redact-secret · Report
API token (apify_api_)
apify_api_ + at least 20 alphanumerics, open-ended (the provider's own leak linter); apify_ui_ Console tokens are a separate, unshaped credential.
Research record
3 events in the review history: 2 observed, 1 reviewed. Latest: observed on 2026-09-28 by automation, project maintainer. Project-maintained review is not independent validation. The family record at this release.
Format
What it looks like
- Descriptive pattern
^apify_api_[A-Za-z0-9]{20,}$
Parts are shown as recorded. Evidence classes belong to the facts below; no class is assigned to a part.
Format facts
Provider documented ·
provider-source· current · observed 2026-09-28apify/awesome-skills lint_references.py TOKEN_RE = apify_api_[A-Za-z0-9]{20,} (added in 4ba9177 by an Apify collaborator, 2026-08-12; ruling R2) and the apify_api_... docs placeholders (ruling R4): apify_api_ + at least 20 alphanumerics, open-ended; no separator or checksum
- apify/awesome-skills @ main: scripts/lint_references.pyprovider-documentation · last read 2026-09-28 · latest outcome read · supports apify_api_ + at least 20 alphanumerics, open-ended; no separator or checksum
Unresolved ·
tool-corroboration· current · observed 2026-09-28Pinned scanner rules are consistent with the contract grammar (1 artifact: trufflehog 3.97.4).
- trufflesecurity/trufflehog @ v3.97.4: pkg/detectors/apify/apify.goscanner-rule-source · last read 2026-09-28 · latest outcome read · supports trufflehog 3.97.4: Apify: \b(apify\_api\_[a-zA-Z-0-9]{36})\b, exact 36 (T2, not used)
Provider documented ·
field-prefix· current · observed 2026-09-28prefix: apify_api_
- docs.apify.com/platform/integrations/apiprovider-documentation · last read 2026-09-28 · latest outcome read · supports apify_api_... placeholders
- github.com/redact-secret/redact-secret/issues/860issue-or-discussion · last read 2026-09-29 · latest outcome read · supports R4: a placeholder is T1 for its prefix · #issuecomment-5871306275
Provider documented ·
field-alphabet· current · observed 2026-09-28alphabet: [A-Za-z0-9]
- github.com/apify/awesome-skills/commit/4ba9177da814provider-sdk-source · last read 2026-09-28 · latest outcome read · supports provider-authored, R2
- apify/awesome-skills @ main: scripts/lint_references.pyprovider-documentation · last read 2026-09-28 · latest outcome read · supports TOKEN_RE
Provider documented ·
field-floor· current · observed 2026-09-28floor: at least 20 body characters, open-ended
- apify/awesome-skills @ main: scripts/lint_references.pyprovider-documentation · last read 2026-09-28 · latest outcome read · supports {20,}
- github.com/redact-secret/redact-secret/issues/860issue-or-discussion · last read 2026-09-29 · latest outcome read · supports R2 · #issuecomment-5871306275
Unresolved ·
field-upper-bound· current · observed 2026-09-28upper-bound: the product caps the run at 128 for streaming (Not a provider fact, and the provider's own rule would flag a longer run: positives reach 128, and no fixture asserts silence on 129.)
- redact-secret/redact-secret @ 54fe385f718c884d7e3dde6b9756e2d70999ca91: docs/audits/evidence/860/apify.mdprovider-sdk-source · last read 2026-09-28 · latest outcome read · supports project policy; the only observed width is 36
Unresolved ·
field-observed-width· current · observed 2026-09-28observed-width: every observed token body is 36 (Default positives carry 36; the 20 and 128 positives exercise the provider floor and the policy cap.)
- trufflesecurity/trufflehog @ v3.97.4: pkg/detectors/apify/apify.goscanner-rule-source · last read 2026-09-28 · latest outcome read · supports exact 36
Unresolved ·
field-console-token· current · observed 2026-09-28console-token: apify_ui_ Console tokens are a separate credential whose length and alphabet no source states (Only the short apify_ui_test identifier appears, as a control; no full Console token is authored either way.)
- github.com/apify/apify-mcp-serverprovider-sdk-source · last read 2026-09-28 · latest outcome read · supports startsWith(UI_TOKEN_PREFIX), R6
- redact-secret/redact-secret @ 54fe385f718c884d7e3dde6b9756e2d70999ca91: docs/audits/evidence/860/apify.mdprovider-sdk-source · last read 2026-09-28 · latest outcome read · supports console-token: apify_ui_ Console tokens are a separate credential whose length and alphabet no source states
Provider documented ·
field-transport· current · observed 2026-09-28transport: the APIFY_TOKEN environment variable, sent as Authorization: Bearer or a token query parameter
- docs.apify.com/api/v2provider-documentation · last read 2026-09-28 · latest outcome read · supports transport: the APIFY_TOKEN environment variable, sent as Authorization: Bearer or a token query parameter
Tool corroborated ·
field-peer-lag· current · observed 2026-09-28peer-lag: trufflehog 3.97.4 has an apify detector (exact 36); gitleaks 8.30.1 has no Apify rule
- gitleaks/gitleaks @ v8.30.1: config/gitleaks.tomlscanner-rule-source · last read 2026-10-04 · latest outcome read · supports no apify rule
- trufflesecurity/trufflehog @ v3.97.4: pkg/detectors/apify/apify.goscanner-rule-source · last read 2026-09-28 · latest outcome read · supports peer-lag: trufflehog 3.97.4 has an apify detector (exact 36); gitleaks 8.30.1 has no Apify rule
Unresolved ·
listed-references· current · observed 2026-09-28The legacy contract lists 11 references without stating which property each supports.
- docs.apify.com/api/v2provider-documentation · last read 2026-09-28 · latest outcome read · supports Listed as a reference by the legacy contract
- docs.apify.com/platform/integrations/apiprovider-documentation · last read 2026-09-28 · latest outcome read · supports Listed as a reference by the legacy contract
- github.com/apify/apify-mcp-serverprovider-sdk-source · last read 2026-09-28 · latest outcome read · supports Listed as a reference by the legacy contract
- github.com/apify/awesome-skills/commit/4ba9177da814provider-sdk-source · last read 2026-09-28 · latest outcome read · supports Listed as a reference by the legacy contract
- apify/awesome-skills @ main: scripts/lint_references.pyprovider-documentation · last read 2026-09-28 · latest outcome read · supports Listed as a reference by the legacy contract
- github.com/redact-secret/redact-secret/issues/916issue-or-discussion · last read 2026-09-28 · latest outcome read · supports Listed as a reference by the legacy contract
- redact-secret/redact-secret @ 54fe385f718c884d7e3dde6b9756e2d70999ca91: docs/audits/evidence/860/tier-b-rerank.mdproject-research-note · last read 2026-09-28 · latest outcome read · supports Listed as a reference by the legacy contract
- redact-secret/redact-secret @ 54fe385f718c884d7e3dde6b9756e2d70999ca91: docs/audits/evidence/860/apify.mdprovider-sdk-source · last read 2026-09-28 · latest outcome read · supports Listed as a reference by the legacy contract
- github.com/redact-secret/redact-secret/issues/860issue-or-discussion · last read 2026-09-29 · latest outcome read · supports Listed as a reference by the legacy contract · #issuecomment-5871306275
- github.com/redact-secret/redact-secret/issues/860issue-or-discussion · last read 2026-09-29 · latest outcome read · supports Listed as a reference by the legacy contract
- github.com/redact-secret/redact-secret-benchmarks/issues/436issue-or-discussion · last read 2026-09-28 · latest outcome read · supports Listed as a reference by the legacy contract
Provider documented ·
dossier-research· current · observed 2026-09-28Legacy dossier research (verdict ready, tier T1) cited 2 sources; the dossier does not attribute sources to individual properties.
- apify/awesome-skills @ 4ba9177da8147607eaebea8022ea6f14b212a8cd: scripts/lint_references.pyother · last read 2026-09-28 · latest outcome read · supports Cited by the legacy dossier research for this family
- redact-secret/redact-secret @ 8b6a5fde52ecb4dfce13f09c7a947062d21483c7: docs/audits/evidence/860/apify.mdproject-research-note · last read 2026-09-28 · latest outcome read · supports Final research evidence recorded by the legacy dossier
Provider documented ·
taxonomy-sources· current · observed 2026-09-28The legacy taxonomy lists 2 sources for this family. The taxonomy records no date; the dossier researchedAt is used as the observed-at date.
- docs.apify.com/platform/integrations/apiprovider-documentation · last read 2026-09-28 · latest outcome read · supports Listed as a source for this family in the legacy taxonomy
- apify/awesome-skills @ main: scripts/lint_references.pyprovider-documentation · last read 2026-09-28 · latest outcome read · supports Listed as a source for this family in the legacy taxonomy
Open questions
No open question is recorded for this revision.
Benchmark dossier notes
- Shape
- prefix
apify_api_, then alphanumerics, at least 20, no separators or checksum. No provider source states an exact length; the only observed width is 36 (trufflehog rule, T2). The 128 upper bound in the handoff is project policy for a bounded run, not a provider fact. - Basis
- prefix T1 from the docs placeholders (ruling R4: a placeholder establishes the prefix only). Alphabet
[A-Za-z0-9]and the floor of 20 are T1 from the provider's own leak linter inapify/awesome-skills, checked for provider authorship on 2026-09-28 (R2). trufflehog's rule (exact 36, a wider class) is T2 and was not used to narrow the grammar. - Issuance
- not attempted. An optional structure-only check (one personal, one organization, one scoped token) could show whether 36 is uniform.
- Contract in core
- detector-families.md; handoff linked in the frontmatter.
In this benchmark
- Fixtures
- 38
- Left readable
- 0
- Redacted too much
- 0
- False alarms
- 0
38 fixtures: 16 expect a redaction, 22 must stay quiet. See every row
| Evidence level | Fixtures | Left readable | Too much | False alarms |
|---|---|---|---|---|
| T1Provider-documented | 16 | 0 | 0 | 0 |
| T2Tool-corroborated | 13 | 0 | 0 | 0 |
| T3Project policy | 9 | 0 | 0 | 0 |
Every scanner on the same fixtures
In run order. Counts are what each scanner recorded on this family's fixtures, whichever rules it has; a scanner with no rule for the family has nothing to report on it.
| Scanner | Fixtures | Left readable | Too much | False alarms |
|---|---|---|---|---|
| flare-redactRuntime library · 1.6.1 · Published npm package · secrets-only (pii, generic_assignment disabled) · JavaScript engineNo rule maps to it | 38 | 14 | 2 | 0 |
| gitleaksRepository scanner · 8.30.1 · Directory scan · default rulesNo rule maps to it | 38 | 7 | 0 | 0 |
| redact-secretProduct measured here · 0.1.0-beta.14 · Published npm package · default detectors1 detector mapped | 38 | 0 | 0 | 0 |
| trufflehogRepository scanner · 3.97.4 · Filesystem scan · verification disabled1 rule targets it | 38 | 2 | 0 | 1 |
Benchmark dossier questions
- Open caveat
- Length is open-ended by construction (floor of 20); an issuance check could narrow it but nothing requires one. The upper cap of 128 is project policy.
Looks like it, but isn't
- Collisions
apify_ui_Console session tokens are a documented sibling with a T1 prefix (R6) but no length or alphabet source. Placeholders such as a prefix followed by a word break the alphanumeric run below 20 characters.
Scanner rules for this family
| Scanner | Rule | What the rule matches |
|---|---|---|
| trufflehog · rules 3.97.4 | apify | apify_api_ + 36 characters |
No rule maps to this family in flare-redact, gitleaks, openredaction.
Fixtures in this family
| Fixture | Kind and evidence | redact-secret |
|---|---|---|
apify-api-token-bare-proseapify · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
apify-api-token-bearer-headerapify · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
apify-api-token-chat-pasteapify · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
apify-api-token-curl-bearerapify · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
apify-api-token-dotenvapify · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
apify-api-token-exportapify · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
apify-api-token-js-clientapify · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
apify-api-token-json-api-keyapify · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
apify-api-token-json-tokenapify · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
apify-api-token-key-shape-bareapify · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
apify-api-token-key-shape-quotedapify · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
apify-api-token-key-shape-unicode-crlfapify · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
apify-api-token-mcp-envapify · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
apify-api-token-python-positionalapify · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
apify-api-token-sdk-kwargapify · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
apify-api-token-trailing-hyphen-twinapify · boundary-violation | Must not flagT2 · Tool-corroborated · twin | Quiet |
apify-api-token-x-api-key-headerapify · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
apify-api-token-actions-secret-referenceapify · templated-reference | Must not flagT3 · Project policy | Quiet |
apify-api-token-body-19-twinapify · wrong-length | Must not flagT2 · Tool-corroborated · twin | Quiet |
apify-api-token-console-token-name-public-idapify · public-identifier | Must not flagT2 · Tool-corroborated | Quiet |
apify-api-token-ellipsis-placeholderapify · documentation-placeholder | Must not flagT3 · Project policy | Quiet |
apify-api-token-env-reference-referenceapify · templated-reference | Must not flagT3 · Project policy | Quiet |
apify-api-token-hyphen-prefix-twinapify · boundary-violation | Must not flagT2 · Tool-corroborated · twin | Quiet |
apify-api-token-identifiers-public-idapify · public-identifier | Must not flagT2 · Tool-corroborated | Quiet |
apify-api-token-label-proseapify · benign-lookalike | Must not flagT3 · Project policy | Quiet |
apify-api-token-leading-glue-twinapify · boundary-violation | Must not flagT2 · Tool-corroborated · twin | Quiet |
apify-api-token-maskapify · benign-lookalike | Must not flagT3 · Project policy | Quiet |
apify-api-token-prefix-at-eol-near-missapify · format-near-miss | Must not flagT2 · Tool-corroborated | Quiet |
apify-api-token-prefix-onlyapify · benign-lookalike | Must not flagT2 · Tool-corroborated | Quiet |
apify-api-token-referenceapify · benign-lookalike | Must not flagT3 · Project policy | Quiet |
apify-api-token-short-bodyapify · benign-lookalike | Must not flagT2 · Tool-corroborated | Quiet |
apify-api-token-short-body-near-missapify · format-near-miss | Must not flagT2 · Tool-corroborated | Quiet |
apify-api-token-test-names-placeholderapify · documentation-placeholder | Must not flagT3 · Project policy | Quiet |
apify-api-token-token-guidance-proseapify · prose-mention | Must not flagT3 · Project policy | Quiet |
apify-api-token-trailing-underscore-twinapify · boundary-violation | Must not flagT2 · Tool-corroborated · twin | Quiet |
apify-api-token-underscore-in-body-twinapify · wrong-alphabet | Must not flagT2 · Tool-corroborated · twin | Quiet |
apify-api-token-uppercase-prefix-twinapify · prefix-near-miss | Must not flagT2 · Tool-corroborated · twin | Quiet |
apify-api-token-your-token-placeholderapify · documentation-placeholder | Must not flagT3 · Project policy | Quiet |
Sources
Documentation and code
- docs.apify.com/platform/integrations/api
- github.com/apify/awesome-skills/blob/main/scripts/lint_references.py
- github.com/apify/awesome-skills/blob/4ba9177da8147607eaebea8022ea6f14b212a8cd/scripts/lint_references.py
Research log
- redact-secret/redact-secret#860Research issue
- redact-secret/redact-secret#916Research issue
- redact-secret/redact-secret-benchmarks#436Research issue
- Final evidence, pinned to a commit/redact-secret/redact-secret/blob/8b6a5fde52ecb4dfce13f09c7a947062d21483c7/docs/audits/evidence/860/apify.md