Skip to content
Benchmarks

redact-secret · Report

Cloud API secret (unprefixed, pre-2025-07-30)

Unprefixed 64-byte base64-body API secret, recognized only beside a same-line confluent keyword.

  • Confluent Cloud
  • Detectors: confluent-cloud-api-secret-legacy
  • Run 2026-10-07
  • Mode published · redact-secret 0.1.0-beta.14
  • Dossier verdictReady
  • Dossier evidence levelT2 · Tool-corroborated
  • Dossier researched2026-09-24
redact-secret#309 (product PR #667). Scored as policy (no value grammar), like twilio:auth-token.

Research record

From credential-evidence snapshot-2026.10.06.4 · records at 77ce761 · schema 1.8.0. It describes the research on the format, not what any scanner or the product does, and not a support status.
  • Review stateDraft, not reviewed
  • Format revision1 · current
  • ResearchResearched
  • Researched2026-09-24

3 events in the review history: 2 observed, 1 reviewed. Latest: observed on 2026-09-24 by automation, project maintainer. Project-maintained review is not independent validation. The family record at this release.

Format

Provider format research from credential-evidence snapshot-2026.10.06.4 · records at 77ce761 · schema 1.8.0.

What it looks like

Shape not recorded.

Format facts

  • Tool corroborated · tool-corroboration · current · observed 2026-09-17

    Pinned scanner rules are consistent with the contract grammar (2 artifacts: gitleaks 8.30.1; trufflehog 3.97.4).

  • Tool corroborated · field-context-gate · current · observed 2026-09-17

    context gate: no value grammar of its own: scored as policy, only beside a same-line confluent keyword

  • Provider documented · field-prefix · current · observed 2026-09-24

    prefix: secrets created before 2025-07-30 "may not include cflt"; the release notes say "do not have" and "on or after" — the cut-over wording differs across three provider pages

  • Provider documented · field-length · current · observed 2026-09-24

    length: 64 characters in every CLI-table placeholder, the Flink JSON example and the provider's Terraform test data; one provider Basic-auth example shows 60 (The 60/64 ambiguity is preserved: positives use 64, and no fixture asserts silence on a 60-character value. The pre-existing 63-character length twin rests on both pinned tools' exact 64-character rules.)

  • Provider documented · field-alphabet · current · observed 2026-09-24

    alphabet: A-Z a-z 0-9 + / with no = padding in any example

  • Unresolved · field-current-issuance-reproducibility · current · observed 2026-09-24

    current-issuance reproducibility: a new key is always the cflt generation, so no new legacy secret can be issued; only an existing pre-cut-over key could corroborate

    • github.com/redact-secret/redact-secret-benchmarks/issues/233provider-documentation · last read 2026-09-24 · latest outcome read · supports current-issuance reproducibility: a new key is always the cflt generation, so no new legacy secret can be issued; only an existing pre-cut-over key could corroborate
  • Unresolved · dossier-research · current · observed 2026-09-24

    Legacy dossier research (verdict ready, tier T2) cited 3 sources; the dossier does not attribute sources to individual properties.

  • Unresolved · taxonomy-sources · current · observed 2026-09-24

    The legacy taxonomy lists 1 source for this family. The taxonomy records no date; the dossier researchedAt is used as the observed-at date.

Open questions

No open question is recorded for this revision.

Benchmark dossier notes

From the provider dossier, as written. The evidence level above says how well the format is backed; a fact the dossier does not record is not shown.
Shape
an unprefixed 64-character run over A-Z a-z 0-9 + /. No checksum is documented. Confluent's CLI-table examples, Flink example and Terraform provider test data show 64; one Connect API Basic-auth example shows 60 (probably a hand-edited placeholder).
Basis
T2. Provider examples and provider test fixtures corroborate length and alphabet; gitleaks ([a-z0-9]{64}, (?i), no + or /) and trufflehog ([a-zA-Z0-9+/]{64}, key and secret pair required) supply the rule shape and the keyword gate. Kingfisher imports the gitleaks lineage and is not independent.
Issuance
not possible; new secrets are prefixed. Cannot be re-observed.
Contract in core
detector-families.md (keyword-gated legacy shape, confidence-gated).

In this benchmark

Fixture rows on the current run. Counts are for redact-secret in published · redact-secret 0.1.0-beta.14 mode.
Fixtures
60
Left readable
0
Redacted too much
0
False alarms
0

60 fixtures: 41 must stay quiet, 19 record project policy. See every row

redact-secret fixture counts by evidence level
Evidence levelFixturesLeft readableToo muchFalse alarms
T2Tool-corroborated18000
T3Project policy42000

Every scanner on the same fixtures

In run order. Counts are what each scanner recorded on this family's fixtures, whichever rules it has; a scanner with no rule for the family has nothing to report on it.

Counts per scanner on this family's fixtures
ScannerFixturesLeft readableToo muchFalse alarms
flare-redactRuntime library · 1.6.1 · Published npm package · secrets-only (pii, generic_assignment disabled) · JavaScript engineNo rule maps to it601810
gitleaksRepository scanner · 8.30.1 · Directory scan · default rules1 rule targets it601102
redact-secretProduct measured here · 0.1.0-beta.14 · Published npm package · default detectors1 detector mapped60000
trufflehogRepository scanner · 3.97.4 · Filesystem scan · verification disabled1 rule targets it601900

Benchmark dossier questions

Things the sources do not settle. They are listed so nobody reads them as settled.
Open caveat
Provider states no length or alphabet for the unprefixed form; 64 comes from doc examples, provider test data and two scanner rules, one doc example shows 60. No legacy secret can be newly issued.

Looks like it, but isn't

Values the dossier records as resembling this credential without being one.
Collisions
any 64-character base64-alphabet run, including a 64-hex digest, so the value is only claimed beside a confluent keyword. A prefixed secret also satisfies this shape. Percent-encoding of + and / inside URL userinfo breaks the run.

Scanner rules for this family

Mapped by hand (reviewed 2026-09-30) from each scanner's pinned rule file, never from what a scanner found on the fixtures.
Peer scanner rules that target this family
ScannerRuleWhat the rule matches
gitleaks · rules 8.30.1confluent-secret-keyconfluent keyword + 64 alphanumerics
trufflehog · rules 3.97.4confluentconfluent keyword + 64 characters

No rule maps to this family in flare-redact, openredaction.

60 of 60 rows

Fixtures in this family

60 rows, redact-secret's outcome on each. Rows that need a look come first (0), then the rest in corpus order. Choose "Every scanner" to see each scanner's outcome for the same rows.
Fixtures in Cloud API secret (unprefixed, pre-2025-07-30)
FixtureKind and evidenceredact-secret
confluent-cloud-api-secret-legacy-actions-envconfluent · documented-format-literalProject policyT3 · Project policyRedacted
confluent-cloud-api-secret-legacy-api-key-id-public-idconfluent · public-identifierMust not flagT2 · Tool-corroboratedQuiet
confluent-cloud-api-secret-legacy-api-key-storeconfluent · documented-format-literalProject policyT3 · Project policyRedacted
confluent-cloud-api-secret-legacy-client-config-createconfluent · documented-format-literalProject policyT3 · Project policyRedacted
confluent-cloud-api-secret-legacy-client-logconfluent · documented-format-literalProject policyT3 · Project policyRedacted
confluent-cloud-api-secret-legacy-compose-jaasconfluent · documented-format-literalProject policyT3 · Project policyRedacted
confluent-cloud-api-secret-legacy-connect-worker-configconfluent · documented-format-literalProject policyT3 · Project policyRedacted
confluent-cloud-api-secret-legacy-envconfluent · documented-format-literalProject policyT3 · Project policyRedacted
confluent-cloud-api-secret-legacy-exportconfluent · documented-format-literalProject policyT3 · Project policyRedacted
confluent-cloud-api-secret-legacy-global-key-id-public-idconfluent · public-identifierMust not flagT2 · Tool-corroboratedQuiet
confluent-cloud-api-secret-legacy-iam-curlconfluent · documented-format-literalProject policyT3 · Project policyRedacted
confluent-cloud-api-secret-legacy-java-client-propertiesconfluent · documented-format-literalProject policyT3 · Project policyRedacted
confluent-cloud-api-secret-legacy-js-constantconfluent · documented-format-literalProject policyT3 · Project policyRedacted
confluent-cloud-api-secret-legacy-k8s-secretconfluent · documented-format-literalProject policyT3 · Project policyRedacted
confluent-cloud-api-secret-legacy-keyword-context-bareconfluent · documented-format-literalProject policyT3 · Project policyRedacted
confluent-cloud-api-secret-legacy-keyword-context-quotedconfluent · documented-format-literalProject policyT3 · Project policyRedacted
confluent-cloud-api-secret-legacy-keyword-context-unicode-crlfconfluent · documented-format-literalProject policyT3 · Project policyRedacted
confluent-cloud-api-secret-legacy-librdkafka-dictconfluent · documented-format-literalProject policyT3 · Project policyRedacted
confluent-cloud-api-secret-legacy-schema-registry-urlconfluent · documented-format-literalProject policyT3 · Project policyRedacted
confluent-cloud-api-secret-legacy-schema-registry-user-infoconfluent · documented-format-literalProject policyT3 · Project policyRedacted
confluent-cloud-api-secret-legacy-tfvarsconfluent · documented-format-literalProject policyT3 · Project policyRedacted
confluent-cloud-api-secret-legacy-actions-context-twinconfluent · missing-context-markerMust not flagT3 · Project policy · twinQuiet
confluent-cloud-api-secret-legacy-actions-secret-referenceconfluent · templated-referenceMust not flagT3 · Project policyQuiet
confluent-cloud-api-secret-legacy-angle-secret-placeholderconfluent · documentation-placeholderMust not flagT3 · Project policyQuiet
confluent-cloud-api-secret-legacy-api-key-list-public-idconfluent · public-identifierMust not flagT2 · Tool-corroboratedQuiet
confluent-cloud-api-secret-legacy-api-key-store-context-twinconfluent · missing-context-markerMust not flagT3 · Project policy · twinQuiet
confluent-cloud-api-secret-legacy-bootstrap-host-public-idconfluent · public-identifierMust not flagT2 · Tool-corroboratedQuiet
confluent-cloud-api-secret-legacy-cflt-asset-url-near-missconfluent · format-near-missMust not flagT2 · Tool-corroboratedQuiet
confluent-cloud-api-secret-legacy-config-provider-referenceconfluent · templated-referenceMust not flagT3 · Project policyQuiet
confluent-cloud-api-secret-legacy-config-provider-reference-templated-referenceconfluent · templated-referenceMust not flagT3 · Project policyQuiet
confluent-cloud-api-secret-legacy-current-generation-tfvars-twinconfluent · prefix-near-missMust not flagT2 · Tool-corroborated · twinQuiet
confluent-cloud-api-secret-legacy-current-generation-twinconfluent · prefix-near-missMust not flagT2 · Tool-corroborated · twinQuiet
confluent-cloud-api-secret-legacy-env-context-twinconfluent · missing-context-markerMust not flagT3 · Project policy · twinQuiet
confluent-cloud-api-secret-legacy-export-context-twinconfluent · missing-context-markerMust not flagT3 · Project policy · twinQuiet
confluent-cloud-api-secret-legacy-iam-curl-context-twinconfluent · missing-context-markerMust not flagT3 · Project policy · twinQuiet
confluent-cloud-api-secret-legacy-image-digest-encoded-valueconfluent · benign-encoded-valueMust not flagT2 · Tool-corroboratedQuiet
confluent-cloud-api-secret-legacy-jaas-template-placeholderconfluent · documentation-placeholderMust not flagT3 · Project policyQuiet
confluent-cloud-api-secret-legacy-js-constant-context-twinconfluent · missing-context-markerMust not flagT3 · Project policy · twinQuiet
confluent-cloud-api-secret-legacy-k8s-secret-context-twinconfluent · missing-context-markerMust not flagT3 · Project policy · twinQuiet
confluent-cloud-api-secret-legacy-key-id-twice-near-missconfluent · format-near-missMust not flagT2 · Tool-corroboratedQuiet
confluent-cloud-api-secret-legacy-keyword-context-bare-twinconfluent · wrong-lengthMust not flagT2 · Tool-corroborated · twinQuiet
confluent-cloud-api-secret-legacy-keyword-context-quoted-twinconfluent · wrong-lengthMust not flagT2 · Tool-corroborated · twinQuiet
confluent-cloud-api-secret-legacy-keyword-context-unicode-crlf-twinconfluent · wrong-lengthMust not flagT2 · Tool-corroborated · twinQuiet
confluent-cloud-api-secret-legacy-label-proseconfluent · benign-lookalikeMust not flagT3 · Project policyQuiet
confluent-cloud-api-secret-legacy-length-63-twinconfluent · wrong-lengthMust not flagT2 · Tool-corroborated · twinQuiet
confluent-cloud-api-secret-legacy-librdkafka-dict-context-twinconfluent · missing-context-markerMust not flagT3 · Project policy · twinQuiet
confluent-cloud-api-secret-legacy-maskconfluent · benign-lookalikeMust not flagT3 · Project policyQuiet
confluent-cloud-api-secret-legacy-masked-table-placeholderconfluent · documentation-placeholderMust not flagT3 · Project policyQuiet
confluent-cloud-api-secret-legacy-missing-keywordconfluent · benign-lookalikeMust not flagT2 · Tool-corroboratedQuiet
confluent-cloud-api-secret-legacy-one-time-note-proseconfluent · prose-mentionMust not flagT3 · Project policyQuiet

Sources

Researched 2026-09-24.

Documentation and code

Other Confluent Cloud families