redact-secret · Report
API key secret (4b1d)
4b1d + exactly 38 [A-Za-z0-9] (42 in all), T1 as of 2025-04-16 (R3, provider staff); the key ID (Basic-auth username) is not claimed. The at-least-one-uppercase guard is product policy, not a provider fact.
Research record
3 events in the review history: 2 observed, 1 reviewed. Latest: observed on 2026-09-28 by automation, project maintainer. Project-maintained review is not independent validation. The family record at this release.
Format
What it looks like
- Descriptive pattern
^4b1d[A-Za-z0-9]{38}$
Parts are shown as recorded. Evidence classes belong to the facts below; no class is assigned to a part.
Format facts
Provider documented ·
provider-source· current · observed 2026-09-29gitleaks PR #1826 (merged 2025-04-16), authored by a ClickHouse employee: "we specifically choose a prefix (4b1d...)" and the rule 4b1d[A-Za-z0-9]{38}; 4b1d + 38 mixed-case alphanumeric examples in the provider-owned Terraform provider since 2023-05; a 42-byte unit-test fixture from 2024-07 (re-checked 2026-09-28): 4b1d + exactly 38 [A-Za-z0-9] (42 in all); no separator or checksum; T1 as of 2025-04-16 (R3), which sets aside the older 2023 39-byte knowledge-base example
- github.com/gitleaks/gitleaks/pull/1826provider-documentation · last read 2026-09-29 · latest outcome read · supports 4b1d + exactly 38 [A-Za-z0-9] (42 in all); no separator or checksum; T1 as of 2025-04-16 (R3), which sets aside the older 2023 39-byte knowledge-base example
Unresolved ·
tool-corroboration· current · observed 2026-09-29Pinned scanner rules are consistent with the contract grammar (1 artifact: gitleaks 8.30.1).
- gitleaks/gitleaks @ v8.30.1: config/gitleaks.tomlscanner-rule-source · last read 2026-10-04 · latest outcome read · supports gitleaks 8.30.1: clickhouse-cloud-api-secret-key
Provider documented ·
field-prefix· current · observed 2026-09-29prefix: 4b1d (T1 as of 2025-04-16. Provider staff wrote it in a third-party repository; the authorship, not the venue, is what R3 weighs.)
- ClickHouse/terraform-provider-clickhouse @ cfa09c82da2856dc163ddf1529ea7ef7a3e76fe7: examples/provider/provider.tfprovider-documentation · last read 2026-09-29 · latest outcome read · supports 4b1d example values since 2023-05 · #L16
- github.com/gitleaks/gitleaks/pull/1826provider-documentation · last read 2026-09-29 · latest outcome read · supports staff statement, merged 2025-04-16
- github.com/redact-secret/redact-secret/issues/860issue-or-discussion · last read 2026-09-29 · latest outcome read · supports R3: dated staff statement · #issuecomment-5852413851
Provider documented ·
field-body-length· current · observed 2026-09-29body-length: exactly 38 after the prefix (42 in all) (A single 2023 knowledge-base example is 39 bytes total; it is older, so R3 date order sets it aside.)
- ClickHouse/terraform-provider-clickhouse @ cfa09c82da2856dc163ddf1529ea7ef7a3e76fe7: internal/api/client_test.goprovider-documentation · last read 2026-09-29 · latest outcome read · supports a 2024 unit-test fixture, 42 bytes · #L20
- ClickHouse/terraform-provider-clickhouse @ cfa09c82da2856dc163ddf1529ea7ef7a3e76fe7: examples/provider/provider.tfprovider-documentation · last read 2026-09-29 · latest outcome read · supports provider example, 42 bytes · #L16
- github.com/gitleaks/gitleaks/pull/1826provider-documentation · last read 2026-09-29 · latest outcome read · supports staff-authored regex {38}
- github.com/redact-secret/redact-secret/issues/860issue-or-discussion · last read 2026-09-29 · latest outcome read · supports the maintainer accepted this on 2026-09-28 · #issuecomment-5880547337
Provider documented ·
field-alphabet· current · observed 2026-09-29alphabet: [A-Za-z0-9], mixed case
- ClickHouse/terraform-provider-clickhouse @ cfa09c82da2856dc163ddf1529ea7ef7a3e76fe7: examples/provider/provider.tfprovider-documentation · last read 2026-09-29 · latest outcome read · supports mixed-case examples · #L16
- github.com/gitleaks/gitleaks/pull/1826provider-documentation · last read 2026-09-29 · latest outcome read · supports staff-authored regex
Unresolved ·
field-policy-uppercase-guard· current · observed 2026-09-29policy-uppercase-guard: POLICY, not T1: the product requires at least one uppercase letter in the 38 body bytes (False-positive policy that removes lowercase and hex digests starting 4b1d. The staff regex admits an all-lowercase body, so no fixture asserts silence on one; every positive is mixed case and every twin keeps a mixed-case body.)
- redact-secret/redact-secret @ 8b6a5fde52ecb4dfce13f09c7a947062d21483c7: docs/audits/evidence/860/clickhouse-cloud.mdproject-research-note · last read 2026-09-29 · latest outcome read · supports implementation notes: project policy; P(no uppercase in 38 random alphanumerics) about 1e-9
Provider documented ·
field-separators· current · observed 2026-09-29separators: none; no checksum
- github.com/gitleaks/gitleaks/pull/1826provider-documentation · last read 2026-09-29 · latest outcome read · supports separators: none; no checksum
Unresolved ·
field-boundary· current · observed 2026-09-29boundary: a key glued to an alphanumeric, _ or - on either side is not claimed; 4b1d is valid hex, so mid-run occurrences must not match (Handoff boundary decision, not a provider statement.)
- redact-secret/redact-secret @ 8b6a5fde52ecb4dfce13f09c7a947062d21483c7: docs/audits/evidence/860/clickhouse-cloud.mdproject-research-note · last read 2026-09-29 · latest outcome read · supports implementation notes
Unresolved ·
field-key-id· current · observed 2026-09-29key-id: the key ID (Basic-auth username) has no marker: 17 or 20 alphanumerics, unresolved (Not claimed; it appears only as an unmarked companion of a positive and as a public-id control.)
- api.clickhouse.cloud/v1provider-documentation · last read 2026-09-29 · latest outcome read · supports key-id: the key ID (Basic-auth username) has no marker: 17 or 20 alphanumerics, unresolved
- redact-secret/redact-secret @ 8b6a5fde52ecb4dfce13f09c7a947062d21483c7: docs/audits/evidence/860/issuance-research/clickhouse-cloud.mdprovider-documentation · last read 2026-09-29 · latest outcome read · supports key-id: the key ID (Basic-auth username) has no marker: 17 or 20 alphanumerics, unresolved
Provider documented ·
field-hashdata-secrets· current · observed 2026-09-29hashdata-secrets: the API accepts a caller-supplied pre-hashed secret (hashData), so such a secret has no fixed shape (An accepted false negative; nothing is authored either way.)
- redact-secret/redact-secret @ 8b6a5fde52ecb4dfce13f09c7a947062d21483c7: docs/audits/evidence/860/issuance-research/clickhouse-cloud.mdprovider-documentation · last read 2026-09-29 · latest outcome read · supports hashdata-secrets: the API accepts a caller-supplied pre-hashed secret (hashData), so such a secret has no fixed shape
Provider documented ·
field-transport· current · observed 2026-09-29transport: CLICKHOUSE_CLOUD_API_KEY / CLICKHOUSE_CLOUD_API_SECRET, the Terraform token_secret and HTTP Basic auth (key ID : secret)
- api.clickhouse.cloud/v1provider-documentation · last read 2026-09-29 · latest outcome read · supports transport: CLICKHOUSE_CLOUD_API_KEY / CLICKHOUSE_CLOUD_API_SECRET, the Terraform token_secret and HTTP Basic auth (key ID : secret)
- ClickHouse/terraform-provider-clickhouse @ cfa09c82da2856dc163ddf1529ea7ef7a3e76fe7: examples/provider/provider.tfprovider-documentation · last read 2026-09-29 · latest outcome read · supports transport: CLICKHOUSE_CLOUD_API_KEY / CLICKHOUSE_CLOUD_API_SECRET, the Terraform token_secret and HTTP Basic auth (key ID : secret) · #L16
Tool corroborated ·
field-peer-lag· current · observed 2026-09-29peer-lag: gitleaks 8.30.1 has clickhouse-cloud-api-secret-key, \b(4b1d[A-Za-z0-9]{38})\b with entropy 3 and no case guard: it agrees with the T1 grammar, misses a low-entropy body under its entropy floor, and \b lets a glued - through; trufflehog 3.97.4 has no ClickHouse Cloud rule
- gitleaks/gitleaks @ v8.30.1: config/gitleaks.tomlscanner-rule-source · last read 2026-10-04 · latest outcome read · supports clickhouse-cloud-api-secret-key
- trufflesecurity/trufflehog @ v3.97.4: pkg/detectorsscanner-rule-source · last read 2026-09-29 · latest outcome read · supports no clickhouse detector directory at the pinned version
Unresolved ·
listed-references· current · observed 2026-09-29The legacy contract lists 12 references without stating which property each supports.
- api.clickhouse.cloud/v1provider-documentation · last read 2026-09-29 · latest outcome read · supports Listed as a reference by the legacy contract
- ClickHouse/terraform-provider-clickhouse @ cfa09c82da2856dc163ddf1529ea7ef7a3e76fe7: internal/api/client_test.goprovider-documentation · last read 2026-09-29 · latest outcome read · supports Listed as a reference by the legacy contract · #L20
- ClickHouse/terraform-provider-clickhouse @ cfa09c82da2856dc163ddf1529ea7ef7a3e76fe7: examples/provider/provider.tfprovider-documentation · last read 2026-09-29 · latest outcome read · supports Listed as a reference by the legacy contract · #L16
- github.com/gitleaks/gitleaks/pull/1826provider-documentation · last read 2026-09-29 · latest outcome read · supports Listed as a reference by the legacy contract
- redact-secret/redact-secret @ 8b6a5fde52ecb4dfce13f09c7a947062d21483c7: docs/audits/evidence/860/clickhouse-cloud.mdproject-research-note · last read 2026-09-29 · latest outcome read · supports Listed as a reference by the legacy contract
- redact-secret/redact-secret @ 8b6a5fde52ecb4dfce13f09c7a947062d21483c7: docs/audits/evidence/860/README.mdproject-research-note · last read 2026-09-29 · latest outcome read · supports Listed as a reference by the legacy contract
- github.com/redact-secret/redact-secret/issues/860issue-or-discussion · last read 2026-09-29 · latest outcome read · supports Listed as a reference by the legacy contract · #issuecomment-5852413851
- github.com/redact-secret/redact-secret/issues/860issue-or-discussion · last read 2026-09-29 · latest outcome read · supports Listed as a reference by the legacy contract · #issuecomment-5880547337
- github.com/redact-secret/redact-secret/issues/860issue-or-discussion · last read 2026-09-29 · latest outcome read · supports Listed as a reference by the legacy contract
- github.com/redact-secret/redact-secret-benchmarks/issues/464issue-or-discussion · last read 2026-09-29 · latest outcome read · supports Listed as a reference by the legacy contract
- redact-secret/redact-secret @ 8b6a5fde52ecb4dfce13f09c7a947062d21483c7: docs/audits/evidence/860/issuance-research/clickhouse-cloud.mdprovider-documentation · last read 2026-09-29 · latest outcome read · supports Listed as a reference by the legacy contract
- github.com/redact-secret/redact-secret/issues/971issue-or-discussion · last read 2026-09-29 · latest outcome read · supports Listed as a reference by the legacy contract
Provider documented ·
dossier-research· current · observed 2026-09-28Legacy dossier research (verdict ready, tier T1) cited 3 sources; the dossier does not attribute sources to individual properties.
- github.com/gitleaks/gitleaks/pull/1826provider-documentation · last read 2026-09-29 · latest outcome read · supports Cited by the legacy dossier research for this family
- redact-secret/redact-secret @ 8b6a5fde52ecb4dfce13f09c7a947062d21483c7: docs/audits/evidence/860/clickhouse-cloud.mdproject-research-note · last read 2026-09-29 · latest outcome read · supports Final research evidence recorded by the legacy dossier
- redact-secret/redact-secret @ 8b6a5fde52ecb4dfce13f09c7a947062d21483c7: docs/audits/evidence/860/issuance-research/clickhouse-cloud.mdprovider-documentation · last read 2026-09-29 · latest outcome read · supports Cited by the legacy dossier research for this family
Provider documented ·
taxonomy-sources· current · observed 2026-09-28The legacy taxonomy lists 2 sources for this family. The taxonomy records no date; the dossier researchedAt is used as the observed-at date.
- github.com/gitleaks/gitleaks/pull/1826provider-documentation · last read 2026-09-29 · latest outcome read · supports Listed as a source for this family in the legacy taxonomy
- redact-secret/redact-secret @ 8b6a5fde52ecb4dfce13f09c7a947062d21483c7: docs/audits/evidence/860/clickhouse-cloud.mdproject-research-note · last read 2026-09-29 · latest outcome read · supports Listed as a source for this family in the legacy taxonomy
Open questions
No open question is recorded for this revision.
Benchmark dossier notes
- Shape
- prefix
4b1d, then exactly 38 alphanumeric characters[A-Za-z0-9](42 in total), mixed case; no separator or checksum. The key ID (Basic-auth username) is not claimed. - Basis
- prefix T1 under R3 (a ClickHouse employee wrote in gitleaks PR #1826, merged 2025-04-16: "we specifically choose a prefix (4b1d...)"), body and alphabet T1 under R2 and R3 (the same author's rule
4b1d[A-Za-z0-9]{38}, corroborated by provider-owned Terraform examples since 2023-05 and a 2024 unit-test fixture, all 42 bytes). T1 as of 2025-04-16. - Issuance
- not attempted; the one contradiction (a 2023 knowledge-base example of 39 bytes) is older than the staff statement, so R3 date order sets it aside.
- Contract in core
- detector-families.md (no row until the Beta.12 detector, redact-secret#971, is merged).
In this benchmark
- Fixtures
- 45
- Left readable
- 0
- Redacted too much
- 0
- False alarms
- 0
45 fixtures: 19 expect a redaction, 26 must stay quiet. See every row
| Evidence level | Fixtures | Left readable | Too much | False alarms |
|---|---|---|---|---|
| T1Provider-documented | 19 | 0 | 0 | 0 |
| T2Tool-corroborated | 18 | 0 | 0 | 0 |
| T3Project policy | 8 | 0 | 0 | 0 |
Every scanner on the same fixtures
In run order. Counts are what each scanner recorded on this family's fixtures, whichever rules it has; a scanner with no rule for the family has nothing to report on it.
| Scanner | Fixtures | Left readable | Too much | False alarms |
|---|---|---|---|---|
| flare-redactRuntime library · 1.6.1 · Published npm package · secrets-only (pii, generic_assignment disabled) · JavaScript engineNo rule maps to it | 45 | 18 | 1 | 1 |
| gitleaksRepository scanner · 8.30.1 · Directory scan · default rules1 rule targets it | 45 | 0 | 0 | 2 |
| redact-secretProduct measured here · 0.1.0-beta.14 · Published npm package · default detectors1 detector mapped | 45 | 0 | 0 | 0 |
| trufflehogRepository scanner · 3.97.4 · Filesystem scan · verification disabledNo rule maps to it | 45 | 19 | 0 | 0 |
Benchmark dossier questions
- Open caveat
- the uppercase guard is project policy (false-negative cost about 1e-9), not a provider fact; secrets supplied through the API's
hashDatahave no fixed shape and are an accepted false negative.
Looks like it, but isn't
- Collisions
4b1dis valid hex, so the leading boundary is load-bearing; the product adds an at-least-one-uppercase guard as policy (removes hex digests starting4b1d), which is not a provider fact. UUIDs containing-4b1d-are not keys.
Scanner rules for this family
| Scanner | Rule | What the rule matches |
|---|---|---|
| gitleaks · rules 8.30.1 | clickhouse-cloud-api-secret-key | 4b1d + 38 alphanumerics |
No rule maps to this family in flare-redact, openredaction, trufflehog.
Fixtures in this family
| Fixture | Kind and evidence | redact-secret |
|---|---|---|
clickhouse-cloud-api-secret-actions-envclickhouse-cloud · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
clickhouse-cloud-api-secret-bare-proseclickhouse-cloud · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
clickhouse-cloud-api-secret-bearer-headerclickhouse-cloud · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
clickhouse-cloud-api-secret-chat-pasteclickhouse-cloud · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
clickhouse-cloud-api-secret-compose-envclickhouse-cloud · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
clickhouse-cloud-api-secret-curl-user-literalclickhouse-cloud · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
clickhouse-cloud-api-secret-curl-user-varclickhouse-cloud · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
clickhouse-cloud-api-secret-dotenvclickhouse-cloud · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
clickhouse-cloud-api-secret-dotenv-key-id-pairclickhouse-cloud · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
clickhouse-cloud-api-secret-exportclickhouse-cloud · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
clickhouse-cloud-api-secret-json-api-keyclickhouse-cloud · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
clickhouse-cloud-api-secret-json-tokenclickhouse-cloud · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
clickhouse-cloud-api-secret-key-guidance-proseclickhouse-cloud · prose-mention | Must not flagT3 · Project policy | Quiet |
clickhouse-cloud-api-secret-key-shape-bareclickhouse-cloud · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
clickhouse-cloud-api-secret-key-shape-quotedclickhouse-cloud · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
clickhouse-cloud-api-secret-key-shape-unicode-crlfclickhouse-cloud · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
clickhouse-cloud-api-secret-python-requests-authclickhouse-cloud · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
clickhouse-cloud-api-secret-sdk-kwargclickhouse-cloud · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
clickhouse-cloud-api-secret-terraform-token-secretclickhouse-cloud · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
clickhouse-cloud-api-secret-trailing-hyphen-twinclickhouse-cloud · boundary-violation | Must not flagT2 · Tool-corroborated · twin | Quiet |
clickhouse-cloud-api-secret-trailing-underscore-twinclickhouse-cloud · boundary-violation | Must not flagT2 · Tool-corroborated · twin | Quiet |
clickhouse-cloud-api-secret-x-api-key-headerclickhouse-cloud · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
clickhouse-cloud-api-secret-actions-secret-referenceclickhouse-cloud · templated-reference | Must not flagT3 · Project policy | Quiet |
clickhouse-cloud-api-secret-base64-run-mid-encoded-valueclickhouse-cloud · benign-encoded-value | Must not flagT2 · Tool-corroborated | Quiet |
clickhouse-cloud-api-secret-body-37-twinclickhouse-cloud · wrong-length | Must not flagT2 · Tool-corroborated · twin | Quiet |
clickhouse-cloud-api-secret-body-39-twinclickhouse-cloud · wrong-length | Must not flagT2 · Tool-corroborated · twin | Quiet |
clickhouse-cloud-api-secret-docs-placeholders-placeholderclickhouse-cloud · documentation-placeholder | Must not flagT3 · Project policy | Quiet |
clickhouse-cloud-api-secret-ellipsis-placeholderclickhouse-cloud · documentation-placeholder | Must not flagT3 · Project policy | Quiet |
clickhouse-cloud-api-secret-env-reference-referenceclickhouse-cloud · templated-reference | Must not flagT3 · Project policy | Quiet |
clickhouse-cloud-api-secret-hyphen-in-body-twinclickhouse-cloud · wrong-alphabet | Must not flagT2 · Tool-corroborated · twin | Quiet |
clickhouse-cloud-api-secret-key-id-alone-public-idclickhouse-cloud · public-identifier | Must not flagT2 · Tool-corroborated | Quiet |
clickhouse-cloud-api-secret-knowledge-base-39-byte-total-twinclickhouse-cloud · wrong-length | Must not flagT2 · Tool-corroborated · twin | Quiet |
clickhouse-cloud-api-secret-label-proseclickhouse-cloud · benign-lookalike | Must not flagT3 · Project policy | Quiet |
clickhouse-cloud-api-secret-leading-glue-twinclickhouse-cloud · boundary-violation | Must not flagT2 · Tool-corroborated · twin | Quiet |
clickhouse-cloud-api-secret-leading-underscore-twinclickhouse-cloud · boundary-violation | Must not flagT2 · Tool-corroborated · twin | Quiet |
clickhouse-cloud-api-secret-maskclickhouse-cloud · benign-lookalike | Must not flagT3 · Project policy | Quiet |
clickhouse-cloud-api-secret-prefix-onlyclickhouse-cloud · benign-lookalike | Must not flagT2 · Tool-corroborated | Quiet |
clickhouse-cloud-api-secret-referenceclickhouse-cloud · benign-lookalike | Must not flagT3 · Project policy | Quiet |
clickhouse-cloud-api-secret-sha1-digest-4b1d-encoded-valueclickhouse-cloud · benign-encoded-value | Must not flagT2 · Tool-corroborated | Quiet |
clickhouse-cloud-api-secret-sha256-digest-4b1d-encoded-valueclickhouse-cloud · benign-encoded-value | Must not flagT2 · Tool-corroborated | Quiet |
clickhouse-cloud-api-secret-short-bodyclickhouse-cloud · benign-lookalike | Must not flagT2 · Tool-corroborated | Quiet |
clickhouse-cloud-api-secret-truncated-near-missclickhouse-cloud · format-near-miss | Must not flagT2 · Tool-corroborated | Quiet |
clickhouse-cloud-api-secret-uppercase-prefix-twinclickhouse-cloud · prefix-near-miss | Must not flagT2 · Tool-corroborated · twin | Quiet |
clickhouse-cloud-api-secret-uuid-with-4b1d-public-idclickhouse-cloud · public-identifier | Must not flagT2 · Tool-corroborated | Quiet |
clickhouse-cloud-api-secret-wrong-prefix-4b1c-twinclickhouse-cloud · prefix-near-miss | Must not flagT2 · Tool-corroborated · twin | Quiet |
Sources
Documentation and code
- github.com/gitleaks/gitleaks/pull/1826
- github.com/redact-secret/redact-secret/blob/8b6a5fde52ecb4dfce13f09c7a947062d21483c7/docs/audits/evidence/860/clickhouse-cloud.md
- github.com/redact-secret/redact-secret/blob/8b6a5fde52ecb4dfce13f09c7a947062d21483c7/docs/audits/evidence/860/issuance-research/clickhouse-cloud.md
Research log
- redact-secret/redact-secret#860Research issue
- redact-secret/redact-secret#971Research issue
- redact-secret/redact-secret-benchmarks#464Research issue
- Final evidence, pinned to a commit/redact-secret/redact-secret/blob/8b6a5fde52ecb4dfce13f09c7a947062d21483c7/docs/audits/evidence/860/clickhouse-cloud.md