Skip to content
Benchmarks

redact-secret · Report

Access token

ATCT prefixed access token.

  • Atlassian
  • Detectors: none mapped
  • Run 2026-10-07
  • Mode published · redact-secret 0.1.0-beta.14
  • Dossier verdictIssuance-gated
  • Dossier evidence levelT0 · Pending
  • Dossier researched2026-09-29
atlassian-api-token's contract review states the pinned TruffleHog detector targets the distinct ATCT access-token family, not the ATAT-prefixed API-token shape.

Research record

From credential-evidence snapshot-2026.10.06.4 · records at 77ce761 · schema 1.8.0. It describes the research on the format, not what any scanner or the product does, and not a support status.
  • Review stateDraft, not reviewed
  • Format revision1 · proposed, none current
  • ResearchResearched
  • Researched2026-09-29

What blocks the research

  • Issuance-gatedThe ATCT prefix needs an R3 ruling on the Atlassian Team community answer; the body layout (header, length, = position, CRC tail) rests on two peer rules (one class). Needs one Bitbucket access token measured.

2 events in the review history: 1 observed, 1 reviewed. Latest: observed on 2026-09-29 by automation, project maintainer. Project-maintained review is not independent validation. The family record at this release.

Format

Provider format research from credential-evidence snapshot-2026.10.06.4 · records at 77ce761 · schema 1.8.0.

What it looks like

Shape not recorded.

Format facts

Open questions

No open question is recorded for this revision.

Benchmark dossier notes

From the provider dossier, as written. The evidence level above says how well the format is backed; a fact the dossier does not record is not shown.
Shape
prefix ATCT. Observed tokens are 192 characters with the same layout as the API token: a fixed 12-character header (ATCTT3xFfGN0, the fourth and fifth characters differ from the ATATT3xFfGF0 API-token header), a 171-character body from [A-Za-z0-9_-], one literal =, then 8 uppercase hex characters. The trailing 8 are a CRC32 of everything before them, = included, in two independent readings (CredSweeper's filter and the measurement below). Auth scheme: Bearer, or x-token-auth as the Basic user name for git over HTTPS; the provider pages show {repository_access_token} and {workspace_access_token} placeholders and no shape.
Issuance
not attempted; a Bitbucket repository access token is free to mint and revoke, which would settle the prefix length question below (evidence checklist item 8 in the #643 record). The #1012 check (repository access token in a free workspace, optionally one organization admin API key): whether it starts ATCTT3xFfGN0, total length (192?), exactly one = and its position, whether the last 8 bytes are [0-9A-F], whether CRC32 of the preceding bytes equals that tail, and whether the part before = is only [A-Za-z0-9_-]. Then revoke.
Contract in core
none. atlassian-api-token covers ATAT only; the taxonomy note records that the pinned TruffleHog detector targets this family.

In this benchmark

Fixture rows on the current run. Counts are for redact-secret in published · redact-secret 0.1.0-beta.14 mode.

No fixtures in this family yet

Nothing in the corpus targets it, so nothing is measured and no coverage is claimed.

Not measured

Benchmark dossier questions

Things the sources do not settle. They are listed so nobody reads them as settled.
Blocked by
The ATCT prefix needs an R3 ruling on the Atlassian Team community answer; the body layout (header, length, = position, CRC tail) rests on two peer rules (one class). Needs one Bitbucket access token measured.
Open caveat
the anchor length is unsettled (staff say ATCT, tools use 10 or 12 characters, and every observed value shares 12); the = plus 8 hex tail is empirical. A fresh token minted through each route (repository, project, workspace, admin key, service account) would confirm all routes share one header.

Looks like it, but isn't

Values the dossier records as resembling this credential without being one.
Collisions
shares the layout of atlassian:api-token (ATAT) and of the dead ATBB app passwords; the header differs, so an ATAT-anchored rule does not match it. Bitbucket Data Center HTTP access tokens (BBDC- prefix, from CredSweeper's rule list) and Jira/Confluence Data Center personal access tokens are different, unprefixed-by-AT credentials and are not this family.

Scanner rules for this family

Mapped by hand (reviewed 2026-09-30) from each scanner's pinned rule file, never from what a scanner found on the fixtures.
Peer scanner rules that target this family
ScannerRuleWhat the rule matches
trufflehog · rules 3.97.4atlassian/v2ATCTT3xFfG + Base64 payload

No rule maps to this family in flare-redact, gitleaks, openredaction.

0 of 0 rows

No fixtures in this family yet

Nothing in the corpus targets it, so nothing is measured and no coverage is claimed.

Not measured

Sources

Researched 2026-09-29.

Documentation and code

  • community.atlassian.com/forums/Bitbucket-questions/Can-we-confirm-BitBucket-s-token-prefixes/qaq-p/3093481
  • support.atlassian.com/bitbucket-cloud/docs/using-access-tokens/
  • github.com/trufflesecurity/trufflehog/blob/48b58d3bf3f02ba17bf23b87f095499bc80c6fd7/pkg/detectors/atlassian/v2/atlassian.go
  • github.com/trufflesecurity/trufflehog/pull/3065
  • github.com/Samsung/CredSweeper/blob/f21ab2f2553eea288a72273b9658cd297ab1d11f/credsweeper/rules/config.yaml
  • github.com/praetorian-inc/trajan/blob/8d8d43a52eacafb0c262f1c7927050966465b381/pkg/bitbucket/bitbucket.go
  • support.atlassian.com/organization-administration/docs/manage-an-organization-with-the-admin-apis/

Research log

Other Atlassian families