redact-secret · Report
Short-term API key (bedrock-api-key-)
bedrock-api-key- prefixed Base64 pre-signed CallWithBearerToken URL, valid for at most 12 hours.
Research record
3 events in the review history: 2 observed, 1 reviewed. Latest: observed on 2026-09-27 by automation, project maintainer. Project-maintained review is not independent validation. The family record at this release.
Format
What it looks like
- Descriptive pattern
^bedrock-api-key-YmVkcm9jay5hbWF6b25hd3MuY29tLz9BY3Rpb249Q2FsbFdpdGhCZWFyZXJUb2tlbiZYLUFtei1BbGdvcml0aG09QVdTNC1ITUFDLVNIQTI1NiZYLUFtei1DcmVkZW50aWFsP[A-Za-z0-9+/]+={0,2}$
Parts are shown as recorded. Evidence classes belong to the facts below; no class is assigned to a part.
Format facts
Provider documented ·
provider-source· current · observed 2026-09-26AUTH_PREFIX = "bedrock-api-key-" in AWS's Python, JS and Java token generators: AWS-authored generators (aws-bedrock-token-generator, Python, JS and Java) build the short-term key as bedrock-api-key- followed by the standard padded Base64 of a SigV4-presigned CallWithBearerToken URL plus &Version=1, and the AWS Security Blog prints the fixed 133-character Base64 head. Provider code and a provider blog are not a documentation page; the maintainer ruling of 2026-09-27 (redact-secret#779) accepts them as T1 evidence for the prefix, the fixed 133-character head and the standard padded Base64 alphabet only. Total length and the session-token part of the body stay T2
- aws/aws-bedrock-token-generator-python @ main: aws_bedrock_token_generator/token_generator.pyprovider-documentation · last read 2026-09-27 · latest outcome read · supports AWS-authored generators (aws-bedrock-token-generator, Python, JS and Java) build the short-term key as bedrock-api-key- followed by the standard padded Base64 of a SigV4-presigned CallWithBearerToken URL plus &Version=1, and the AWS Security Blog prints the fixed 133-character Base64 head. Provider code and a provider blog are not a documentation page; the maintainer ruling of 2026-09-27 (redact-secret#779) accepts them as T1 evidence for the prefix, the fixed 133-character head and the standard padded Base64 alphabet only. Total length and the session-token part of the body stay T2
Tool corroborated ·
tool-corroboration· current · observed 2026-09-26Pinned scanner rules are consistent with the contract grammar (2 artifacts: awslabs/git-secrets; gitleaks 8.30.1).
- github.com/awslabs/git-secrets/pull/264provider-documentation · last read 2026-09-26 · latest outcome read · supports awslabs/git-secrets: bedrock-api-key-YmVkcm9jay5hbWF6b25hd3MuY29t
- gitleaks/gitleaks @ v8.30.1: config/gitleaks.tomlscanner-rule-source · last read 2026-10-04 · latest outcome read · supports gitleaks 8.30.1: gitleaks.toml
Provider documented ·
field-prefix· current · observed 2026-09-26prefix: bedrock-api-key-
- aws/aws-bedrock-token-generator-java @ main: src/main/java/software/amazon/bedrock/token/BedrockTokenGenerator.javaprovider-sdk-source · last read 2026-09-26 · latest outcome read · supports AUTH_PREFIX
- aws/aws-bedrock-token-generator-js @ main: src/token.tsprovider-sdk-source · last read 2026-09-26 · latest outcome read · supports AUTH_PREFIX
- aws/aws-bedrock-token-generator-python @ main: aws_bedrock_token_generator/token_generator.pyprovider-documentation · last read 2026-09-27 · latest outcome read · supports AUTH_PREFIX
Provider documented ·
field-fixed-head· current · observed 2026-09-26fixed-head: the 133 Base64 characters after the prefix encode bedrock.amazonaws.com/?Action=CallWithBearerToken&X-Amz-Algorithm=AWS4-HMAC-SHA256&X-Amz-Credential (The weaker 28-character anchor used by gitleaks and git-secrets is a tool choice; the twins here differ from the positive within the first 28 characters of the head, so they hold under either anchor.)
- aws.amazon.com/blogs/security/securing-amazon-bedrock-api-keys-best-practices-for-implementation-and-management/provider-documentation · last read 2026-09-29 · latest outcome read · supports the blog regex prints the head
- aws/aws-bedrock-token-generator-python @ main: aws_bedrock_token_generator/token_generator.pyprovider-documentation · last read 2026-09-27 · latest outcome read · supports host, Action and signing parameters
Provider documented ·
field-body-alphabet· current · observed 2026-09-26body-alphabet: standard padded Base64 ([A-Za-z0-9+/], up to two trailing =) (The blog's printed body class is malformed; no source documents a URL-safe variant.)
- aws/aws-bedrock-token-generator-java @ main: src/main/java/software/amazon/bedrock/token/BedrockTokenGenerator.javaprovider-sdk-source · last read 2026-09-26 · latest outcome read · supports Base64.getEncoder()
- aws/aws-bedrock-token-generator-js @ main: src/token.tsprovider-sdk-source · last read 2026-09-26 · latest outcome read · supports toString("base64")
- aws/aws-bedrock-token-generator-python @ main: aws_bedrock_token_generator/token_generator.pyprovider-documentation · last read 2026-09-27 · latest outcome read · supports base64.b64encode
Provider documented ·
field-version-suffix· current · observed 2026-09-26version-suffix: the encoded payload ends with &Version=1
- aws/aws-bedrock-token-generator-js @ main: src/token.tsprovider-sdk-source · last read 2026-09-26 · latest outcome read · supports TOKEN_VERSION
- aws/aws-bedrock-token-generator-python @ main: aws_bedrock_token_generator/token_generator.pyprovider-documentation · last read 2026-09-27 · latest outcome read · supports TOKEN_VERSION
Unresolved ·
field-total-length· current · observed 2026-09-26total-length: about 500 characters for a key presigned without a session token and over 1000 with one; no bound is documented (Positives carry three sizes; no length twin is authored.)
- github.com/redact-secret/redact-secret/issues/779third-party-writeup · last read 2026-09-26 · latest outcome read · supports reconstruction by construction, about 500 without a session token
- www.wiz.io/blog/a-new-type-of-long-lived-key-on-aws-bedrock-api-keysprovider-documentation · last read 2026-09-26 · latest outcome read · supports over 1000 characters
Provider documented ·
field-lifetime· current · observed 2026-09-26lifetime: valid for the shorter of 12 hours and the generating session
- docs.aws.amazon.com/bedrock/latest/userguide/api-keys-reference.htmlprovider-documentation · last read 2026-09-27 · latest outcome read · supports lifetime: valid for the shorter of 12 hours and the generating session
Provider documented ·
field-transport· current · observed 2026-09-26transport: AWS_BEARER_TOKEN_BEDROCK environment variable or Authorization: Bearer, shared with the long-term key
- docs.aws.amazon.com/bedrock/latest/userguide/api-keys-use.htmlprovider-documentation · last read 2026-09-26 · latest outcome read · supports transport: AWS_BEARER_TOKEN_BEDROCK environment variable or Authorization: Bearer, shared with the long-term key
Unresolved ·
field-console-output· current · observed 2026-09-26console-output: whether a console-generated short-term key is byte-identical to the SDK output
- github.com/redact-secret/redact-secret/issues/779third-party-writeup · last read 2026-09-26 · latest outcome read · supports hands-on checklist item
Unresolved ·
listed-references· current · observed 2026-09-26The legacy contract lists 7 references without stating which property each supports.
- aws.amazon.com/blogs/security/securing-amazon-bedrock-api-keys-best-practices-for-implementation-and-management/provider-documentation · last read 2026-09-29 · latest outcome read · supports Listed as a reference by the legacy contract
- docs.aws.amazon.com/bedrock/latest/userguide/api-keys-reference.htmlprovider-documentation · last read 2026-09-27 · latest outcome read · supports Listed as a reference by the legacy contract
- docs.aws.amazon.com/bedrock/latest/userguide/api-keys-use.htmlprovider-documentation · last read 2026-09-26 · latest outcome read · supports Listed as a reference by the legacy contract
- aws/aws-bedrock-token-generator-java @ main: src/main/java/software/amazon/bedrock/token/BedrockTokenGenerator.javaprovider-sdk-source · last read 2026-09-26 · latest outcome read · supports Listed as a reference by the legacy contract
- aws/aws-bedrock-token-generator-js @ main: src/token.tsprovider-sdk-source · last read 2026-09-26 · latest outcome read · supports Listed as a reference by the legacy contract
- github.com/redact-secret/redact-secret/issues/864issue-or-discussion · last read 2026-09-26 · latest outcome read · supports Listed as a reference by the legacy contract
- github.com/redact-secret/redact-secret/issues/779third-party-writeup · last read 2026-09-26 · latest outcome read · supports Listed as a reference by the legacy contract
Provider documented ·
dossier-research· current · observed 2026-09-27Legacy dossier research (verdict ready, tier T1) cited 7 sources; the dossier does not attribute sources to individual properties.
- aws.amazon.com/blogs/security/securing-amazon-bedrock-api-keys-best-practices-for-implementation-and-management/provider-documentation · last read 2026-09-29 · latest outcome read · supports Cited by the legacy dossier research for this family
- docs.aws.amazon.com/bedrock/latest/userguide/api-keys-revoke.htmlprovider-documentation · last read 2026-09-27 · latest outcome read · supports Cited by the legacy dossier research for this family
- docs.aws.amazon.com/bedrock/latest/userguide/api-keys-reference.htmlprovider-documentation · last read 2026-09-27 · latest outcome read · supports Cited by the legacy dossier research for this family
- aws/aws-bedrock-token-generator-java @ 65a626daa1314c16536030c86adafbad4a6b2d56: src/main/java/software/amazon/bedrock/token/BedrockTokenGenerator.javaother · last read 2026-09-27 · latest outcome read · supports Cited by the legacy dossier research for this family
- aws/aws-bedrock-token-generator-js @ 86277e1489354192c64ffc8f995601daacc1f715: src/token.tsother · last read 2026-09-27 · latest outcome read · supports Cited by the legacy dossier research for this family
- aws/aws-bedrock-token-generator-python @ 228eec2bfcf209d53dc776c902e00d9e6548e508: aws_bedrock_token_generator/token_generator.pyother · last read 2026-09-27 · latest outcome read · supports Cited by the legacy dossier research for this family
- redact-secret/redact-secret @ 8b6a5fde52ecb4dfce13f09c7a947062d21483c7: docs/audits/evidence/864/README.mdproject-research-note · last read 2026-09-27 · latest outcome read · supports Final research evidence recorded by the legacy dossier
Provider documented ·
taxonomy-sources· current · observed 2026-09-27The legacy taxonomy lists 2 sources for this family. The taxonomy records no date; the dossier researchedAt is used as the observed-at date.
- docs.aws.amazon.com/bedrock/latest/userguide/api-keys-reference.htmlprovider-documentation · last read 2026-09-27 · latest outcome read · supports Listed as a source for this family in the legacy taxonomy
- aws/aws-bedrock-token-generator-python @ main: aws_bedrock_token_generator/token_generator.pyprovider-documentation · last read 2026-09-27 · latest outcome read · supports Listed as a source for this family in the legacy taxonomy
Open questions
No open question is recorded for this revision.
Benchmark dossier notes
- Shape
- prefix
bedrock-api-key-, then Base64 of a SigV4-presignedCallWithBearerTokenURL ending in&Version=1. The first 133 Base64 characters after the prefix are constant (they encode the fixed host, action, algorithm and credential parameters). Padded standard Base64, no URL-safe variant. Length is undocumented: about 500 characters with an empty session token, longer with one; "over 1000" is a vendor-blog figure. - Basis
- T1 for prefix, head and alphabet, from three AWS-authored token generators (Python, JavaScript, Java) and the AWS blog regex, whose printed body class is malformed (the intended class is standard Base64). Tail length is T2.
- Issuance
- not attempted. Generated client-side or from the console; never listed or revocable per key, only by denying the generating session. The #779 checklist compares console output with SDK output.
- Contract in core
- detector-families.md; final evidence in the #864 record linked in the frontmatter.
In this benchmark
- Fixtures
- 34
- Left readable
- 0
- Redacted too much
- 0
- False alarms
- 0
34 fixtures: 13 expect a redaction, 21 must stay quiet. See every row
| Evidence level | Fixtures | Left readable | Too much | False alarms |
|---|---|---|---|---|
| T1Provider-documented | 13 | 0 | 0 | 0 |
| T2Tool-corroborated | 13 | 0 | 0 | 0 |
| T3Project policy | 8 | 0 | 0 | 0 |
Every scanner on the same fixtures
In run order. Counts are what each scanner recorded on this family's fixtures, whichever rules it has; a scanner with no rule for the family has nothing to report on it.
| Scanner | Fixtures | Left readable | Too much | False alarms |
|---|---|---|---|---|
| flare-redactRuntime library · 1.6.1 · Published npm package · secrets-only (pii, generic_assignment disabled) · JavaScript engineNo rule maps to it | 34 | 12 | 1 | 0 |
| gitleaksRepository scanner · 8.30.1 · Directory scan · default rules1 rule targets it | 34 | 12 | 0 | 7 |
| redact-secretProduct measured here · 0.1.0-beta.14 · Published npm package · default detectors1 detector mapped | 34 | 0 | 0 | 0 |
| trufflehogRepository scanner · 3.97.4 · Filesystem scan · verification disabledNo rule maps to it | 34 | 13 | 0 | 0 |
Benchmark dossier questions
- Open caveat
- T1 covers the prefix, the fixed 133-character head and the alphabet; total length and the session-token part are T2 (undocumented). Needs console-issued keys to compare with SDK output (checklist in #779).
Looks like it, but isn't
- Collisions
- shares the header and variable with the long-term key; the prefix decides. The decoded URL exposes an
ASIAaccess key id, but the encoded form is Base64-wrapped. Claude Platform on AWS keys use a different prefix and are a separate product.
Scanner rules for this family
| Scanner | Rule | What the rule matches |
|---|---|---|
| gitleaks · rules 8.30.1 | aws-amazon-bedrock-api-key-short-lived | bedrock-api-key- + the Base64 pre-signed URL prefix |
No rule maps to this family in flare-redact, openredaction, trufflehog.
Fixtures in this family
| Fixture | Kind and evidence | redact-secret |
|---|---|---|
aws-bedrock-short-term-api-key-actions-envaws-bedrock · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
aws-bedrock-short-term-api-key-agent-settingsaws-bedrock · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
aws-bedrock-short-term-api-key-curl-beareraws-bedrock · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
aws-bedrock-short-term-api-key-dotenvaws-bedrock · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
aws-bedrock-short-term-api-key-embedded-leading-twinaws-bedrock · boundary-violation | Must not flagT2 · Tool-corroborated · twin | Quiet |
aws-bedrock-short-term-api-key-export-with-sessionaws-bedrock · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
aws-bedrock-short-term-api-key-head-only-twinaws-bedrock · wrong-length | Must not flagT2 · Tool-corroborated · twin | Quiet |
aws-bedrock-short-term-api-key-key-shape-bareaws-bedrock · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
aws-bedrock-short-term-api-key-key-shape-quotedaws-bedrock · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
aws-bedrock-short-term-api-key-key-shape-unicode-crlfaws-bedrock · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
aws-bedrock-short-term-api-key-openai-sdk-mantleaws-bedrock · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
aws-bedrock-short-term-api-key-pasted-keyaws-bedrock · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
aws-bedrock-short-term-api-key-plural-prefix-twinaws-bedrock · prefix-near-miss | Must not flagT2 · Tool-corroborated · twin | Quiet |
aws-bedrock-short-term-api-key-proxy-logaws-bedrock · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
aws-bedrock-short-term-api-key-python-environaws-bedrock · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
aws-bedrock-short-term-api-key-rule-with-body-class-near-missaws-bedrock · format-near-miss | Must not flagT2 · Tool-corroborated | Quiet |
aws-bedrock-short-term-api-key-scanner-rule-anchor-near-missaws-bedrock · format-near-miss | Must not flagT2 · Tool-corroborated | Quiet |
aws-bedrock-short-term-api-key-short-bodyaws-bedrock · benign-lookalike | Must not flagT2 · Tool-corroborated | Quiet |
aws-bedrock-short-term-api-key-tool-callaws-bedrock · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
aws-bedrock-short-term-api-key-urlsafe-body-twinaws-bedrock · wrong-alphabet | Must not flagT2 · Tool-corroborated · twin | Quiet |
aws-bedrock-short-term-api-key-capitalized-prefix-twinaws-bedrock · prefix-near-miss | Must not flagT2 · Tool-corroborated · twin | Quiet |
aws-bedrock-short-term-api-key-decoded-host-only-encoded-valueaws-bedrock · benign-encoded-value | Must not flagT2 · Tool-corroborated | Quiet |
aws-bedrock-short-term-api-key-docs-angle-placeholderaws-bedrock · documentation-placeholder | Must not flagT3 · Project policy | Quiet |
aws-bedrock-short-term-api-key-env-reference-referenceaws-bedrock · templated-reference | Must not flagT3 · Project policy | Quiet |
aws-bedrock-short-term-api-key-head-one-char-off-twinaws-bedrock · prefix-near-miss | Must not flagT2 · Tool-corroborated · twin | Quiet |
aws-bedrock-short-term-api-key-iam-action-and-arn-public-idaws-bedrock · public-identifier | Must not flagT2 · Tool-corroborated | Quiet |
aws-bedrock-short-term-api-key-key-guidance-proseaws-bedrock · prose-mention | Must not flagT3 · Project policy | Quiet |
aws-bedrock-short-term-api-key-label-proseaws-bedrock · benign-lookalike | Must not flagT3 · Project policy | Quiet |
aws-bedrock-short-term-api-key-maskaws-bedrock · benign-lookalike | Must not flagT3 · Project policy | Quiet |
aws-bedrock-short-term-api-key-prefix-onlyaws-bedrock · benign-lookalike | Must not flagT2 · Tool-corroborated | Quiet |
aws-bedrock-short-term-api-key-python-getenv-referenceaws-bedrock · templated-reference | Must not flagT3 · Project policy | Quiet |
aws-bedrock-short-term-api-key-referenceaws-bedrock · benign-lookalike | Must not flagT3 · Project policy | Quiet |
aws-bedrock-short-term-api-key-unrelated-base64-encoded-valueaws-bedrock · benign-encoded-value | Must not flagT2 · Tool-corroborated | Quiet |
aws-bedrock-short-term-api-key-your-key-here-placeholderaws-bedrock · documentation-placeholder | Must not flagT3 · Project policy | Quiet |
Sources
Documentation and code
- docs.aws.amazon.com/bedrock/latest/userguide/api-keys-reference.html
- github.com/aws/aws-bedrock-token-generator-python/blob/main/aws_bedrock_token_generator/token_generator.py
- aws.amazon.com/blogs/security/securing-amazon-bedrock-api-keys-best-practices-for-implementation-and-management/
- docs.aws.amazon.com/bedrock/latest/userguide/api-keys-revoke.html
- github.com/aws/aws-bedrock-token-generator-python/blob/228eec2bfcf209d53dc776c902e00d9e6548e508/aws_bedrock_token_generator/token_generator.py
- github.com/aws/aws-bedrock-token-generator-js/blob/86277e1489354192c64ffc8f995601daacc1f715/src/token.ts
- github.com/aws/aws-bedrock-token-generator-java/blob/65a626daa1314c16536030c86adafbad4a6b2d56/src/main/java/software/amazon/bedrock/token/BedrockTokenGenerator.java
Research log
- redact-secret/redact-secret#779Research issue
- redact-secret/redact-secret#774Research issue
- redact-secret/redact-secret#864Research issue
- redact-secret/redact-secret-benchmarks#384Research issue
- Final evidence, pinned to a commit/redact-secret/redact-secret/blob/8b6a5fde52ecb4dfce13f09c7a947062d21483c7/docs/audits/evidence/864/README.md