redact-secret · Report
API key (unprefixed)
40 alphanumeric characters recognised only beside a same-line cohere or CO_API_KEY name, host or SDK constructor; trial and production keys share one shape.
Research record
3 events in the review history: 2 observed, 1 reviewed. Latest: observed on 2026-09-27 by automation, project maintainer. Project-maintained review is not independent validation. The family record at this release.
Format
What it looks like
- Descriptive pattern
^[A-Za-z0-9]{40}$
Parts are shown as recorded. Evidence classes belong to the facts below; no class is assigned to a part.
Format facts
Unresolved ·
tool-corroboration· current · observed 2026-09-26Pinned scanner rules are consistent with the contract grammar (1 artifact: gitleaks 8.30.1).
- gitleaks/gitleaks @ v8.30.1: config/gitleaks.tomlscanner-rule-source · last read 2026-10-04 · latest outcome read · supports gitleaks 8.30.1: gitleaks.toml
Unresolved ·
field-shape· current · observed 2026-09-26shape: 40 alphanumeric characters, no prefix (One scanner rule; the length is the rule author's inference, not provider-stated.)
- gitleaks/gitleaks @ v8.30.1: config/gitleaks.tomlscanner-rule-source · last read 2026-10-04 · latest outcome read · supports cohere-api-token: [a-zA-Z0-9]{40}, entropy 4
Unresolved ·
field-context· current · observed 2026-09-26context: a same-line cohere or CO_API_KEY name before the value
- gitleaks/gitleaks @ v8.30.1: config/gitleaks.tomlscanner-rule-source · last read 2026-10-04 · latest outcome read · supports context: a same-line cohere or CO_API_KEY name before the value
Provider documented ·
field-trial-vs-production· current · observed 2026-09-26trial-vs-production: trial and production keys are one credential family; the difference is entitlement, not shape (The candidate id premise of a distinct production shape is unsupported.)
- docs.cohere.com/docs/rate-limitsprovider-documentation · last read 2026-09-27 · latest outcome read · supports trial-vs-production: trial and production keys are one credential family; the difference is entitlement, not shape
Provider documented ·
field-transport· current · observed 2026-09-26transport: CO_API_KEY (documented), COHERE_API_KEY (accepted), Authorization: Bearer
- docs.cohere.com/reference/check-api-keyprovider-documentation · last read 2026-09-26 · latest outcome read · supports transport: CO_API_KEY (documented), COHERE_API_KEY (accepted), Authorization: Bearer
- github.com/cohere-ai/cohere-pythonprovider-sdk-source · last read 2026-09-26 · latest outcome read · supports transport: CO_API_KEY (documented), COHERE_API_KEY (accepted), Authorization: Bearer
Unresolved ·
field-co-prefix· current · observed 2026-09-26co-prefix: a co- prefix (Not adopted and not asserted either way.)
- getbifrost.ai/guides/api-keys/how-to-get-a-cohere-api-keythird-party-writeup · last read 2026-09-26 · latest outcome read · supports one vendor blog; contradicts the gitleaks rule and GitGuardian
Provider documented ·
field-public-ids· current · observed 2026-09-26public-ids: organization_id (org_...) and owner_id (user_...) from the check-api-key response are public identifiers (Illustrative examples only; backs the public-id controls.)
- docs.cohere.com/reference/check-api-keyprovider-documentation · last read 2026-09-26 · latest outcome read · supports public-ids: organization_id (org_...) and owner_id (user_...) from the check-api-key response are public identifiers
Unresolved ·
listed-references· current · observed 2026-09-26The legacy contract lists 7 references without stating which property each supports.
- docs.cohere.com/reference/check-api-keyprovider-documentation · last read 2026-09-26 · latest outcome read · supports Listed as a reference by the legacy contract
- docs.cohere.com/docs/rate-limitsprovider-documentation · last read 2026-09-27 · latest outcome read · supports Listed as a reference by the legacy contract
- docs.gitguardian.com/secrets-detection/secrets-detection-engine/detectors/specifics/cohere_apikeyother · last read 2026-09-26 · latest outcome read · supports Listed as a reference by the legacy contract
- docs.github.com/en/code-security/secret-scanning/introduction/supported-secret-scanning-patternsprovider-documentation · last read 2026-10-05 · latest outcome read · supports Listed as a reference by the legacy contract
- github.com/cohere-ai/cohere-pythonprovider-sdk-source · last read 2026-09-26 · latest outcome read · supports Listed as a reference by the legacy contract
- github.com/redact-secret/redact-secret/issues/782issue-or-discussion · last read 2026-09-26 · latest outcome read · supports Listed as a reference by the legacy contract
- github.com/redact-secret/redact-secret/issues/868issue-or-discussion · last read 2026-09-26 · latest outcome read · supports Listed as a reference by the legacy contract
Tool corroborated ·
dossier-research· current · observed 2026-09-27Legacy dossier research (verdict ready, tier T2) cited 2 sources; the dossier does not attribute sources to individual properties.
- docs.cohere.com/docs/rate-limitsprovider-documentation · last read 2026-09-27 · latest outcome read · supports Cited by the legacy dossier research for this family
- gitleaks/gitleaks @ 83d9cd684c87d95d656c1458ef04895a7f1cbd8e: config/gitleaks.tomlscanner-rule-source · last read 2026-09-27 · latest outcome read · supports Cited by the legacy dossier research for this family
Tool corroborated ·
taxonomy-sources· current · observed 2026-09-27The legacy taxonomy lists 2 sources for this family. The taxonomy records no date; the dossier researchedAt is used as the observed-at date.
- docs.cohere.com/docs/rate-limitsprovider-documentation · last read 2026-09-27 · latest outcome read · supports Listed as a source for this family in the legacy taxonomy
- gitleaks/gitleaks @ v8.30.1: config/gitleaks.tomlscanner-rule-source · last read 2026-10-04 · latest outcome read · supports Listed as a source for this family in the legacy taxonomy
Open questions
No open question is recorded for this revision.
Benchmark dossier notes
- Shape
- no documented prefix; 40 alphanumeric characters
[A-Za-z0-9], recognised only beside a same-linecoherename,CO_API_KEY, the API host or an SDK constructor. Never a bare 40-character run. The length is not provider-stated. - Basis
- T2 at best; #868 records that no provider has T1 here. One gitleaks rule (
cohere-api-token, keyword then[a-zA-Z0-9]{40}) is the only length source. GitGuardian says "Prefixed: False" with no length. The SDK does no validation. GitHub secret scanning lists a Cohere pattern without publishing it. A vendor blog claims aco-prefix; it contradicts both scanners, has no example and no second source, and was not adopted. - Issuance
- not attempted. Dashboard API keys page, key names cannot contain spaces, shown once, revocable in the web UI or CLI. The #782 checklist compares a trial and a production key.
- Contract in core
- detector-families.md, section Keyword-gated provider keys (#868). #932 recognised the Java
Cohere.builder().token(...)form; amasked_-led LiteLLM log value stays unreported by policy.
In this benchmark
- Fixtures
- 78
- Left readable
- 0
- Redacted too much
- 0
- False alarms
- 0
78 fixtures: 51 must stay quiet, 27 record project policy. See every row
| Evidence level | Fixtures | Left readable | Too much | False alarms |
|---|---|---|---|---|
| T2Tool-corroborated | 21 | 0 | 0 | 0 |
| T3Project policy | 57 | 0 | 0 | 0 |
Every scanner on the same fixtures
In run order. Counts are what each scanner recorded on this family's fixtures, whichever rules it has; a scanner with no rule for the family has nothing to report on it.
| Scanner | Fixtures | Left readable | Too much | False alarms |
|---|---|---|---|---|
| flare-redactRuntime library · 1.6.1 · Published npm package · secrets-only (pii, generic_assignment disabled) · JavaScript engineNo rule maps to it | 78 | 25 | 2 | 0 |
| gitleaksRepository scanner · 8.30.1 · Directory scan · default rules1 rule targets it | 78 | 3 | 0 | 4 |
| redact-secretProduct measured here · 0.1.0-beta.14 · Published npm package · default detectors1 detector mapped | 78 | 0 | 0 | 0 |
| trufflehogRepository scanner · 3.97.4 · Filesystem scan · verification disabledNo rule maps to it | 78 | 27 | 0 | 0 |
Benchmark dossier questions
- Open caveat
- No provider source states any shape; 40 alphanumeric is one gitleaks rule's inference, so contextual only. Needs one trial and one production key measured (checklist in #782).
Looks like it, but isn't
- Collisions
- SHA-1-length hex and random ids,
org_anduser_ids from the check-api-key response, and unrelatedco-strings.
Scanner rules for this family
| Scanner | Rule | What the rule matches |
|---|---|---|
| gitleaks · rules 8.30.1 | cohere-api-token | cohere or CO_API_KEY keyword + 40 alphanumerics |
No rule maps to this family in flare-redact, openredaction, trufflehog.
Fixtures in this family
| Fixture | Kind and evidence | redact-secret |
|---|---|---|
cohere-api-key-actions-env-literalcohere · documented-format-literal | Project policyT3 · Project policy | Redacted |
cohere-api-key-azure-pipelines-varscohere · documented-format-literal | Project policyT3 · Project policy | Redacted |
cohere-api-key-compose-envcohere · documented-format-literal | Project policyT3 · Project policy | Redacted |
cohere-api-key-curl-headercohere · documented-format-literal | Project policyT3 · Project policy | Redacted |
cohere-api-key-docker-run-envcohere · documented-format-literal | Project policyT3 · Project policy | Redacted |
cohere-api-key-dotenvcohere · documented-format-literal | Project policyT3 · Project policy | Redacted |
cohere-api-key-dotenv-altcohere · documented-format-literal | Project policyT3 · Project policy | Redacted |
cohere-api-key-exportcohere · documented-format-literal | Project policyT3 · Project policy | Redacted |
cohere-api-key-http-request-headercohere · documented-format-literal | Project policyT3 · Project policy | Redacted |
cohere-api-key-id-named-env-alt-twincohere · missing-context-marker | Must not flagT3 · Project policy · twin | Quiet |
cohere-api-key-id-named-json-twincohere · missing-context-marker | Must not flagT3 · Project policy · twin | Quiet |
cohere-api-key-id-named-kwarg-twincohere · missing-context-marker | Must not flagT3 · Project policy · twin | Quiet |
cohere-api-key-inline-env-commandcohere · documented-format-literal | Project policyT3 · Project policy | Redacted |
cohere-api-key-java-builder-tokencohere · documented-format-literal | Project policyT3 · Project policy | Redacted |
cohere-api-key-json-configcohere · documented-format-literal | Project policyT3 · Project policy | Redacted |
cohere-api-key-k8s-env-valuecohere · documented-format-literal | Project policyT3 · Project policy | Redacted |
cohere-api-key-key-shape-barecohere · documented-format-literal | Project policyT3 · Project policy | Redacted |
cohere-api-key-key-shape-quotedcohere · documented-format-literal | Project policyT3 · Project policy | Redacted |
cohere-api-key-key-shape-unicode-crlfcohere · documented-format-literal | Project policyT3 · Project policy | Redacted |
cohere-api-key-langchain-kwargcohere · documented-format-literal | Project policyT3 · Project policy | Redacted |
cohere-api-key-litellm-proxy-debugcohere · documented-format-literal | Project policyT3 · Project policy | Redacted |
cohere-api-key-litellm-yamlcohere · documented-format-literal | Project policyT3 · Project policy | Redacted |
cohere-api-key-llamaindex-rerankcohere · documented-format-literal | Project policyT3 · Project policy | Redacted |
cohere-api-key-mcp-config-printcohere · documented-format-literal | Project policyT3 · Project policy | Redacted |
cohere-api-key-other-host-curl-twincohere · missing-context-marker | Must not flagT3 · Project policy · twin | Quiet |
cohere-api-key-printenv-outputcohere · documented-format-literal | Project policyT3 · Project policy | Redacted |
cohere-api-key-proxy-logcohere · documented-format-literal | Project policyT3 · Project policy | Redacted |
cohere-api-key-python-ctorcohere · documented-format-literal | Project policyT3 · Project policy | Redacted |
cohere-api-key-toml-config-keycohere · documented-format-literal | Project policyT3 · Project policy | Redacted |
cohere-api-key-tool-callcohere · documented-format-literal | Project policyT3 · Project policy | Redacted |
cohere-api-key-ts-ctorcohere · documented-format-literal | Project policyT3 · Project policy | Redacted |
cohere-api-key-actions-secret-referencecohere · templated-reference | Must not flagT3 · Project policy | Quiet |
cohere-api-key-angle-key-placeholdercohere · documentation-placeholder | Must not flagT3 · Project policy | Quiet |
cohere-api-key-bare-in-prose-near-misscohere · format-near-miss | Must not flagT2 · Tool-corroborated | Quiet |
cohere-api-key-bare-line-near-misscohere · format-near-miss | Must not flagT2 · Tool-corroborated | Quiet |
cohere-api-key-base64-text-encoded-valuecohere · benign-encoded-value | Must not flagT2 · Tool-corroborated | Quiet |
cohere-api-key-data-uri-encoded-valuecohere · benign-encoded-value | Must not flagT2 · Tool-corroborated | Quiet |
cohere-api-key-docs-ctor-placeholdercohere · documentation-placeholder | Must not flagT3 · Project policy | Quiet |
cohere-api-key-embed-response-public-idcohere · public-identifier | Must not flagT2 · Tool-corroborated | Quiet |
cohere-api-key-embedded-run-near-misscohere · format-near-miss | Must not flagT2 · Tool-corroborated | Quiet |
cohere-api-key-env-reference-referencecohere · templated-reference | Must not flagT3 · Project policy | Quiet |
cohere-api-key-finetune-listing-public-idcohere · public-identifier | Must not flagT2 · Tool-corroborated | Quiet |
cohere-api-key-id-named-compose-twincohere · missing-context-marker | Must not flagT3 · Project policy · twin | Quiet |
cohere-api-key-id-named-env-twincohere · missing-context-marker | Must not flagT3 · Project policy · twin | Quiet |
cohere-api-key-id-named-export-twincohere · missing-context-marker | Must not flagT3 · Project policy · twin | Quiet |
cohere-api-key-id-named-tool-call-twincohere · missing-context-marker | Must not flagT3 · Project policy · twin | Quiet |
cohere-api-key-key-guidance-prosecohere · prose-mention | Must not flagT3 · Project policy | Quiet |
cohere-api-key-key-shape-bare-twincohere · wrong-length | Must not flagT2 · Tool-corroborated · twin | Quiet |
cohere-api-key-key-shape-quoted-twincohere · wrong-length | Must not flagT2 · Tool-corroborated · twin | Quiet |
cohere-api-key-key-shape-unicode-crlf-twincohere · wrong-length | Must not flagT2 · Tool-corroborated · twin | Quiet |
Sources
Documentation and code
- docs.cohere.com/docs/rate-limits
- github.com/gitleaks/gitleaks/blob/v8.30.1/config/gitleaks.toml
- github.com/gitleaks/gitleaks/blob/83d9cd684c87d95d656c1458ef04895a7f1cbd8e/config/gitleaks.toml
Research log
- redact-secret/redact-secret#782Research issue
- redact-secret/redact-secret#774Research issue
- redact-secret/redact-secret#868Research issue
- redact-secret/redact-secret#932Research issue
- redact-secret/redact-secret-benchmarks#384Research issue