Skip to content
Benchmarks

redact-secret · Report

Enterprise organization key (sk-ant-api01-)

sk-ant-api01- prefixed key that Anthropic documents as a Compliance Access Key; the prefix is the general Claude Enterprise organization key for any scope set, so a finding must not claim 'compliance'.

  • Anthropic
  • Detectors: anthropic-api01-key
  • Run 2026-10-07
  • Mode published · redact-secret 0.1.0-beta.14
  • Dossier verdictReady
  • Dossier evidence levelT1 · Provider-documented
  • Dossier researched2026-09-27
Beta.10 arrival family anthropic-api01-key (#384, research redact-secret#776, product #862, #882). The product extends the shared anthropic-token detector; since product PR #882 (redact-secret#774) it reports its own anthropic_enterprise_api_key finding type (previously the shared anthropic_api_key type), so this family maps to no registry detector id but is scored on its own arrival id by finding type (scanners/families.mjs arrivalFindingTypes), never borrowing the status of anthropic:secret-api-key. T1 on the prefix only; the body is unspecified.

Research record

From credential-evidence snapshot-2026.10.06.4 · records at 77ce761 · schema 1.8.0. It describes the research on the format, not what any scanner or the product does, and not a support status.
  • Review stateDraft, not reviewed
  • Format revision1 · current
  • ResearchResearched
  • Researched2026-09-27

4 events in the review history: 3 observed, 1 reviewed. Latest: observed on 2026-10-03 by automation, project maintainer. Project-maintained review is not independent validation. The family record at this release.

Format

Provider format research from credential-evidence snapshot-2026.10.06.4 · records at 77ce761 · schema 1.8.0.

What it looks like

Descriptive pattern
^sk-ant-api01-[A-Za-z0-9_-]{20,}$

Parts are shown as recorded. Evidence classes belong to the facts below; no class is assigned to a part.

Format facts

  • Provider documented · provider-source · current · observed 2026-09-26

    Key type table: Compliance Access Key (sk-ant-api01-...): the provider documents sk-ant-api01- as the prefix of a Claude Enterprise key and quotes "sk-ant-api01- is a Compliance Access Key"; it states no body length, alphabet or tail

    • platform.claude.com/docs/en/manage-claude/compliance-api-accessprovider-documentation · last read 2026-10-04 · latest outcome read · supports the provider documents sk-ant-api01- as the prefix of a Claude Enterprise key and quotes "sk-ant-api01- is a Compliance Access Key"; it states no body length, alphabet or tail
  • Provider documented · field-prefix · current · observed 2026-09-26

    prefix: sk-ant-api01-

  • Provider documented · field-scope-of-prefix · current · observed 2026-09-26

    scope-of-prefix: the prefix is the Enterprise organization key for any scope set (compliance, analytics, spend limits, members), not a compliance-only credential

  • Unresolved · field-body · current · observed 2026-09-26

    body: an opaque URL-safe run; the product floor is 20 bytes of [A-Za-z0-9_-] (assumption, not evidence) (No length, alphabet or AA-tail twin is authored. Positives use the api03/admin01 93-character + AA shape only as a subset of the floor.)

  • Unresolved · field-aa-tail · current · observed 2026-09-26

    aa-tail: whether api01 keys end in AA as api03 and admin01 rules assume (Not claimed either way.)

  • Provider documented · field-header · current · observed 2026-09-26

    header: sent as x-api-key; the authentication page now recommends Authorization: Bearer for API keys

  • Unresolved · field-sibling-classes · current · observed 2026-09-26

    sibling-classes: sk-ant-api03- (Claude API key) and sk-ant-admin01- (Admin API key) are different provider classes; sk-ant-oat01-/sk-ant-ort01- (OAuth) and other versions have no provider source (Only api03 and admin01 back prefix twins. No fixture asserts silence on api02, api04, oat01, ort01 or an unversioned prefix.)

    • github.com/gitleaks/gitleaks/issues/2158provider-documentation · last read 2026-09-26 · latest outcome read · supports community request for oat01/ort01; no provider source
    • platform.claude.com/docs/en/manage-claude/admin-api-keysprovider-documentation · last read 2026-10-03 · latest outcome read · supports sibling-classes: sk-ant-api03- (Claude API key) and sk-ant-admin01- (Admin API key) are different provider classes; sk-ant-oat01-/sk-ant-ort01- (OAuth) and other versions have no provider source
  • Unresolved · field-encoded-form · current · observed 2026-09-26

    encoded-form: whether a Base64-encoded copy is in family scope (No Base64 fixture is authored.)

  • Unresolved · listed-references · current · observed 2026-09-26

    The legacy contract lists 4 references without stating which property each supports.

  • Provider documented · dossier-research · current · observed 2026-09-27

    Legacy dossier research (verdict ready, tier T1) cited 4 sources; the dossier does not attribute sources to individual properties.

  • Provider documented · taxonomy-sources · current · observed 2026-09-27

    The legacy taxonomy lists 2 sources for this family. The taxonomy records no date; the dossier researchedAt is used as the observed-at date.

Open questions

No open question is recorded for this revision.

Benchmark dossier notes

From the provider dossier, as written. The evidence level above says how well the format is backed; a fact the dossier does not record is not shown.
Shape
prefix sk-ant-api01-, created in claude.ai Organization settings > API, shown once, does not expire on its own. The same prefix is used for any scope set (compliance, analytics, spend limits, members), so the value does not say "compliance" and scope is not encoded in it. Body length, alphabet and tail: no evidence. Do not extrapolate the api03 body.
Basis
T1 prefix on the provider documentation pages in the frontmatter; the staff help center article covers issuance and "shown once" only. No scanner rule handles api01. Third-party vendor pages that repeat the prefix are community evidence and disagree with the provider on where the key is created.
Issuance
needs a Claude Enterprise parent organization and its primary owner or an organization owner, with the Compliance API enabled. A standalone Console organization cannot create one. The structural-facts checklist is in the #776 discovery comment.
Contract in core
detector-families.md. Whether the finding type should say "compliance" or "Enterprise" was a product decision raised in #776 and settled by #882: sk-ant-api01- keys get their own type, anthropic_enterprise_api_key, named for the general Enterprise scope and deliberately not "compliance" (#776 disposition).

In this benchmark

Fixture rows on the current run. Counts are for redact-secret in published · redact-secret 0.1.0-beta.14 mode.
Fixtures
37
Left readable
0
Redacted too much
0
False alarms
0

37 fixtures: 15 expect a redaction, 22 must stay quiet. See every row

redact-secret fixture counts by evidence level
Evidence levelFixturesLeft readableToo muchFalse alarms
T1Provider-documented19000
T3Project policy18000

Every scanner on the same fixtures

In run order. Counts are what each scanner recorded on this family's fixtures, whichever rules it has; a scanner with no rule for the family has nothing to report on it.

Counts per scanner on this family's fixtures
ScannerFixturesLeft readableToo muchFalse alarms
flare-redactRuntime library · 1.6.1 · Published npm package · secrets-only (pii, generic_assignment disabled) · JavaScript engine1 rule targets it37001
gitleaksRepository scanner · 8.30.1 · Directory scan · default rulesNo rule maps to it371303
redact-secretProduct measured here · 0.1.0-beta.14 · Published npm package · default detectors1 detector mapped37000
trufflehogRepository scanner · 3.97.4 · Filesystem scan · verification disabledNo rule maps to it371500

Benchmark dossier questions

Things the sources do not settle. They are listed so nobody reads them as settled.
Open caveat
Body length, alphabet and tail are unmeasured for this prefix; needs one issued Enterprise key (checklist in #776).

Looks like it, but isn't

Values the dossier records as resembling this credential without being one.
Collisions
sk-ant-api03- (Console Claude API key) and sk-ant-admin01- (admin key) differ only in the prefix segment and are distinct credential classes. Enterprise api01 keys are also a documented confusable in third-party integration guides, which reject the wrong type.

Scanner rules for this family

Mapped by hand (reviewed 2026-09-30) from each scanner's pinned rule file, never from what a scanner found on the fixtures.
Peer scanner rules that target this family
ScannerRuleWhat the rule matches
flare-redact · rules 1.6.1anthropic_keysk-ant- + 24-160 characters

No rule maps to this family in gitleaks, openredaction, trufflehog.

37 of 37 rows

Fixtures in this family

37 rows, redact-secret's outcome on each. Rows that need a look come first (0), then the rest in corpus order. Choose "Every scanner" to see each scanner's outcome for the same rows.
Fixtures in Enterprise organization key (sk-ant-api01-)
FixtureKind and evidenceredact-secret
anthropic-api01-key-admin01-prefix-twinanthropic · prefix-near-missMust not flagT1 · Provider-documented · twinQuiet
anthropic-api01-key-apl-letter-twinanthropic · prefix-near-missMust not flagT3 · Project policy · twinQuiet
anthropic-api01-key-buildkite-envanthropic · documented-format-literalMust redactT1 · Provider-documentedRedacted
anthropic-api01-key-compliance-export-yamlanthropic · documented-format-literalMust redactT1 · Provider-documentedRedacted
anthropic-api01-key-compose-envanthropic · documented-format-literalMust redactT1 · Provider-documentedRedacted
anthropic-api01-key-curl-x-api-keyanthropic · documented-format-literalMust redactT1 · Provider-documentedRedacted
anthropic-api01-key-dotenvanthropic · documented-format-literalMust redactT1 · Provider-documentedRedacted
anthropic-api01-key-exportanthropic · documented-format-literalMust redactT1 · Provider-documentedRedacted
anthropic-api01-key-go-const-longanthropic · documented-format-literalMust redactT1 · Provider-documentedRedacted
anthropic-api01-key-httpx-clientanthropic · documented-format-literalMust redactT1 · Provider-documentedRedacted
anthropic-api01-key-job-loganthropic · documented-format-literalMust redactT1 · Provider-documentedRedacted
anthropic-api01-key-json-configanthropic · documented-format-literalMust redactT1 · Provider-documentedRedacted
anthropic-api01-key-key-digest-encoded-valueanthropic · benign-encoded-valueMust not flagT3 · Project policyQuiet
anthropic-api01-key-pasted-keyanthropic · documented-format-literalMust redactT1 · Provider-documentedRedacted
anthropic-api01-key-python-sdkanthropic · documented-format-literalMust redactT1 · Provider-documentedRedacted
anthropic-api01-key-secretsmanager-getanthropic · documented-format-literalMust redactT1 · Provider-documentedRedacted
anthropic-api01-key-ticket-parenanthropic · documented-format-literalMust redactT1 · Provider-documentedRedacted
anthropic-api01-key-tool-callanthropic · documented-format-literalMust redactT1 · Provider-documentedRedacted
anthropic-api01-key-underscore-delimiters-twinanthropic · boundary-violationMust not flagT3 · Project policy · twinQuiet
anthropic-api01-key-actions-secret-referenceanthropic · templated-referenceMust not flagT3 · Project policyQuiet
anthropic-api01-key-activity-feed-public-idanthropic · public-identifierMust not flagT3 · Project policyQuiet
anthropic-api01-key-activity-ids-public-idanthropic · public-identifierMust not flagT3 · Project policyQuiet
anthropic-api01-key-allowlist-comment-near-missanthropic · format-near-missMust not flagT1 · Provider-documentedQuiet
anthropic-api01-key-angle-key-placeholderanthropic · documentation-placeholderMust not flagT3 · Project policyQuiet
anthropic-api01-key-api03-prefix-twinanthropic · prefix-near-missMust not flagT1 · Provider-documented · twinQuiet
anthropic-api01-key-body-only-twinanthropic · prefix-near-missMust not flagT3 · Project policy · twinQuiet
anthropic-api01-key-docs-ellipsis-placeholderanthropic · documentation-placeholderMust not flagT3 · Project policyQuiet
anthropic-api01-key-embedded-leading-twinanthropic · boundary-violationMust not flagT3 · Project policy · twinQuiet
anthropic-api01-key-env-reference-referenceanthropic · templated-referenceMust not flagT3 · Project policyQuiet
anthropic-api01-key-fingerprint-table-encoded-valueanthropic · benign-encoded-valueMust not flagT3 · Project policyQuiet
anthropic-api01-key-masked-display-placeholderanthropic · documentation-placeholderMust not flagT3 · Project policyQuiet
anthropic-api01-key-prefix-guidance-proseanthropic · prose-mentionMust not flagT3 · Project policyQuiet
anthropic-api01-key-prefix-only-near-missanthropic · format-near-missMust not flagT1 · Provider-documentedQuiet
anthropic-api01-key-procurement-note-proseanthropic · prose-mentionMust not flagT3 · Project policyQuiet
anthropic-api01-key-uppercase-prefix-twinanthropic · prefix-near-missMust not flagT3 · Project policy · twinQuiet
anthropic-api01-key-vault-path-referenceanthropic · templated-referenceMust not flagT3 · Project policyQuiet
anthropic-api01-key-version-and-org-public-idanthropic · public-identifierMust not flagT3 · Project policyQuiet

Sources

Researched 2026-09-27.

Documentation and code

Other Anthropic families