redact-secret · Report
Cloud API secret (unprefixed, pre-2025-07-30)
Unprefixed 64-byte base64-body API secret, recognized only beside a same-line confluent keyword.
Research record
3 events in the review history: 2 observed, 1 reviewed. Latest: observed on 2026-09-24 by automation, project maintainer. Project-maintained review is not independent validation. The family record at this release.
Format
What it looks like
Shape not recorded.
Format facts
Tool corroborated ·
tool-corroboration· current · observed 2026-09-17Pinned scanner rules are consistent with the contract grammar (2 artifacts: gitleaks 8.30.1; trufflehog 3.97.4).
- gitleaks/gitleaks @ v8.30.1: config/gitleaks.tomlscanner-rule-source · last read 2026-10-04 · latest outcome read · supports gitleaks 8.30.1: gitleaks.toml
- trufflesecurity/trufflehog @ v3.97.4: pkg/detectors/confluent/confluent.goscanner-rule-source · last read 2026-09-23 · latest outcome read · supports trufflehog 3.97.4: confluent/confluent
Tool corroborated ·
field-context-gate· current · observed 2026-09-17context gate: no value grammar of its own: scored as policy, only beside a same-line confluent keyword
- gitleaks/gitleaks @ v8.30.1: config/gitleaks.tomlscanner-rule-source · last read 2026-10-04 · latest outcome read · supports context gate: no value grammar of its own: scored as policy, only beside a same-line confluent keyword
- trufflesecurity/trufflehog @ v3.97.4: pkg/detectors/confluent/confluent.goscanner-rule-source · last read 2026-09-23 · latest outcome read · supports context gate: no value grammar of its own: scored as policy, only beside a same-line confluent keyword
Provider documented ·
field-prefix· current · observed 2026-09-24prefix: secrets created before 2025-07-30 "may not include cflt"; the release notes say "do not have" and "on or after" — the cut-over wording differs across three provider pages
- docs.confluent.io/cloud/current/security/authenticate/workload-identities/service-accounts/api-keys/overview.htmlprovider-documentation · last read 2026-09-24 · latest outcome read · supports prefix: secrets created before 2025-07-30 "may not include cflt"; the release notes say "do not have" and "on or after" — the cut-over wording differs across three provider pages
- docs.confluent.io/cloud/current/release-notes/index.htmlprovider-documentation · last read 2026-09-24 · latest outcome read · supports prefix: secrets created before 2025-07-30 "may not include cflt"; the release notes say "do not have" and "on or after" — the cut-over wording differs across three provider pages
Provider documented ·
field-length· current · observed 2026-09-24length: 64 characters in every CLI-table placeholder, the Flink JSON example and the provider's Terraform test data; one provider Basic-auth example shows 60 (The 60/64 ambiguity is preserved: positives use 64, and no fixture asserts silence on a 60-character value. The pre-existing 63-character length twin rests on both pinned tools' exact 64-character rules.)
- docs.confluent.io/cloud/current/connectors/connect-api-section.htmlprovider-documentation · last read 2026-09-24 · latest outcome read · supports 60-character example
- docs.confluent.io/cloud/current/flink/operate-and-deploy/generate-api-key-for-flink.htmlprovider-documentation · last read 2026-09-24 · latest outcome read · supports length: 64 characters in every CLI-table placeholder, the Flink JSON example and the provider's Terraform test data; one provider Basic-auth example shows 60
- github.com/redact-secret/redact-secret-benchmarks/issues/233provider-documentation · last read 2026-09-24 · latest outcome read · supports length: 64 characters in every CLI-table placeholder, the Flink JSON example and the provider's Terraform test data; one provider Basic-auth example shows 60
Provider documented ·
field-alphabet· current · observed 2026-09-24alphabet: A-Z a-z 0-9 + / with no = padding in any example
- github.com/redact-secret/redact-secret-benchmarks/issues/233provider-documentation · last read 2026-09-24 · latest outcome read · supports alphabet: A-Z a-z 0-9 + / with no = padding in any example
Unresolved ·
field-current-issuance-reproducibility· current · observed 2026-09-24current-issuance reproducibility: a new key is always the cflt generation, so no new legacy secret can be issued; only an existing pre-cut-over key could corroborate
- github.com/redact-secret/redact-secret-benchmarks/issues/233provider-documentation · last read 2026-09-24 · latest outcome read · supports current-issuance reproducibility: a new key is always the cflt generation, so no new legacy secret can be issued; only an existing pre-cut-over key could corroborate
Unresolved ·
dossier-research· current · observed 2026-09-24Legacy dossier research (verdict ready, tier T2) cited 3 sources; the dossier does not attribute sources to individual properties.
- docs.confluent.io/cloud/current/security/authenticate/workload-identities/service-accounts/api-keys/overview.htmlprovider-documentation · last read 2026-09-24 · latest outcome read · supports Cited by the legacy dossier research for this family
- docs.confluent.io/cloud/current/security/authenticate/identity-faq.htmlprovider-documentation · last read 2026-09-24 · latest outcome read · supports Cited by the legacy dossier research for this family
- docs.confluent.io/cloud/current/release-notes/index.htmlprovider-documentation · last read 2026-09-24 · latest outcome read · supports Cited by the legacy dossier research for this family
Unresolved ·
taxonomy-sources· current · observed 2026-09-24The legacy taxonomy lists 1 source for this family. The taxonomy records no date; the dossier researchedAt is used as the observed-at date.
- docs.confluent.io/cloud/current/security/authenticate/workload-identities/service-accounts/api-keys/overview.htmlprovider-documentation · last read 2026-09-24 · latest outcome read · supports Listed as a source for this family in the legacy taxonomy
Open questions
No open question is recorded for this revision.
Benchmark dossier notes
- Shape
- an unprefixed 64-character run over
A-Z a-z 0-9 + /. No checksum is documented. Confluent's CLI-table examples, Flink example and Terraform provider test data show 64; one Connect API Basic-auth example shows 60 (probably a hand-edited placeholder). - Basis
- T2. Provider examples and provider test fixtures corroborate length and alphabet; gitleaks (
[a-z0-9]{64},(?i), no+or/) and trufflehog ([a-zA-Z0-9+/]{64}, key and secret pair required) supply the rule shape and the keyword gate. Kingfisher imports the gitleaks lineage and is not independent. - Issuance
- not possible; new secrets are prefixed. Cannot be re-observed.
- Contract in core
- detector-families.md (keyword-gated legacy shape, confidence-gated).
In this benchmark
- Fixtures
- 60
- Left readable
- 0
- Redacted too much
- 0
- False alarms
- 0
60 fixtures: 41 must stay quiet, 19 record project policy. See every row
| Evidence level | Fixtures | Left readable | Too much | False alarms |
|---|---|---|---|---|
| T2Tool-corroborated | 18 | 0 | 0 | 0 |
| T3Project policy | 42 | 0 | 0 | 0 |
Every scanner on the same fixtures
In run order. Counts are what each scanner recorded on this family's fixtures, whichever rules it has; a scanner with no rule for the family has nothing to report on it.
| Scanner | Fixtures | Left readable | Too much | False alarms |
|---|---|---|---|---|
| flare-redactRuntime library · 1.6.1 · Published npm package · secrets-only (pii, generic_assignment disabled) · JavaScript engineNo rule maps to it | 60 | 18 | 1 | 0 |
| gitleaksRepository scanner · 8.30.1 · Directory scan · default rules1 rule targets it | 60 | 11 | 0 | 2 |
| redact-secretProduct measured here · 0.1.0-beta.14 · Published npm package · default detectors1 detector mapped | 60 | 0 | 0 | 0 |
| trufflehogRepository scanner · 3.97.4 · Filesystem scan · verification disabled1 rule targets it | 60 | 19 | 0 | 0 |
Benchmark dossier questions
- Open caveat
- Provider states no length or alphabet for the unprefixed form; 64 comes from doc examples, provider test data and two scanner rules, one doc example shows 60. No legacy secret can be newly issued.
Looks like it, but isn't
- Collisions
- any 64-character base64-alphabet run, including a 64-hex digest, so the value is only claimed beside a
confluentkeyword. A prefixed secret also satisfies this shape. Percent-encoding of+and/inside URL userinfo breaks the run.
Scanner rules for this family
| Scanner | Rule | What the rule matches |
|---|---|---|
| gitleaks · rules 8.30.1 | confluent-secret-key | confluent keyword + 64 alphanumerics |
| trufflehog · rules 3.97.4 | confluent | confluent keyword + 64 characters |
No rule maps to this family in flare-redact, openredaction.
Fixtures in this family
| Fixture | Kind and evidence | redact-secret |
|---|---|---|
confluent-cloud-api-secret-legacy-actions-envconfluent · documented-format-literal | Project policyT3 · Project policy | Redacted |
confluent-cloud-api-secret-legacy-api-key-id-public-idconfluent · public-identifier | Must not flagT2 · Tool-corroborated | Quiet |
confluent-cloud-api-secret-legacy-api-key-storeconfluent · documented-format-literal | Project policyT3 · Project policy | Redacted |
confluent-cloud-api-secret-legacy-client-config-createconfluent · documented-format-literal | Project policyT3 · Project policy | Redacted |
confluent-cloud-api-secret-legacy-client-logconfluent · documented-format-literal | Project policyT3 · Project policy | Redacted |
confluent-cloud-api-secret-legacy-compose-jaasconfluent · documented-format-literal | Project policyT3 · Project policy | Redacted |
confluent-cloud-api-secret-legacy-connect-worker-configconfluent · documented-format-literal | Project policyT3 · Project policy | Redacted |
confluent-cloud-api-secret-legacy-envconfluent · documented-format-literal | Project policyT3 · Project policy | Redacted |
confluent-cloud-api-secret-legacy-exportconfluent · documented-format-literal | Project policyT3 · Project policy | Redacted |
confluent-cloud-api-secret-legacy-global-key-id-public-idconfluent · public-identifier | Must not flagT2 · Tool-corroborated | Quiet |
confluent-cloud-api-secret-legacy-iam-curlconfluent · documented-format-literal | Project policyT3 · Project policy | Redacted |
confluent-cloud-api-secret-legacy-java-client-propertiesconfluent · documented-format-literal | Project policyT3 · Project policy | Redacted |
confluent-cloud-api-secret-legacy-js-constantconfluent · documented-format-literal | Project policyT3 · Project policy | Redacted |
confluent-cloud-api-secret-legacy-k8s-secretconfluent · documented-format-literal | Project policyT3 · Project policy | Redacted |
confluent-cloud-api-secret-legacy-keyword-context-bareconfluent · documented-format-literal | Project policyT3 · Project policy | Redacted |
confluent-cloud-api-secret-legacy-keyword-context-quotedconfluent · documented-format-literal | Project policyT3 · Project policy | Redacted |
confluent-cloud-api-secret-legacy-keyword-context-unicode-crlfconfluent · documented-format-literal | Project policyT3 · Project policy | Redacted |
confluent-cloud-api-secret-legacy-librdkafka-dictconfluent · documented-format-literal | Project policyT3 · Project policy | Redacted |
confluent-cloud-api-secret-legacy-schema-registry-urlconfluent · documented-format-literal | Project policyT3 · Project policy | Redacted |
confluent-cloud-api-secret-legacy-schema-registry-user-infoconfluent · documented-format-literal | Project policyT3 · Project policy | Redacted |
confluent-cloud-api-secret-legacy-tfvarsconfluent · documented-format-literal | Project policyT3 · Project policy | Redacted |
confluent-cloud-api-secret-legacy-actions-context-twinconfluent · missing-context-marker | Must not flagT3 · Project policy · twin | Quiet |
confluent-cloud-api-secret-legacy-actions-secret-referenceconfluent · templated-reference | Must not flagT3 · Project policy | Quiet |
confluent-cloud-api-secret-legacy-angle-secret-placeholderconfluent · documentation-placeholder | Must not flagT3 · Project policy | Quiet |
confluent-cloud-api-secret-legacy-api-key-list-public-idconfluent · public-identifier | Must not flagT2 · Tool-corroborated | Quiet |
confluent-cloud-api-secret-legacy-api-key-store-context-twinconfluent · missing-context-marker | Must not flagT3 · Project policy · twin | Quiet |
confluent-cloud-api-secret-legacy-bootstrap-host-public-idconfluent · public-identifier | Must not flagT2 · Tool-corroborated | Quiet |
confluent-cloud-api-secret-legacy-cflt-asset-url-near-missconfluent · format-near-miss | Must not flagT2 · Tool-corroborated | Quiet |
confluent-cloud-api-secret-legacy-config-provider-referenceconfluent · templated-reference | Must not flagT3 · Project policy | Quiet |
confluent-cloud-api-secret-legacy-config-provider-reference-templated-referenceconfluent · templated-reference | Must not flagT3 · Project policy | Quiet |
confluent-cloud-api-secret-legacy-current-generation-tfvars-twinconfluent · prefix-near-miss | Must not flagT2 · Tool-corroborated · twin | Quiet |
confluent-cloud-api-secret-legacy-current-generation-twinconfluent · prefix-near-miss | Must not flagT2 · Tool-corroborated · twin | Quiet |
confluent-cloud-api-secret-legacy-env-context-twinconfluent · missing-context-marker | Must not flagT3 · Project policy · twin | Quiet |
confluent-cloud-api-secret-legacy-export-context-twinconfluent · missing-context-marker | Must not flagT3 · Project policy · twin | Quiet |
confluent-cloud-api-secret-legacy-iam-curl-context-twinconfluent · missing-context-marker | Must not flagT3 · Project policy · twin | Quiet |
confluent-cloud-api-secret-legacy-image-digest-encoded-valueconfluent · benign-encoded-value | Must not flagT2 · Tool-corroborated | Quiet |
confluent-cloud-api-secret-legacy-jaas-template-placeholderconfluent · documentation-placeholder | Must not flagT3 · Project policy | Quiet |
confluent-cloud-api-secret-legacy-js-constant-context-twinconfluent · missing-context-marker | Must not flagT3 · Project policy · twin | Quiet |
confluent-cloud-api-secret-legacy-k8s-secret-context-twinconfluent · missing-context-marker | Must not flagT3 · Project policy · twin | Quiet |
confluent-cloud-api-secret-legacy-key-id-twice-near-missconfluent · format-near-miss | Must not flagT2 · Tool-corroborated | Quiet |
confluent-cloud-api-secret-legacy-keyword-context-bare-twinconfluent · wrong-length | Must not flagT2 · Tool-corroborated · twin | Quiet |
confluent-cloud-api-secret-legacy-keyword-context-quoted-twinconfluent · wrong-length | Must not flagT2 · Tool-corroborated · twin | Quiet |
confluent-cloud-api-secret-legacy-keyword-context-unicode-crlf-twinconfluent · wrong-length | Must not flagT2 · Tool-corroborated · twin | Quiet |
confluent-cloud-api-secret-legacy-label-proseconfluent · benign-lookalike | Must not flagT3 · Project policy | Quiet |
confluent-cloud-api-secret-legacy-length-63-twinconfluent · wrong-length | Must not flagT2 · Tool-corroborated · twin | Quiet |
confluent-cloud-api-secret-legacy-librdkafka-dict-context-twinconfluent · missing-context-marker | Must not flagT3 · Project policy · twin | Quiet |
confluent-cloud-api-secret-legacy-maskconfluent · benign-lookalike | Must not flagT3 · Project policy | Quiet |
confluent-cloud-api-secret-legacy-masked-table-placeholderconfluent · documentation-placeholder | Must not flagT3 · Project policy | Quiet |
confluent-cloud-api-secret-legacy-missing-keywordconfluent · benign-lookalike | Must not flagT2 · Tool-corroborated | Quiet |
confluent-cloud-api-secret-legacy-one-time-note-proseconfluent · prose-mention | Must not flagT3 · Project policy | Quiet |
Sources
Documentation and code
- docs.confluent.io/cloud/current/security/authenticate/workload-identities/service-accounts/api-keys/overview.html
- docs.confluent.io/cloud/current/release-notes/index.html
- docs.confluent.io/cloud/current/security/authenticate/identity-faq.html
Research log
- redact-secret/redact-secret-benchmarks#233Research issue