redact-secret · Report
Context-specific credential
Context-specific temporary credential, prefixed ACCA.
Research record
2 events in the review history: 1 observed, 1 reviewed. Latest: observed on 2026-09-29 by automation, project maintainer. Project-maintained review is not independent validation. The family record at this release.
Format
What it looks like
Shape not recorded.
Format facts
Unresolved ·
dossier-research· current · observed 2026-09-29Legacy dossier research (verdict rejected, tier none) cited 9 sources; the dossier does not attribute sources to individual properties.
- aws.amazon.com/blogs/security/securing-amazon-bedrock-api-keys-best-practices-for-implementation-and-management/provider-documentation · last read 2026-09-29 · latest outcome read · supports Cited by the legacy dossier research for this family
- docs.aws.amazon.com/IAM/latest/UserGuide/reference_identifiers.htmlprovider-documentation · last read 2026-10-04 · latest outcome unchanged · supports Cited by the legacy dossier research for this family · #identifiers-prefixes
- docs.aws.amazon.com/IAM/latest/APIReference/API_ServiceSpecificCredential.htmlprovider-documentation · last read 2026-09-29 · latest outcome read · supports Cited by the legacy dossier research for this family
- docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_api_keys_for_aws_services.htmlother · last read 2026-09-29 · latest outcome read · supports Cited by the legacy dossier research for this family
- BishopFox/jsluice @ 0ddfab153e060a9eeaded4d8669233f7c071e7e4: secret-aws.goother · last read 2026-09-29 · latest outcome read · supports Cited by the legacy dossier research for this family
- gitleaks/gitleaks @ b58d3f102cf3a2c84cb7f923d05c25c9b1aed84b: cmd/generate/config/rules/aws.goscanner-rule-source · last read 2026-09-29 · latest outcome read · supports Cited by the legacy dossier research for this family
- hashicorp/aws-sdk-go-base @ 41fc7e1b09a140821eb9cbe6889bb53072a0da2e: logging/aws.goother · last read 2026-09-29 · latest outcome read · supports Cited by the legacy dossier research for this family
- redact-secret/redact-secret @ 378581770a87751d72e27529796c4f790649fd00: docs/audits/evidence/1012/aws-other-iam-prefixes.mdproject-research-note · last read 2026-09-29 · latest outcome read · supports Final research evidence recorded by the legacy dossier
- trufflesecurity/trufflehog @ 48b58d3bf3f02ba17bf23b87f095499bc80c6fd7: pkg/detectors/aws/access_keys/accesskey.goother · last read 2026-09-29 · latest outcome read · supports Cited by the legacy dossier research for this family
Unresolved ·
taxonomy-sources· current · observed 2026-09-29The legacy taxonomy lists 1 source for this family. The taxonomy records no date; the dossier researchedAt is used as the observed-at date.
- docs.aws.amazon.com/IAM/latest/UserGuide/reference_identifiers.htmlprovider-documentation · last read 2026-10-04 · latest outcome unchanged · supports Listed as a source for this family in the legacy taxonomy · #identifiers-prefixes
Open questions
No open question is recorded for this revision.
Benchmark dossier notes
- Shape
- ACCA is the prefix of a service-specific credential ID, at least 20 and at most 128 word characters. It identifies a credential and does not authenticate.
- Contract in core
- detector-families.md.
In this benchmark
No fixtures in this family yet
Nothing in the corpus targets it, so nothing is measured and no coverage is claimed.
Not measured
Scanner rules for this family
| Scanner | Rule | What the rule matches |
|---|---|---|
| gitleaks · rules 8.30.1 | aws-access-token | AKIA, ASIA, ABIA or ACCA + 16 characters |
| trufflehog · rules 3.97.4 | aws/access_keys | AKIA, ABIA or ACCA id, reported with its paired secret |
No rule maps to this family in flare-redact, openredaction.
No fixtures in this family yet
Nothing in the corpus targets it, so nothing is measured and no coverage is claimed.
Not measured
Sources
Documentation and code
- docs.aws.amazon.com/IAM/latest/UserGuide/reference_identifiers.html#identifiers-prefixes
- docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_api_keys_for_aws_services.html
- docs.aws.amazon.com/IAM/latest/APIReference/API_ServiceSpecificCredential.html
- aws.amazon.com/blogs/security/securing-amazon-bedrock-api-keys-best-practices-for-implementation-and-management/
- github.com/gitleaks/gitleaks/blob/b58d3f102cf3a2c84cb7f923d05c25c9b1aed84b/cmd/generate/config/rules/aws.go
- github.com/trufflesecurity/trufflehog/blob/48b58d3bf3f02ba17bf23b87f095499bc80c6fd7/pkg/detectors/aws/access_keys/accesskey.go
- github.com/hashicorp/aws-sdk-go-base/blob/41fc7e1b09a140821eb9cbe6889bb53072a0da2e/logging/aws.go
- github.com/BishopFox/jsluice/blob/0ddfab153e060a9eeaded4d8669233f7c071e7e4/secret-aws.go
Research log
- redact-secret/redact-secret-benchmarks#473Research issue
- redact-secret/redact-secret#1012Research issue
- Final evidence, pinned to a commit/redact-secret/redact-secret/blob/378581770a87751d72e27529796c4f790649fd00/docs/audits/evidence/1012/aws-other-iam-prefixes.md