redact-secret · Report
Cloud API secret (cflt-prefixed)
API secret created after 2025-07-30: literal cflt prefix, then 54 base64-alphabet body bytes and a 6-byte checksum (standard Base64 of the little-endian CRC32 of those 54 bytes), 64 in total.
Research record
3 events in the review history: 2 observed, 1 reviewed. Latest: observed on 2026-09-24 by automation, project maintainer. Project-maintained review is not independent validation. The family record at this release.
Format
What it looks like
- Descriptive pattern
^cflt[A-Za-z0-9+/]{60}$
Parts are shown as recorded. Evidence classes belong to the facts below; no class is assigned to a part.
Format facts
Provider documented ·
provider-source· current · observed 2026-09-23cflt-prefixed API secret (created after 2025-07-30): the page states "API secrets created after July 30, 2025 have a cflt prefix followed by 60 characters consisting of A-Z, a-z, 0-9, + or /" and that "the final 6 characters contain a Base64-encoded CRC32 checksum of the prior 54 characters"; its own secret-detection snippet fixes the algorithm (CRC32 over the 54 characters after cflt, little-endian bytes, standard Base64, first 6 characters), so the checksum is recomputable and `validate` enforces it (#209, research #234)
- docs.confluent.io/cloud/current/security/authenticate/workload-identities/service-accounts/api-keys/overview.htmlprovider-documentation · last read 2026-09-24 · latest outcome read · supports the page states "API secrets created after July 30, 2025 have a cflt prefix followed by 60 characters consisting of A-Z, a-z, 0-9, + or /" and that "the final 6 characters contain a Base64-encoded CRC32 checksum of the prior 54 characters"; its own secret-detection snippet fixes the algorithm (CRC32 over the 54 characters after cflt, little-endian bytes, standard Base64, first 6 characters), so the checksum is recomputable and `validate` enforces it (#209, research #234)
Tool corroborated ·
tool-corroboration· current · observed 2026-09-23Pinned scanner rules are consistent with the contract grammar (2 artifacts: gitleaks 8.30.1; trufflehog 3.97.4).
- gitleaks/gitleaks @ v8.30.1: config/gitleaks.tomlscanner-rule-source · last read 2026-10-04 · latest outcome read · supports gitleaks 8.30.1: gitleaks.toml
- trufflesecurity/trufflehog @ v3.97.4: pkg/detectors/confluent/confluent.goscanner-rule-source · last read 2026-09-23 · latest outcome read · supports trufflehog 3.97.4: confluent/confluent
Provider documented ·
field-prefix· current · observed 2026-09-24prefix: cflt
- docs.confluent.io/cloud/current/security/authenticate/workload-identities/service-accounts/api-keys/overview.htmlprovider-documentation · last read 2026-09-24 · latest outcome read · supports prefix: cflt
Provider documented ·
field-total-length· current · observed 2026-09-24total-length: 64 characters: cflt plus 60
- docs.confluent.io/cloud/current/security/authenticate/workload-identities/service-accounts/api-keys/overview.htmlprovider-documentation · last read 2026-09-24 · latest outcome read · supports total-length: 64 characters: cflt plus 60
Provider documented ·
field-alphabet· current · observed 2026-09-24alphabet: [A-Za-z0-9+/] after the prefix
- docs.confluent.io/cloud/current/security/authenticate/workload-identities/service-accounts/api-keys/overview.htmlprovider-documentation · last read 2026-09-24 · latest outcome read · supports "A-Z, a-z, 0-9, + or /"
Provider documented ·
field-checksum· current · observed 2026-09-24checksum: the final 6 characters are a Base64-encoded CRC32 of the 54 characters before them
- docs.confluent.io/cloud/current/security/authenticate/workload-identities/service-accounts/api-keys/overview.htmlprovider-documentation · last read 2026-09-24 · latest outcome read · supports checksum: the final 6 characters are a Base64-encoded CRC32 of the 54 characters before them
Provider documented ·
field-checksum-algorithm· current · observed 2026-09-24checksum-algorithm: CRC32 over the 54 body characters after cflt (prefix excluded), 4 bytes little-endian, standard Base64, first 6 characters (Published as code on the provider's documentation page, so it is recorded as provider code, not prose. Corrects the earlier claim that the checksum could not be recomputed.)
- docs.confluent.io/cloud/current/security/authenticate/workload-identities/service-accounts/api-keys/overview.htmlprovider-documentation · last read 2026-09-24 · latest outcome read · supports the page's own secret-detection snippet
- github.com/redact-secret/redact-secret-benchmarks/issues/234provider-sdk-source · last read 2026-09-24 · latest outcome read · supports the page's example validates little-endian and fails big-endian or prefix-included
Unresolved ·
field-final-character· current · observed 2026-09-24final-character: one of A, Q, g, w (6 Base64 characters carry 36 bits for 32 CRC bits) (Derived from the published algorithm; not separately fixtured.)
- github.com/redact-secret/redact-secret-benchmarks/issues/234provider-sdk-source · last read 2026-09-24 · latest outcome read · supports final-character: one of A, Q, g, w (6 Base64 characters carry 36 bits for 32 CRC bits)
Unresolved ·
field-generation-boundary· current · observed 2026-09-24generation-boundary: cflt secrets are those created after (or on and after) 2025-07-30 (Wording drift between the two pages; a drift note, not a blocker.)
- docs.confluent.io/cloud/current/security/authenticate/workload-identities/service-accounts/api-keys/overview.htmlprovider-documentation · last read 2026-09-24 · latest outcome read · supports "after July 30, 2025"
- docs.confluent.io/cloud/current/release-notes/index.htmlprovider-documentation · last read 2026-09-24 · latest outcome read · supports "on or after July 30, 2025"
Provider documented ·
field-key-id· current · observed 2026-09-24key-id: the 16-character API key ID is "not considered secret information" (Backs the public-id controls.)
- docs.confluent.io/cloud/current/security/authenticate/workload-identities/service-accounts/api-keys/overview.htmlprovider-documentation · last read 2026-09-24 · latest outcome read · supports key-id: the 16-character API key ID is "not considered secret information"
Unresolved ·
field-scope-coverage· current · observed 2026-09-24scope-coverage: every API-key scope (cloud, Kafka, Schema Registry, ksqlDB, Flink, Tableflow, global) issues cflt secrets
- github.com/redact-secret/redact-secret-benchmarks/issues/234provider-sdk-source · last read 2026-09-24 · latest outcome read · supports scope-coverage: every API-key scope (cloud, Kafka, Schema Registry, ksqlDB, Flink, Tableflow, global) issues cflt secrets
Provider documented ·
dossier-research· current · observed 2026-09-24Legacy dossier research (verdict ready, tier T1) cited 3 sources; the dossier does not attribute sources to individual properties.
- docs.confluent.io/cloud/current/security/authenticate/workload-identities/service-accounts/api-keys/overview.htmlprovider-documentation · last read 2026-09-24 · latest outcome read · supports Cited by the legacy dossier research for this family
- docs.confluent.io/cloud/current/security/authenticate/identity-faq.htmlprovider-documentation · last read 2026-09-24 · latest outcome read · supports Cited by the legacy dossier research for this family
- docs.confluent.io/cloud/current/release-notes/index.htmlprovider-documentation · last read 2026-09-24 · latest outcome read · supports Cited by the legacy dossier research for this family
Provider documented ·
taxonomy-sources· current · observed 2026-09-24The legacy taxonomy lists 1 source for this family. The taxonomy records no date; the dossier researchedAt is used as the observed-at date.
- docs.confluent.io/cloud/current/security/authenticate/workload-identities/service-accounts/api-keys/overview.htmlprovider-documentation · last read 2026-09-24 · latest outcome read · supports Listed as a source for this family in the legacy taxonomy
Open questions
No open question is recorded for this revision.
Benchmark dossier notes
- Shape
- literal
cflt, then 60 characters fromA-Z a-z 0-9 + /(64 in all). The final 6 characters are a Base64-encoded CRC-32 checksum of the 54 body characters before them. The provider's own detection snippet fixes the recipe: CRC-32 over the 54 body characters excluding the prefix, little-endian bytes, standard Base64, first 6 characters. The #234 pass recomputed the documented example this way and found big-endian or prefix-included variants fail it. Six Base64 characters carry 36 bits and the CRC is 32, so the last character can take only four values (derived by the #234 pass, unchecked against an issued secret). - Basis
- T1: the overview page (prefix, length, alphabet, checksum and snippet). The boundary day is worded three ways ("after", "on or after", "starting") across the page, the release notes and the identity FAQ, and older secrets are said to "may not" carry the prefix on one page and "do not" on another. Kingfisher has a checksum-validating rule; gitleaks and trufflehog match 64 characters with no
cfltor checksum handling. - Issuance
- Cloud API keys created from the Console or CLI. Not attempted.
- Contract in core
- detector-families.md (evidence-backed table: T1 on prefix, body and checksum, #738).
In this benchmark
- Fixtures
- 31
- Left readable
- 0
- Redacted too much
- 0
- False alarms
- 0
31 fixtures: 13 expect a redaction, 18 must stay quiet. See every row
| Evidence level | Fixtures | Left readable | Too much | False alarms |
|---|---|---|---|---|
| T1Provider-documented | 13 | 0 | 0 | 0 |
| T2Tool-corroborated | 14 | 0 | 0 | 0 |
| T3Project policy | 4 | 0 | 0 | 0 |
Every scanner on the same fixtures
In run order. Counts are what each scanner recorded on this family's fixtures, whichever rules it has; a scanner with no rule for the family has nothing to report on it.
| Scanner | Fixtures | Left readable | Too much | False alarms |
|---|---|---|---|---|
| flare-redactRuntime library · 1.6.1 · Published npm package · secrets-only (pii, generic_assignment disabled) · JavaScript engineNo rule maps to it | 31 | 13 | 0 | 0 |
| gitleaksRepository scanner · 8.30.1 · Directory scan · default rulesNo rule maps to it | 31 | 4 | 1 | 2 |
| redact-secretProduct measured here · 0.1.0-beta.14 · Published npm package · default detectors1 detector mapped | 31 | 0 | 0 | 0 |
| trufflehogRepository scanner · 3.97.4 · Filesystem scan · verification disabledNo rule maps to it | 31 | 13 | 0 | 1 |
Benchmark dossier questions
- Open caveat
- The checksum recipe is recomputed from the provider's own snippet, not yet checked against a freshly issued secret; every scope is assumed to issue the same shape.
Looks like it, but isn't
- Collisions
- the 16-character key id (public), resource ids (
lkc-,lsrc-,env-,sa-), the SCIM tokencflt-scim_<JWT>, and the NASDAQ ticker in prose. The legacy 64-character shape overlaps this family's alphabet and length.
Scanner rules for this family
No peer rule maps to this family
None of the reviewed peer scanners has a rule that can match a credential of this family.
None mapped
Fixtures in this family
| Fixture | Kind and evidence | redact-secret |
|---|---|---|
confluent-cloud-api-secret-cli-api-key-create-jsonconfluent · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
confluent-cloud-api-secret-confluent-api-key-storeconfluent · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
confluent-cloud-api-secret-curl-basic-authconfluent · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
confluent-cloud-api-secret-env-cloud-secretconfluent · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
confluent-cloud-api-secret-env-cloud-secret-checksum-twinconfluent · invalid-checksum | Must not flagT2 · Tool-corroborated · twin | Quiet |
confluent-cloud-api-secret-github-actions-connector-deployconfluent · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
confluent-cloud-api-secret-k8s-secret-stringdataconfluent · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
confluent-cloud-api-secret-kafka-client-propertiesconfluent · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
confluent-cloud-api-secret-prefixed-shape-bareconfluent · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
confluent-cloud-api-secret-prefixed-shape-quotedconfluent · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
confluent-cloud-api-secret-prefixed-shape-unicode-crlfconfluent · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
confluent-cloud-api-secret-public-idconfluent · benign-lookalike | Must not flagT2 · Tool-corroborated | Quiet |
confluent-cloud-api-secret-python-producer-configconfluent · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
confluent-cloud-api-secret-secrets-manager-jsonconfluent · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
confluent-cloud-api-secret-shell-export-secretconfluent · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
confluent-cloud-api-secret-cli-api-key-create-json-checksum-prefix-included-twinconfluent · invalid-checksum | Must not flagT2 · Tool-corroborated · twin | Quiet |
confluent-cloud-api-secret-kafka-client-properties-checksum-byte-order-twinconfluent · invalid-checksum | Must not flagT2 · Tool-corroborated · twin | Quiet |
confluent-cloud-api-secret-label-proseconfluent · benign-lookalike | Must not flagT3 · Project policy | Quiet |
confluent-cloud-api-secret-maskconfluent · benign-lookalike | Must not flagT3 · Project policy | Quiet |
confluent-cloud-api-secret-prefix-onlyconfluent · benign-lookalike | Must not flagT2 · Tool-corroborated | Quiet |
confluent-cloud-api-secret-prefixed-shape-bare-twinconfluent · wrong-length | Must not flagT2 · Tool-corroborated · twin | Quiet |
confluent-cloud-api-secret-prefixed-shape-prefix-bare-twinconfluent · prefix-near-miss | Must not flagT2 · Tool-corroborated · twin | Quiet |
confluent-cloud-api-secret-prefixed-shape-prefix-quoted-twinconfluent · prefix-near-miss | Must not flagT2 · Tool-corroborated · twin | Quiet |
confluent-cloud-api-secret-prefixed-shape-prefix-unicode-crlf-twinconfluent · prefix-near-miss | Must not flagT2 · Tool-corroborated · twin | Quiet |
confluent-cloud-api-secret-prefixed-shape-quoted-twinconfluent · wrong-length | Must not flagT2 · Tool-corroborated · twin | Quiet |
confluent-cloud-api-secret-prefixed-shape-unicode-crlf-twinconfluent · wrong-length | Must not flagT2 · Tool-corroborated · twin | Quiet |
confluent-cloud-api-secret-referenceconfluent · benign-lookalike | Must not flagT3 · Project policy | Quiet |
confluent-cloud-api-secret-sasl-username-only-public-idconfluent · public-identifier | Must not flagT2 · Tool-corroborated | Quiet |
confluent-cloud-api-secret-secrets-manager-json-alphabet-twinconfluent · wrong-alphabet | Must not flagT2 · Tool-corroborated · twin | Quiet |
confluent-cloud-api-secret-short-bodyconfluent · benign-lookalike | Must not flagT2 · Tool-corroborated | Quiet |
confluent-cloud-api-secret-ticker-note-proseconfluent · prose-mention | Must not flagT3 · Project policy | Quiet |
Sources
Documentation and code
- docs.confluent.io/cloud/current/security/authenticate/workload-identities/service-accounts/api-keys/overview.html
- docs.confluent.io/cloud/current/release-notes/index.html
- docs.confluent.io/cloud/current/security/authenticate/identity-faq.html
Research log
- redact-secret/redact-secret-benchmarks#234Research issue
- redact-secret/redact-secret#738Research issue