redact-secret#862Research issue
- redact-secret/redact-secret#882Research issue