redact-secret · Report
Enterprise organization key (sk-ant-api01-)
sk-ant-api01- prefixed key that Anthropic documents as a Compliance Access Key; the prefix is the general Claude Enterprise organization key for any scope set, so a finding must not claim 'compliance'.
Research record
4 events in the review history: 3 observed, 1 reviewed. Latest: observed on 2026-10-03 by automation, project maintainer. Project-maintained review is not independent validation. The family record at this release.
Format
What it looks like
- Descriptive pattern
^sk-ant-api01-[A-Za-z0-9_-]{20,}$
Parts are shown as recorded. Evidence classes belong to the facts below; no class is assigned to a part.
Format facts
Provider documented ·
provider-source· current · observed 2026-09-26Key type table: Compliance Access Key (sk-ant-api01-...): the provider documents sk-ant-api01- as the prefix of a Claude Enterprise key and quotes "sk-ant-api01- is a Compliance Access Key"; it states no body length, alphabet or tail
- platform.claude.com/docs/en/manage-claude/compliance-api-accessprovider-documentation · last read 2026-10-04 · latest outcome read · supports the provider documents sk-ant-api01- as the prefix of a Claude Enterprise key and quotes "sk-ant-api01- is a Compliance Access Key"; it states no body length, alphabet or tail
Provider documented ·
field-prefix· current · observed 2026-09-26prefix: sk-ant-api01-
- platform.claude.com/docs/en/manage-claude/compliance-api-accessprovider-documentation · last read 2026-10-04 · latest outcome read · supports "sk-ant-api01- is a Compliance Access Key"
- platform.claude.com/docs/en/manage-claude/admin-api-keysprovider-documentation · last read 2026-10-03 · latest outcome read · supports table: Claude Enterprise organization key prefix
Provider documented ·
field-scope-of-prefix· current · observed 2026-09-26scope-of-prefix: the prefix is the Enterprise organization key for any scope set (compliance, analytics, spend limits, members), not a compliance-only credential
- github.com/redact-secret/redact-secret/issues/776provider-documentation · last read 2026-09-26 · latest outcome read · supports research finding 6
- platform.claude.com/docs/en/manage-claude/admin-api-keysprovider-documentation · last read 2026-10-03 · latest outcome read · supports scope-of-prefix: the prefix is the Enterprise organization key for any scope set (compliance, analytics, spend limits, members), not a compliance-only credential
Unresolved ·
field-body· current · observed 2026-09-26body: an opaque URL-safe run; the product floor is 20 bytes of [A-Za-z0-9_-] (assumption, not evidence) (No length, alphabet or AA-tail twin is authored. Positives use the api03/admin01 93-character + AA shape only as a subset of the floor.)
- github.com/redact-secret/redact-secret/issues/776provider-documentation · last read 2026-09-26 · latest outcome read · supports no provider, tool or observation states a length for api01
Unresolved ·
field-aa-tail· current · observed 2026-09-26aa-tail: whether api01 keys end in AA as api03 and admin01 rules assume (Not claimed either way.)
- github.com/redact-secret/redact-secret/issues/776provider-documentation · last read 2026-09-26 · latest outcome read · supports hands-on checklist item
Provider documented ·
field-header· current · observed 2026-09-26header: sent as x-api-key; the authentication page now recommends Authorization: Bearer for API keys
- platform.claude.com/docs/en/manage-claude/admin-apiprovider-documentation · last read 2026-09-27 · latest outcome read · supports header: sent as x-api-key; the authentication page now recommends Authorization: Bearer for API keys
- platform.claude.com/docs/en/manage-claude/authenticationprovider-documentation · last read 2026-10-04 · latest outcome read · supports header: sent as x-api-key; the authentication page now recommends Authorization: Bearer for API keys
Unresolved ·
field-sibling-classes· current · observed 2026-09-26sibling-classes: sk-ant-api03- (Claude API key) and sk-ant-admin01- (Admin API key) are different provider classes; sk-ant-oat01-/sk-ant-ort01- (OAuth) and other versions have no provider source (Only api03 and admin01 back prefix twins. No fixture asserts silence on api02, api04, oat01, ort01 or an unversioned prefix.)
- github.com/gitleaks/gitleaks/issues/2158provider-documentation · last read 2026-09-26 · latest outcome read · supports community request for oat01/ort01; no provider source
- platform.claude.com/docs/en/manage-claude/admin-api-keysprovider-documentation · last read 2026-10-03 · latest outcome read · supports sibling-classes: sk-ant-api03- (Claude API key) and sk-ant-admin01- (Admin API key) are different provider classes; sk-ant-oat01-/sk-ant-ort01- (OAuth) and other versions have no provider source
Unresolved ·
field-encoded-form· current · observed 2026-09-26encoded-form: whether a Base64-encoded copy is in family scope (No Base64 fixture is authored.)
- github.com/redact-secret/redact-secret/issues/776provider-documentation · last read 2026-09-26 · latest outcome read · supports encoded-form: whether a Base64-encoded copy is in family scope
Unresolved ·
listed-references· current · observed 2026-09-26The legacy contract lists 4 references without stating which property each supports.
- github.com/redact-secret/redact-secret/issues/862issue-or-discussion · last read 2026-09-26 · latest outcome read · supports Listed as a reference by the legacy contract
- github.com/redact-secret/redact-secret/issues/776provider-documentation · last read 2026-09-26 · latest outcome read · supports Listed as a reference by the legacy contract
- platform.claude.com/docs/en/manage-claude/admin-api-keysprovider-documentation · last read 2026-10-03 · latest outcome read · supports Listed as a reference by the legacy contract
- platform.claude.com/docs/en/manage-claude/authenticationprovider-documentation · last read 2026-10-04 · latest outcome read · supports Listed as a reference by the legacy contract
Provider documented ·
dossier-research· current · observed 2026-09-27Legacy dossier research (verdict ready, tier T1) cited 4 sources; the dossier does not attribute sources to individual properties.
- platform.claude.com/docs/en/manage-claude/compliance-api-accessprovider-documentation · last read 2026-10-04 · latest outcome read · supports Cited by the legacy dossier research for this family
- platform.claude.com/docs/en/manage-claude/compliance-activity-feedprovider-documentation · last read 2026-09-27 · latest outcome read · supports Cited by the legacy dossier research for this family
- platform.claude.com/docs/en/manage-claude/admin-api-keysprovider-documentation · last read 2026-10-03 · latest outcome read · supports Cited by the legacy dossier research for this family
- support.claude.com/en/articles/13015708-access-the-compliance-apiprovider-documentation · last read 2026-09-27 · latest outcome read · supports Cited by the legacy dossier research for this family
Provider documented ·
taxonomy-sources· current · observed 2026-09-27The legacy taxonomy lists 2 sources for this family. The taxonomy records no date; the dossier researchedAt is used as the observed-at date.
- platform.claude.com/docs/en/manage-claude/compliance-api-accessprovider-documentation · last read 2026-10-04 · latest outcome read · supports Listed as a source for this family in the legacy taxonomy
- platform.claude.com/docs/en/manage-claude/admin-api-keysprovider-documentation · last read 2026-10-03 · latest outcome read · supports Listed as a source for this family in the legacy taxonomy
Open questions
No open question is recorded for this revision.
Benchmark dossier notes
- Shape
- prefix
sk-ant-api01-, created in claude.ai Organization settings > API, shown once, does not expire on its own. The same prefix is used for any scope set (compliance, analytics, spend limits, members), so the value does not say "compliance" and scope is not encoded in it. Body length, alphabet and tail: no evidence. Do not extrapolate theapi03body. - Basis
- T1 prefix on the provider documentation pages in the frontmatter; the staff help center article covers issuance and "shown once" only. No scanner rule handles
api01. Third-party vendor pages that repeat the prefix are community evidence and disagree with the provider on where the key is created. - Issuance
- needs a Claude Enterprise parent organization and its primary owner or an organization owner, with the Compliance API enabled. A standalone Console organization cannot create one. The structural-facts checklist is in the #776 discovery comment.
- Contract in core
- detector-families.md. Whether the finding type should say "compliance" or "Enterprise" was a product decision raised in #776 and settled by #882:
sk-ant-api01-keys get their own type,anthropic_enterprise_api_key, named for the general Enterprise scope and deliberately not "compliance" (#776 disposition).
In this benchmark
- Fixtures
- 37
- Left readable
- 0
- Redacted too much
- 0
- False alarms
- 0
37 fixtures: 15 expect a redaction, 22 must stay quiet. See every row
| Evidence level | Fixtures | Left readable | Too much | False alarms |
|---|---|---|---|---|
| T1Provider-documented | 19 | 0 | 0 | 0 |
| T3Project policy | 18 | 0 | 0 | 0 |
Every scanner on the same fixtures
In run order. Counts are what each scanner recorded on this family's fixtures, whichever rules it has; a scanner with no rule for the family has nothing to report on it.
| Scanner | Fixtures | Left readable | Too much | False alarms |
|---|---|---|---|---|
| flare-redactRuntime library · 1.6.1 · Published npm package · secrets-only (pii, generic_assignment disabled) · JavaScript engine1 rule targets it | 37 | 0 | 0 | 1 |
| gitleaksRepository scanner · 8.30.1 · Directory scan · default rulesNo rule maps to it | 37 | 13 | 0 | 3 |
| redact-secretProduct measured here · 0.1.0-beta.14 · Published npm package · default detectors1 detector mapped | 37 | 0 | 0 | 0 |
| trufflehogRepository scanner · 3.97.4 · Filesystem scan · verification disabledNo rule maps to it | 37 | 15 | 0 | 0 |
Benchmark dossier questions
- Open caveat
- Body length, alphabet and tail are unmeasured for this prefix; needs one issued Enterprise key (checklist in #776).
Looks like it, but isn't
- Collisions
sk-ant-api03-(Console Claude API key) andsk-ant-admin01-(admin key) differ only in the prefix segment and are distinct credential classes. Enterpriseapi01keys are also a documented confusable in third-party integration guides, which reject the wrong type.
Scanner rules for this family
| Scanner | Rule | What the rule matches |
|---|---|---|
| flare-redact · rules 1.6.1 | anthropic_key | sk-ant- + 24-160 characters |
No rule maps to this family in gitleaks, openredaction, trufflehog.
Fixtures in this family
| Fixture | Kind and evidence | redact-secret |
|---|---|---|
anthropic-api01-key-admin01-prefix-twinanthropic · prefix-near-miss | Must not flagT1 · Provider-documented · twin | Quiet |
anthropic-api01-key-apl-letter-twinanthropic · prefix-near-miss | Must not flagT3 · Project policy · twin | Quiet |
anthropic-api01-key-buildkite-envanthropic · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
anthropic-api01-key-compliance-export-yamlanthropic · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
anthropic-api01-key-compose-envanthropic · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
anthropic-api01-key-curl-x-api-keyanthropic · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
anthropic-api01-key-dotenvanthropic · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
anthropic-api01-key-exportanthropic · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
anthropic-api01-key-go-const-longanthropic · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
anthropic-api01-key-httpx-clientanthropic · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
anthropic-api01-key-job-loganthropic · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
anthropic-api01-key-json-configanthropic · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
anthropic-api01-key-key-digest-encoded-valueanthropic · benign-encoded-value | Must not flagT3 · Project policy | Quiet |
anthropic-api01-key-pasted-keyanthropic · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
anthropic-api01-key-python-sdkanthropic · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
anthropic-api01-key-secretsmanager-getanthropic · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
anthropic-api01-key-ticket-parenanthropic · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
anthropic-api01-key-tool-callanthropic · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
anthropic-api01-key-underscore-delimiters-twinanthropic · boundary-violation | Must not flagT3 · Project policy · twin | Quiet |
anthropic-api01-key-actions-secret-referenceanthropic · templated-reference | Must not flagT3 · Project policy | Quiet |
anthropic-api01-key-activity-feed-public-idanthropic · public-identifier | Must not flagT3 · Project policy | Quiet |
anthropic-api01-key-activity-ids-public-idanthropic · public-identifier | Must not flagT3 · Project policy | Quiet |
anthropic-api01-key-allowlist-comment-near-missanthropic · format-near-miss | Must not flagT1 · Provider-documented | Quiet |
anthropic-api01-key-angle-key-placeholderanthropic · documentation-placeholder | Must not flagT3 · Project policy | Quiet |
anthropic-api01-key-api03-prefix-twinanthropic · prefix-near-miss | Must not flagT1 · Provider-documented · twin | Quiet |
anthropic-api01-key-body-only-twinanthropic · prefix-near-miss | Must not flagT3 · Project policy · twin | Quiet |
anthropic-api01-key-docs-ellipsis-placeholderanthropic · documentation-placeholder | Must not flagT3 · Project policy | Quiet |
anthropic-api01-key-embedded-leading-twinanthropic · boundary-violation | Must not flagT3 · Project policy · twin | Quiet |
anthropic-api01-key-env-reference-referenceanthropic · templated-reference | Must not flagT3 · Project policy | Quiet |
anthropic-api01-key-fingerprint-table-encoded-valueanthropic · benign-encoded-value | Must not flagT3 · Project policy | Quiet |
anthropic-api01-key-masked-display-placeholderanthropic · documentation-placeholder | Must not flagT3 · Project policy | Quiet |
anthropic-api01-key-prefix-guidance-proseanthropic · prose-mention | Must not flagT3 · Project policy | Quiet |
anthropic-api01-key-prefix-only-near-missanthropic · format-near-miss | Must not flagT1 · Provider-documented | Quiet |
anthropic-api01-key-procurement-note-proseanthropic · prose-mention | Must not flagT3 · Project policy | Quiet |
anthropic-api01-key-uppercase-prefix-twinanthropic · prefix-near-miss | Must not flagT3 · Project policy · twin | Quiet |
anthropic-api01-key-vault-path-referenceanthropic · templated-reference | Must not flagT3 · Project policy | Quiet |
anthropic-api01-key-version-and-org-public-idanthropic · public-identifier | Must not flagT3 · Project policy | Quiet |
Sources
Documentation and code
- platform.claude.com/docs/en/manage-claude/compliance-api-access
- platform.claude.com/docs/en/manage-claude/admin-api-keys
- platform.claude.com/docs/en/manage-claude/compliance-activity-feed
- support.claude.com/en/articles/13015708-access-the-compliance-api
Research log
- redact-secret/redact-secret#774Research issue
- redact-secret/redact-secret#776Research issue
- redact-secret/redact-secret#862Research issue
- redact-secret/redact-secret#882Research issue