redact-secret · Report
API token
ATAT prefixed API token (minimum-length contract; Atlassian disclaims a fixed length).
Research record
3 events in the review history: 2 observed, 1 reviewed. Latest: observed on 2026-10-03 by automation, project maintainer. Project-maintained review is not independent validation. The family record at this release.
Format
What it looks like
- Descriptive pattern
^ATAT[A-Za-z0-9_-]{100,}(?:=[0-9A-F]{8})?$
Parts are shown as recorded. Evidence classes belong to the facts below; no class is assigned to a part.
Format facts
Unresolved ·
tool-corroboration· current · observed 2026-09-22Pinned scanner rules are consistent with the contract grammar (1 artifact: gitleaks 8.30.1).
- gitleaks/gitleaks @ v8.30.1: config/gitleaks.tomlscanner-rule-source · last read 2026-10-04 · latest outcome read · supports gitleaks 8.30.1: gitleaks.toml
Unresolved ·
field-prefix· current · observed 2026-09-22prefix: ATAT (An account labelled "Atlassian Team" on community.atlassian.com wrote "You can rely on" ATAT/ATBB/ATCT (2025-08-25), while a 2022 staff post called tokens opaque; whether that answer is provider documentation is an open maintainer decision (redact-secret#643).)
- gitleaks/gitleaks @ v8.30.1: config/gitleaks.tomlscanner-rule-source · last read 2026-10-04 · latest outcome read · supports prefix: ATAT
Unresolved ·
field-minimum-length· current · observed 2026-09-22minimum length: ATAT plus at least 100 body characters of [A-Za-z0-9_-]; Atlassian calls the length "varied"
- github.com/redact-secret/redact-secret/issues/643scanner-rule-source · last read 2026-09-22 · latest outcome read · supports minimum length: ATAT plus at least 100 body characters of [A-Za-z0-9_-]; Atlassian calls the length "varied"
- support.atlassian.com/atlassian-account/docs/manage-api-tokens-for-your-atlassian-account/scanner-rule-source · last read 2026-10-03 · latest outcome read · supports "We use a varied API token length"
Unresolved ·
field-fixed-header· current · observed 2026-09-22fixed header: the first 12 characters are ATATT3xFfGF0
- github.com/redact-secret/redact-secret/issues/643scanner-rule-source · last read 2026-09-22 · latest outcome read · supports Maintainer-confirmed on one issued key; a customer report of five keys and every scanner sample agree.
Unresolved ·
field-total-length-and-suffix· current · observed 2026-09-22total length and suffix: 192 characters: 12-character header, 171 body characters, a literal =, then 8 uppercase hex characters
- github.com/redact-secret/redact-secret/issues/643scanner-rule-source · last read 2026-09-22 · latest outcome read · supports Maintainer answered length 192, = at position 184, last 8 in [0-9A-F]; one observation, below #205's five-observation floor.
Tool corroborated ·
field-checksum· current · observed 2026-09-22checksum: the trailing 8 hex characters are CRC32 (big-endian, uppercase hex) of everything before them, = included (Fixtures carry a CRC32-valid suffix; the maintainer could not confirm the check on an issued key, so no checksum-only twin is scored.)
- DataDog/dd-sensitive-data-scanner @ main: sds/src/secondary_validation/atlassian_token_checksum.rsscanner-rule-source · last read 2026-09-22 · latest outcome read · supports checksum: the trailing 8 hex characters are CRC32 (big-endian, uppercase hex) of everything before them, = included
- Samsung/CredSweeper @ main: credsweeper/filters/value_atlassian_token_check.pyscanner-rule-source · last read 2026-09-22 · latest outcome read · supports checksum: the trailing 8 hex characters are CRC32 (big-endian, uppercase hex) of everything before them, = included
Tool corroborated ·
dossier-research· current · observed 2026-09-24Legacy dossier research (verdict ready, tier T2) cited 5 sources; the dossier does not attribute sources to individual properties.
- community.atlassian.com/forums/Bitbucket-questions/Can-we-confirm-BitBucket-s-token-prefixes/qaq-p/3093481other · last read 2026-09-29 · latest outcome read · supports Cited by the legacy dossier research for this family
- community.developer.atlassian.com/t/about-the-format-of-atlassian-security-tokens/62553other · last read 2026-10-03 · latest outcome read · supports Cited by the legacy dossier research for this family
- DataDog/dd-sensitive-data-scanner @ 4e53b6ac37ab4b6699f4331868a1c486f0d21147: sds/src/secondary_validation/atlassian_token_checksum.rsother · last read 2026-10-03 · latest outcome read · supports Cited by the legacy dossier research for this family
- redact-secret/redact-secret @ 8b6a5fde52ecb4dfce13f09c7a947062d21483c7: docs/audits/evidence/643/README.mdproject-research-note · last read 2026-09-24 · latest outcome read · supports Final research evidence recorded by the legacy dossier
- support.atlassian.com/atlassian-account/docs/manage-api-tokens-for-your-atlassian-account/scanner-rule-source · last read 2026-10-03 · latest outcome read · supports Cited by the legacy dossier research for this family
Open questions
No open question is recorded for this revision.
Benchmark dossier notes
- Shape
- prefix
ATAT. Observed current tokens are 192 characters: a fixed 12-character headerATATT3xFfGF0, a 171-character body from[A-Za-z0-9_-], one literal=, then 8 uppercase hex characters that two scanner implementations treat as a CRC32 of everything before them. The maintainer confirmed the header, length and=position, and the 171-character[A-Za-z0-9_-]body and the final 8 characters in[0-9A-F], on one freshly issued key (web-search pass); the CRC32 was not confirmed on it. Tokens created before 2023-01-18 were unprefixed and 24 characters; the support page says all older tokens expired by 2026-05-12. - Basis
- the
ATATprefix rests on one answer (2025-08-25) by an account labelled "Atlassian Team" on Atlassian's community site; whether that meets the T1 bar is an open maintainer ruling. A 2022 staff post says tokens are opaque and clients cannot depend on format, which predates the 2023 change. Everything else is T2: gitleaks, trufflehog (jiratoken v2), Nosey Parker, CredSweeper and Datadog's scanner (the checksum validator) plus the maintainer key and a five-key community report. - Issuance
- one maintainer-issued key was used for the header check. A fresh key would settle the CRC32 (evidence checklist in the #643 passes).
- Contract in core
- detector-families.md; evidence #643 record.
In this benchmark
- Fixtures
- 45
- Left readable
- 0
- Redacted too much
- 0
- False alarms
- 0
45 fixtures: 14 expect a redaction, 27 must stay quiet, 4 record project policy. See every row
| Evidence level | Fixtures | Left readable | Too much | False alarms |
|---|---|---|---|---|
| T2Tool-corroborated | 21 | 0 | 0 | 0 |
| T3Project policy | 24 | 0 | 0 | 0 |
Every scanner on the same fixtures
In run order. Counts are what each scanner recorded on this family's fixtures, whichever rules it has; a scanner with no rule for the family has nothing to report on it.
| Scanner | Fixtures | Left readable | Too much | False alarms |
|---|---|---|---|---|
| flare-redactRuntime library · 1.6.1 · Published npm package · secrets-only (pii, generic_assignment disabled) · JavaScript engineNo rule maps to it | 45 | 17 | 0 | 0 |
| gitleaksRepository scanner · 8.30.1 · Directory scan · default rules1 rule targets it | 45 | 4 | 0 | 0 |
| redact-secretProduct measured here · 0.1.0-beta.14 · Published npm package · default detectors1 detector mapped | 45 | 0 | 0 | 0 |
| trufflehogRepository scanner · 3.97.4 · Filesystem scan · verification disabled1 rule targets it | 45 | 11 | 0 | 1 |
Benchmark dossier questions
- Open caveat
- T1 needs a maintainer ruling that an Atlassian Team forum answer counts as provider documentation; length, alphabet, the = delimiter and the CRC32 suffix are empirical only.
Looks like it, but isn't
- Collisions
ATBB(Bitbucket app passwords, stopped working 2026-06-09) andATCT(Bitbucket access tokens) share the layout. The=is outside the contract's alphabet, but since #741 core includes a directly following=plus 8 uppercase hex in the span.
Scanner rules for this family
| Scanner | Rule | What the rule matches |
|---|---|---|
| gitleaks · rules 8.30.1 | atlassian-api-token | ATATT3 + 186 chars (second alternative) |
| trufflehog · rules 3.97.4 | jiratoken/v2 | ATATT + Base64 payload |
No rule maps to this family in flare-redact, openredaction.
Fixtures in this family
| Fixture | Kind and evidence | redact-secret |
|---|---|---|
atlassian-api-token-acli-loginatlassian · documented-format-literal | Must redactT2 · Tool-corroborated | Redacted |
atlassian-api-token-airflow-connectionatlassian · documented-format-literal | Must redactT2 · Tool-corroborated | Redacted |
atlassian-api-token-bitbucket-remoteatlassian · documented-format-literal | Project policyT3 · Project policy | Redacted |
atlassian-api-token-compose-envatlassian · documented-format-literal | Must redactT2 · Tool-corroborated | Redacted |
atlassian-api-token-curl-basicatlassian · documented-format-literal | Must redactT2 · Tool-corroborated | Redacted |
atlassian-api-token-debug-logatlassian · documented-format-literal | Must redactT2 · Tool-corroborated | Redacted |
atlassian-api-token-envatlassian · documented-format-literal | Must redactT2 · Tool-corroborated | Redacted |
atlassian-api-token-floor-length-json-twinatlassian · wrong-length | Must not flagT3 · Project policy · twin | Quiet |
atlassian-api-token-jira-clientatlassian · documented-format-literal | Must redactT2 · Tool-corroborated | Redacted |
atlassian-api-token-netrcatlassian · documented-format-literal | Must redactT2 · Tool-corroborated | Redacted |
atlassian-api-token-op-item-getatlassian · documented-format-literal | Must redactT2 · Tool-corroborated | Redacted |
atlassian-api-token-pipelines-variableatlassian · documented-format-literal | Must redactT2 · Tool-corroborated | Redacted |
atlassian-api-token-python-client-yamlatlassian · documented-format-literal | Must redactT2 · Tool-corroborated | Redacted |
atlassian-api-token-settings-jsonatlassian · documented-format-literal | Must redactT2 · Tool-corroborated | Redacted |
atlassian-api-token-shape-1-bareatlassian · documented-format-literal | Project policyT3 · Project policy | Redacted |
atlassian-api-token-shape-1-quotedatlassian · documented-format-literal | Project policyT3 · Project policy | Redacted |
atlassian-api-token-shape-1-unicode-crlfatlassian · documented-format-literal | Project policyT3 · Project policy | Redacted |
atlassian-api-token-shell-exportatlassian · documented-format-literal | Must redactT2 · Tool-corroborated | Redacted |
atlassian-api-token-ticket-pasteatlassian · documented-format-literal | Must redactT2 · Tool-corroborated | Redacted |
atlassian-api-token-account-id-public-idatlassian · public-identifier | Must not flagT3 · Project policy | Quiet |
atlassian-api-token-actions-secret-referenceatlassian · templated-reference | Must not flagT3 · Project policy | Quiet |
atlassian-api-token-alphabet-twinatlassian · wrong-alphabet | Must not flagT2 · Tool-corroborated · twin | Quiet |
atlassian-api-token-cli-digest-encoded-valueatlassian · benign-encoded-value | Must not flagT3 · Project policy | Quiet |
atlassian-api-token-cloud-id-public-idatlassian · public-identifier | Must not flagT3 · Project policy | Quiet |
atlassian-api-token-creation-note-proseatlassian · prose-mention | Must not flagT3 · Project policy | Quiet |
atlassian-api-token-docs-ellipsis-placeholderatlassian · documentation-placeholder | Must not flagT3 · Project policy | Quiet |
atlassian-api-token-floor-length-twinatlassian · wrong-length | Must not flagT3 · Project policy · twin | Quiet |
atlassian-api-token-header-only-near-missatlassian · format-near-miss | Must not flagT2 · Tool-corroborated | Quiet |
atlassian-api-token-issue-url-public-idatlassian · public-identifier | Must not flagT3 · Project policy | Quiet |
atlassian-api-token-label-proseatlassian · benign-lookalike | Must not flagT3 · Project policy | Quiet |
atlassian-api-token-maskatlassian · benign-lookalike | Must not flagT3 · Project policy | Quiet |
atlassian-api-token-masked-placeholderatlassian · documentation-placeholder | Must not flagT3 · Project policy | Quiet |
atlassian-api-token-netrc-variable-referenceatlassian · templated-reference | Must not flagT3 · Project policy | Quiet |
atlassian-api-token-op-read-referenceatlassian · templated-reference | Must not flagT3 · Project policy | Quiet |
atlassian-api-token-prefix-ci-twinatlassian · prefix-near-miss | Must not flagT2 · Tool-corroborated · twin | Quiet |
atlassian-api-token-prefix-onlyatlassian · benign-lookalike | Must not flagT2 · Tool-corroborated | Quiet |
atlassian-api-token-prefix-twinatlassian · prefix-near-miss | Must not flagT2 · Tool-corroborated · twin | Quiet |
atlassian-api-token-referenceatlassian · benign-lookalike | Must not flagT3 · Project policy | Quiet |
atlassian-api-token-shape-1-bare-twinatlassian · wrong-length | Must not flagT3 · Project policy · twin | Quiet |
atlassian-api-token-shape-1-quoted-twinatlassian · wrong-length | Must not flagT3 · Project policy · twin | Quiet |
atlassian-api-token-shape-1-unicode-crlf-twinatlassian · wrong-length | Must not flagT3 · Project policy · twin | Quiet |
atlassian-api-token-short-bodyatlassian · benign-lookalike | Must not flagT2 · Tool-corroborated | Quiet |
atlassian-api-token-site-and-email-public-idatlassian · public-identifier | Must not flagT3 · Project policy | Quiet |
atlassian-api-token-unprefixed-random-near-missatlassian · format-near-miss | Must not flagT2 · Tool-corroborated | Quiet |
atlassian-api-token-your-token-placeholderatlassian · documentation-placeholder | Must not flagT3 · Project policy | Quiet |
Sources
Documentation and code
- support.atlassian.com/atlassian-account/docs/manage-api-tokens-for-your-atlassian-account/
- community.atlassian.com/forums/Bitbucket-questions/Can-we-confirm-BitBucket-s-token-prefixes/qaq-p/3093481
- community.developer.atlassian.com/t/about-the-format-of-atlassian-security-tokens/62553
- github.com/DataDog/dd-sensitive-data-scanner/blob/4e53b6ac37ab4b6699f4331868a1c486f0d21147/sds/src/secondary_validation/atlassian_token_checksum.rs
Research log
- redact-secret/redact-secret#643Research issue
- redact-secret/redact-secret#741Research issue
- Final evidence, pinned to a commit/redact-secret/redact-secret/blob/8b6a5fde52ecb4dfce13f09c7a947062d21483c7/docs/audits/evidence/643/README.md