Skip to content
Benchmarks

redact-secret · Report

STS temporary access key

Short-lived access key ID issued by AWS STS, prefixed ASIA; requires an accompanying session token.

  • Amazon Web Services
  • Detectors: none mapped
  • Run 2026-10-07
  • Mode published · redact-secret 0.1.0-beta.14
  • Dossier verdictReady
  • Dossier evidence levelT2 · Tool-corroborated
  • Dossier researched2026-09-29
Measured as the Beta.12 unscored arrival family aws-sts-temporary-access-key (benchmarks/lib/beta8/1012d.ts; #1012 research, T2: ASIA + exactly 16 [A-Z0-9]). The product claims ASIA inside aws-access-key under the shared aws_access_key_id finding type (redact-secret#1027), so its findings carry no family evidence of their own and no detector is mapped here; the registry aws-access-key contract stays AKIA-only. A bare ASIA id is an identifier and scores as project policy.

Research record

From credential-evidence snapshot-2026.10.06.4 · records at 77ce761 · schema 1.8.0. It describes the research on the format, not what any scanner or the product does, and not a support status.
  • Review stateDraft, not reviewed
  • Format revision1 · current
  • ResearchResearched
  • Researched2026-09-29

Format revisions

  • Revision 1 aws:sts-temporary-access-key@1current · draft, not reviewed · superseded by @2 · the family's current revision
  • Revision 2 aws:sts-temporary-access-key@2proposed · draft, not reviewed · supersedes @1

4 events in the review history: 3 observed, 1 reviewed. Latest: observed on 2026-10-04 by automation, project maintainer. Project-maintained review is not independent validation. The family record at this release.

Format

Provider format research from credential-evidence snapshot-2026.10.06.4 · records at 77ce761 · schema 1.8.0.

What it looks like

Descriptive pattern
^ASIA[A-Z0-9]{16}$

Parts are shown as recorded. Evidence classes belong to the facts below; no class is assigned to a part.

Format facts

Open questions

No open question is recorded for this revision.

Benchmark dossier notes

From the provider dossier, as written. The evidence level above says how well the format is backed; a fact the dossier does not record is not shown.
Shape
Short-lived access key ID from STS operations, prefixed ASIA: four prefix characters plus a 16-character body, 20 in all. It is usable only together with a secret access key and a session token, so the key ID alone authenticates nothing.
Contract in core
detector-families.md.

In this benchmark

Fixture rows on the current run. Counts are for redact-secret in published · redact-secret 0.1.0-beta.14 mode.
Fixtures
31
Left readable
0
Redacted too much
0
False alarms
0

31 fixtures: 18 must stay quiet, 13 record project policy. See every row

redact-secret fixture counts by evidence level
Evidence levelFixturesLeft readableToo muchFalse alarms
T2Tool-corroborated12000
T3Project policy18000
T0Pending review1000

Every scanner on the same fixtures

In run order. Counts are what each scanner recorded on this family's fixtures, whichever rules it has; a scanner with no rule for the family has nothing to report on it.

Counts per scanner on this family's fixtures
ScannerFixturesLeft readableToo muchFalse alarms
flare-redactRuntime library · 1.6.1 · Published npm package · secrets-only (pii, generic_assignment disabled) · JavaScript engine1 rule targets it31002
gitleaksRepository scanner · 8.30.1 · Directory scan · default rules1 rule targets it31500
redact-secretProduct measured here · 0.1.0-beta.14 · Published npm package · default detectorsNo detector mapped31000
trufflehogRepository scanner · 3.97.4 · Filesystem scan · verification disabled1 rule targets it311300

Scanner rules for this family

Mapped by hand (reviewed 2026-09-30) from each scanner's pinned rule file, never from what a scanner found on the fixtures.
Peer scanner rules that target this family
ScannerRuleWhat the rule matches
flare-redact · rules 1.6.1aws_access_keyAKIA or ASIA + 16 characters
gitleaks · rules 8.30.1aws-access-tokenAKIA, ASIA, ABIA or ACCA + 16 characters
trufflehog · rules 3.97.4aws/session_keysASIA id + a session token of 100 or more characters

No rule maps to this family in openredaction.

31 of 31 rows

Fixtures in this family

31 rows, redact-secret's outcome on each. Rows that need a look come first (0), then the rest in corpus order. Choose "Every scanner" to see each scanner's outcome for the same rows.
Fixtures in STS temporary access key
FixtureKind and evidenceredact-secret
aws-sts-temporary-access-key-bare-proseaws · documented-format-literalProject policyT3 · Project policyRedacted
aws-sts-temporary-access-key-bearer-headeraws · documented-format-literalProject policyT3 · Project policyRedacted
aws-sts-temporary-access-key-chat-pasteaws · documented-format-literalProject policyT3 · Project policyRedacted
aws-sts-temporary-access-key-cloudtrail-eventaws · documented-format-literalProject policyT3 · Project policyRedacted
aws-sts-temporary-access-key-credentials-fileaws · documented-format-literalProject policyT3 · Project policyRedacted
aws-sts-temporary-access-key-dotenvaws · documented-format-literalProject policyT3 · Project policyRedacted
aws-sts-temporary-access-key-exportaws · documented-format-literalProject policyT3 · Project policyRedacted
aws-sts-temporary-access-key-iam-user-id-public-idaws · public-identifierMust not flagT2 · Tool-corroboratedQuiet
aws-sts-temporary-access-key-json-api-keyaws · documented-format-literalProject policyT3 · Project policyRedacted
aws-sts-temporary-access-key-json-tokenaws · documented-format-literalProject policyT3 · Project policyRedacted
aws-sts-temporary-access-key-role-id-public-idaws · public-identifierMust not flagT2 · Tool-corroboratedQuiet
aws-sts-temporary-access-key-sdk-kwargaws · documented-format-literalProject policyT3 · Project policyRedacted
aws-sts-temporary-access-key-sts-jsonaws · documented-format-literalProject policyT3 · Project policyRedacted
aws-sts-temporary-access-key-x-api-key-headeraws · documented-format-literalProject policyT3 · Project policyRedacted
sts-credentials-past-expirationenvironment-and-test-values-authored · aws-temporary-credentials-with-expiration-fieldProject policyT3 · Project policyRedacted
aws-sts-temporary-access-key-account-and-arn-public-idaws · public-identifierMust not flagT2 · Tool-corroboratedQuiet
aws-sts-temporary-access-key-actions-output-referenceaws · templated-referenceMust not flagT3 · Project policyQuiet
aws-sts-temporary-access-key-angle-placeholderaws · documentation-placeholderMust not flagT3 · Project policyQuiet
aws-sts-temporary-access-key-asib-prefix-twinaws · prefix-near-missMust not flagT2 · Tool-corroborated · twinQuiet
aws-sts-temporary-access-key-body-15-twinaws · wrong-lengthMust not flagT2 · Tool-corroborated · twinQuiet
aws-sts-temporary-access-key-body-17-twinaws · wrong-lengthMust not flagT2 · Tool-corroborated · twinQuiet
aws-sts-temporary-access-key-env-reference-referenceaws · templated-referenceMust not flagT3 · Project policyQuiet
aws-sts-temporary-access-key-identifier-near-missaws · format-near-missMust not flagT2 · Tool-corroboratedQuiet
aws-sts-temporary-access-key-leading-glue-twinaws · boundary-violationMust not flagT2 · Tool-corroborated · twinQuiet
aws-sts-temporary-access-key-lowercase-byte-twinaws · wrong-alphabetMust not flagT2 · Tool-corroborated · twinQuiet
aws-sts-temporary-access-key-masked-placeholderaws · documentation-placeholderMust not flagT3 · Project policyQuiet
aws-sts-temporary-access-key-prefix-guidance-proseaws · prose-mentionMust not flagT3 · Project policyQuiet
aws-sts-temporary-access-key-region-word-near-missaws · format-near-missMust not flagT2 · Tool-corroboratedQuiet
aws-sts-temporary-access-key-trailing-glue-twinaws · boundary-violationMust not flagT2 · Tool-corroborated · twinQuiet
aws-sts-temporary-access-key-truncated-near-missaws · format-near-missMust not flagT2 · Tool-corroboratedQuiet
session-token-aloneaws-compound-credentials-authored · aws-session-token-alone-confidentialityPending reviewT0 · PendingUnscored

Sources

Researched 2026-09-29.

Documentation and code

  • docs.aws.amazon.com/IAM/latest/UserGuide/reference_identifiers.html#identifiers-prefixes
  • github.com/redact-secret/redact-secret/blob/4fb78827f1ddf5b3106f25130ca510a836ada186/docs/audits/evidence/1012/aws-sts-temporary-access-key.md
  • docs.aws.amazon.com/IAM/latest/UserGuide/security-creds-programmatic-access.html
  • docs.aws.amazon.com/STS/latest/APIReference/API_Credentials.html
  • docs.aws.amazon.com/STS/latest/APIReference/API_AssumeRole.html
  • github.com/gitleaks/gitleaks/blob/b58d3f102cf3a2c84cb7f923d05c25c9b1aed84b/cmd/generate/config/rules/aws.go
  • github.com/Yelp/detect-secrets/blob/5e141933554a0b74e7341841f318be21e895339c/detect_secrets/plugins/aws.py
  • github.com/trufflesecurity/trufflehog/blob/48b58d3bf3f02ba17bf23b87f095499bc80c6fd7/pkg/detectors/aws/session_keys/sessionkey.go
  • github.com/awslabs/git-secrets/blob/7d6b970cbd3c216353cb22b383b70c150140662e/git-secrets
  • github.com/awslabs/ferret-scan/blob/c3b10fba90a5ed6178314ac646988546122afc60/internal/validators/secrets/validator.go#L1444
  • github.com/hashicorp/aws-sdk-go-base/blob/41fc7e1b09a140821eb9cbe6889bb53072a0da2e/logging/aws.go
  • github.com/BishopFox/jsluice/blob/0ddfab153e060a9eeaded4d8669233f7c071e7e4/secret-aws.go
  • github.com/gitleaks/gitleaks/pull/1816
  • awsteele.com/blog/2020/09/26/aws-access-key-format.html
  • summitroute.com/blog/2018/06/20/aws_security_credential_formats/
  • blog.adobe.com/security/uncovering-the-hidden-identities-within-aws-access-keys
  • hackingthe.cloud/aws/general-knowledge/iam-key-identifiers/
  • docs.github.com/en/code-security/secret-scanning/introduction/supported-secret-scanning-patterns

Research log

Other Amazon Web Services families