redact-secret · Report
IAM user access key
Long-term access key ID for an IAM user, prefixed AKIA.
Research record
1 event in the review history: 1 reviewed. Latest: reviewed on 2026-09-20 by automation, project maintainer. Project-maintained review is not independent validation. The family record at this release.
Format
What it looks like
- companion (companion)
A separate 40-character secret access key is required. ASIA additionally needs a session token and is not covered by this contract.- Descriptive pattern
^AKIA[A-Z2-7]{16}$
Parts are shown as recorded. Evidence classes belong to the facts below; no class is assigned to a part.
Format facts
Provider documented ·
provider-source· current · observed 2026-09-17IAM unique-ID prefix table: AKIA/ASIA/ABIA/ACCA prefixes, and AIDA as the IAM-user unique-ID prefix rather than an access key (re-checked 2026-09-20, #36); 16-character base32 body and 40-character secret are tool-corroborated
- docs.aws.amazon.com/IAM/latest/UserGuide/reference_identifiers.htmlprovider-documentation · last read 2026-10-04 · latest outcome unchanged · supports AKIA/ASIA/ABIA/ACCA prefixes, and AIDA as the IAM-user unique-ID prefix rather than an access key (re-checked 2026-09-20, #36); 16-character base32 body and 40-character secret are tool-corroborated · #identifiers-prefixes
Tool corroborated ·
tool-corroboration· current · observed 2026-09-17Pinned scanner rules are consistent with the contract grammar (2 artifacts: gitleaks 8.30.1; trufflehog 3.97.4).
- gitleaks/gitleaks @ v8.30.1: config/gitleaks.tomlscanner-rule-source · last read 2026-10-04 · latest outcome read · supports gitleaks 8.30.1: gitleaks.toml
- trufflesecurity/trufflehog @ v3.97.4: pkg/detectors/aws/access_keys/accesskey.goscanner-rule-source · last read 2026-09-17 · latest outcome read · supports trufflehog 3.97.4: aws/access_keys/accesskey
Provider documented ·
dossier-research· current · observed 2026-09-20Legacy dossier research (verdict ready, tier T1) cited 1 source; the dossier does not attribute sources to individual properties.
- docs.aws.amazon.com/IAM/latest/UserGuide/reference_identifiers.htmlprovider-documentation · last read 2026-10-04 · latest outcome unchanged · supports Cited by the legacy dossier research for this family · #identifiers-prefixes
Provider documented ·
taxonomy-sources· current · observed 2026-09-20The legacy taxonomy lists 1 source for this family. The taxonomy records no date; the dossier researchedAt is used as the observed-at date.
- docs.aws.amazon.com/IAM/latest/UserGuide/reference_identifiers.htmlprovider-documentation · last read 2026-10-04 · latest outcome unchanged · supports Listed as a source for this family in the legacy taxonomy · #identifiers-prefixes
Open questions
No open question is recorded for this revision.
Benchmark dossier notes
- Shape
- Long-term access key ID for an IAM user, prefixed AKIA.
- Basis
- T1 per the shipped
aws-access-keycontract in the benchmarks assessment: the IAM unique-identifier prefix table documents the AKIA prefix. The 16-character base32 body and the 40-character companion secret are tool-corroborated, not provider-stated. Provider source re-checked 2026-09-20 in benchmarks#36 (PR #38). The contract does not cover ASIA. - Contract in core
- detector-families.md.
In this benchmark
- Fixtures
- 31
- Left readable
- 0
- Redacted too much
- 0
- False alarms
- 0
31 fixtures: 2 expect a redaction, 15 must stay quiet, 14 record project policy. See every row
| Evidence level | Fixtures | Left readable | Too much | False alarms |
|---|---|---|---|---|
| T1Provider-documented | 2 | 0 | 0 | 0 |
| T2Tool-corroborated | 9 | 0 | 0 | 0 |
| T3Project policy | 19 | 0 | 0 | 0 |
| T0Pending review | 1 | 0 | 0 | 0 |
Every scanner on the same fixtures
In run order. Counts are what each scanner recorded on this family's fixtures, whichever rules it has; a scanner with no rule for the family has nothing to report on it.
| Scanner | Fixtures | Left readable | Too much | False alarms |
|---|---|---|---|---|
| flare-redactRuntime library · 1.6.1 · Published npm package · secrets-only (pii, generic_assignment disabled) · JavaScript engine1 rule targets it | 31 | 0 | 0 | 8 |
| gitleaksRepository scanner · 8.30.1 · Directory scan · default rules1 rule targets it | 31 | 8 | 0 | 0 |
| redact-secretProduct measured here · 0.1.0-beta.14 · Published npm package · default detectors1 detector mapped | 31 | 0 | 0 | 0 |
| trufflehogRepository scanner · 3.97.4 · Filesystem scan · verification disabled1 rule targets it | 31 | 14 | 0 | 0 |
Scanner rules for this family
| Scanner | Rule | What the rule matches |
|---|---|---|
| flare-redact · rules 1.6.1 | aws_access_key | AKIA or ASIA + 16 characters |
| gitleaks · rules 8.30.1 | aws-access-token | AKIA, ASIA, ABIA or ACCA + 16 characters |
| openredaction · rules 1.1.5 | AWS_ACCESS_KEY | AKIA + 16 characters |
| trufflehog · rules 3.97.4 | aws/access_keys | AKIA, ABIA or ACCA id, reported with its paired secret |
Fixtures in this family
| Fixture | Kind and evidence | redact-secret |
|---|---|---|
aws-idauthored-aws · early-filler-token-assignments | Project policyT3 · Project policy | Redacted |
aws-access-key-boto3-clientaws · documented-format-literal | Project policyT3 · Project policy | Redacted |
aws-access-key-configure-credentials-actionaws · documented-format-literal | Project policyT3 · Project policy | Redacted |
aws-access-key-shape-1-bareaws · documented-format-literal | Project policyT3 · Project policy | Redacted |
aws-access-key-shape-1-bare-twinaws · prefix-near-miss | Must not flagT2 · Tool-corroborated · twin | Quiet |
aws-access-key-shape-1-quotedaws · documented-format-literal | Project policyT3 · Project policy | Redacted |
aws-access-key-shape-1-quoted-twinaws · prefix-near-miss | Must not flagT2 · Tool-corroborated · twin | Quiet |
aws-access-key-shape-1-unicode-crlfaws · documented-format-literal | Project policyT3 · Project policy | Redacted |
aws-access-key-shape-1-unicode-crlf-twinaws · prefix-near-miss | Must not flagT2 · Tool-corroborated · twin | Quiet |
aws-access-key-shape-2-bareaws · documented-format-literal | Project policyT3 · Project policy | Redacted |
aws-access-key-shape-2-bare-twinaws · prefix-near-miss | Must not flagT2 · Tool-corroborated · twin | Quiet |
aws-access-key-shape-2-quotedaws · documented-format-literal | Project policyT3 · Project policy | Redacted |
aws-access-key-shape-2-quoted-twinaws · prefix-near-miss | Must not flagT2 · Tool-corroborated · twin | Quiet |
aws-access-key-shape-2-unicode-crlfaws · documented-format-literal | Project policyT3 · Project policy | Redacted |
aws-access-key-shape-2-unicode-crlf-twinaws · prefix-near-miss | Must not flagT2 · Tool-corroborated · twin | Quiet |
changed-idaws · aws-example-keys-one-character-off | Project policyT3 · Project policy | Redacted |
id-bareaws · aws-documented-example-keys | Must not flagT3 · Project policy | Quiet |
id-envaws · aws-documented-example-keys | Must not flagT3 · Project policy | Quiet |
aws-key-id-shaped-body-of-example-marker-basepolicy-ambiguous-assignment-bases-authored · example-marker-inside-provider-shaped-value-not-published-by-provider | Project policyT3 · Project policy | Redacted |
aws-key-id-shaped-body-of-example-marker-in-english-prosepolicy-ambiguous-assignment-projections-generated · example-marker-inside-provider-shaped-value-not-published-by-provider | Project policyT3 · Project policy | Redacted |
aws-key-id-shaped-body-of-example-marker-in-korean-prosepolicy-ambiguous-assignment-projections-generated · example-marker-inside-provider-shaped-value-not-published-by-provider | Project policyT3 · Project policy | Redacted |
aws-key-id-shaped-body-of-example-marker-in-markdown-fencepolicy-ambiguous-assignment-projections-generated · example-marker-inside-provider-shaped-value-not-published-by-provider | Project policyT3 · Project policy | Redacted |
aws-access-key-iam-user-identity-public-idaws · public-identifier | Must not flagT2 · Tool-corroborated | Quiet |
aws-access-key-maskaws · benign-lookalike | Must not flagT3 · Project policy | Quiet |
aws-access-key-pair-plainaws · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
aws-access-key-pair-unicode-crlfaws · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
aws-access-key-prefix-onlyaws · benign-lookalike | Must not flagT2 · Tool-corroborated | Quiet |
aws-access-key-referenceaws · benign-lookalike | Must not flagT3 · Project policy | Quiet |
aws-access-key-rotation-note-proseaws · prose-mention | Must not flagT3 · Project policy | Quiet |
aws-access-key-short-bodyaws · benign-lookalike | Must not flagT2 · Tool-corroborated | Quiet |
identifier-aloneaws-compound-credentials-authored · aws-access-key-id-without-secret-confidentiality | Pending reviewT0 · Pending | Unscored |
Sources
Documentation and code
- docs.aws.amazon.com/IAM/latest/UserGuide/reference_identifiers.html#identifiers-prefixes
Research log
- redact-secret/redact-secret-benchmarks#36Research issue