Skip to content
Benchmarks

redact-secret · Report

Tokens (bkua_ and sibling role prefixes)

One of 15 provider-listed prefixes + a base64url-and-dot body of 24 or more characters.

  • Buildkite
  • Detectors: buildkite-token
  • Run 2026-10-07
  • Mode published · redact-secret 0.1.0-beta.14
  • Dossier verdictReady
  • Dossier evidence levelT1 · Provider-documented
  • Dossier researched2026-09-30
Registered in the product at the 3b1a5aa re-pin (redact-secret PR #1214, unreleased), with a benchmark contract and a seeded corpus (#583, `beta8-583e`); the claim stays provisional until the conformance and arrival gates and the open ruling questions settle. Not a support claim. Handoff buildkite.md (READY); includes a JWT-body case the existing peer rule does not know.

Research record

From credential-evidence snapshot-2026.10.06.4 · records at 77ce761 · schema 1.8.0. It describes the research on the format, not what any scanner or the product does, and not a support status.
  • Review stateNot recorded
  • Format revisionNot recorded
  • ResearchNot recorded
  • ResearchedNot recorded

No research record for this family

snapshot-2026.10.06.4 has no family record for buildkite:access-token, so its review state, format revision and format facts are not recorded here.

Not recorded

Format

Provider format research from credential-evidence snapshot-2026.10.06.4 · records at 77ce761 · schema 1.8.0.

Format not recorded

No format contract is recorded for this family in the pinned release.

Not recorded

Benchmark dossier notes

From the provider dossier, as written. The evidence level above says how well the format is backed; a fact the dossier does not record is not shown.
Shape
one of 15 provider-listed prefixes (bkua_, bkur_, bktx_, bkaa_, bkar_, bkct_, bkcqt_, bkaj_, bkjat_, bkpt_, bkrt_, bktr_, bkat_, bkpat_, bkps_) + 24 to 2048 bytes over [A-Za-z0-9_.-]. Bodies are bare hex, an org id then . then base58, an org id then _ then hex, or a three-part JWT (bkjat_, bkaj_).
Basis
T1 under R2: the provider's own redactor (buildkite/agent internal/redact/redact.go, merged 2026-09-29) lists the prefixes, the alphabet, the floor 24 and the cap 2048; the provider token docs list nine of the prefixes by role, and six rest on the rule and its comments alone. The provider states no per-type length, so none is claimed. The floor of 24 serving as the T1 floor is ruling Q7 (open, recommendation yes); a floor of 38 is a one-constant change. trufflehog buildkite/v2 reads only bkua_ + 40 lowercase hex (T2, lag measured).
Issuance
not attempted; the handoff records no issuance gate (an optional structure-only check of one API access token and one agent token is described there).
Contract in core
detector-families.md (the detector buildkite-token, redact-secret#1105, registered on main and unreleased). The benchmark contract is benchmarks/lib/beta8/583e.ts.

In this benchmark

Fixture rows on the current run. Counts are for redact-secret in published · redact-secret 0.1.0-beta.14 mode.

No fixtures in this family yet

Nothing in the corpus targets it, so nothing is measured and no coverage is claimed.

Not measured

Looks like it, but isn't

Values the dossier records as resembling this credential without being one.
Collisions
the legacy bare 40-hex API token and the unprefixed agent token have no distinctive shape (unclaimed); bka_ + 40 alphanumerics has one third-party source (unclaimed); a snake_case identifier that begins with a listed prefix and has a body of 24 or more is the accepted false positive; jwt also sees the eyJ body of bkjat_ and bkaj_, and the prefixed form wins (R7).

Scanner rules for this family

Mapped by hand (reviewed 2026-09-30) from each scanner's pinned rule file, never from what a scanner found on the fixtures.
Peer scanner rules that target this family
ScannerRuleWhat the rule matches
trufflehog · rules 3.97.4buildkite/v2bkua_ + 40 [a-z0-9] (the API access token role only)

No rule maps to this family in flare-redact, gitleaks, openredaction.

0 of 0 rows

No fixtures in this family yet

Nothing in the corpus targets it, so nothing is measured and no coverage is claimed.

Not measured

Sources

Researched 2026-09-30.

Documentation and code

  • github.com/redact-secret/redact-secret/blob/3b1a5aa9935c57416a026a44f45501fd41ffeac8/docs/audits/evidence/1014/buildkite.md
  • github.com/buildkite/agent/blob/4b52e509c730797c2a97487972fdf99477fd07e6/internal/redact/redact.go#L30-L69
  • buildkite.com/docs/platform/security/tokens

Research log