Skip to content
Benchmarks

redact-secret · Report

API key (dtn_)

dtn_ + exactly 64 lowercase hex, T1 as of v0.190.0 (2026-06-23) under ruling R9; the same generator mints region proxy, SSH-gateway and runner keys, which are lexically identical.

  • Daytona
  • Detectors: daytona-api-key
  • Run 2026-10-07
  • Mode published · redact-secret 0.1.0-beta.14
  • Dossier verdictReady
  • Dossier evidence levelT1 · Provider-documented
  • Dossier researched2026-09-28
Beta.12 arrival family daytona-api-key (#464, product redact-secret#970), contract in benchmarks/lib/beta8/464a.ts from the #860 handoff daytona.md. T1 as of v0.190.0 (R9, dated provider code); provider code went private after that release. Neither pinned scanner has a Daytona rule. Since the 4fb7882 re-pin the product detector is in the pinned registry, so the row maps to it.

Research record

From credential-evidence snapshot-2026.10.06.4 · records at 77ce761 · schema 1.8.0. It describes the research on the format, not what any scanner or the product does, and not a support status.
  • Review stateDraft, not reviewed
  • Format revision1 · current
  • ResearchResearched
  • Researched2026-09-28

3 events in the review history: 2 observed, 1 reviewed. Latest: observed on 2026-09-28 by automation, project maintainer. Project-maintained review is not independent validation. The family record at this release.

Format

Provider format research from credential-evidence snapshot-2026.10.06.4 · records at 77ce761 · schema 1.8.0.

What it looks like

Descriptive pattern
^dtn_[0-9a-f]{64}$

Parts are shown as recorded. Evidence classes belong to the facts below; no class is assigned to a part.

Format facts

Open questions

No open question is recorded for this revision.

Benchmark dossier notes

From the provider dossier, as written. The evidence level above says how well the format is backed; a fact the dossier does not record is not shown.
Shape
prefix dtn_, then exactly 64 lowercase hex characters (68 in total); no separator or checksum.
Basis
prefix and body T1 under ruling R1 and R9: the provider generator returns dtn_ + 32 random bytes hex-encoded (public up to v0.190.0, 2026-06-23; the same inline form since 2025-04-28). Core development moved to a private codebase in June 2026, so the contract is dated. Every later public source (daytona/clients OpenAPI and CLI, helm-charts scripts, SDK 0.218.0, docs dump) is prefix-only and none contradicts it.
Issuance
not attempted; R9 accepts the dated generator as T1 until a newer provider source contradicts it. An issuance check is optional confirmation.
Contract in core
detector-families.md (no row until the Beta.12 detector, redact-secret#970, is merged).

In this benchmark

Fixture rows on the current run. Counts are for redact-secret in published · redact-secret 0.1.0-beta.14 mode.
Fixtures
44
Left readable
0
Redacted too much
0
False alarms
0

44 fixtures: 19 expect a redaction, 25 must stay quiet. See every row

redact-secret fixture counts by evidence level
Evidence levelFixturesLeft readableToo muchFalse alarms
T1Provider-documented19000
T2Tool-corroborated16000
T3Project policy9000

Every scanner on the same fixtures

In run order. Counts are what each scanner recorded on this family's fixtures, whichever rules it has; a scanner with no rule for the family has nothing to report on it.

Counts per scanner on this family's fixtures
ScannerFixturesLeft readableToo muchFalse alarms
flare-redactRuntime library · 1.6.1 · Published npm package · secrets-only (pii, generic_assignment disabled) · JavaScript engineNo rule maps to it441720
gitleaksRepository scanner · 8.30.1 · Directory scan · default rulesNo rule maps to it44603
redact-secretProduct measured here · 0.1.0-beta.14 · Published npm package · default detectors1 detector mapped44000
trufflehogRepository scanner · 3.97.4 · Filesystem scan · verification disabledNo rule maps to it441900

Benchmark dossier questions

Things the sources do not settle. They are listed so nobody reads them as settled.
Open caveat
T1 only as of v0.190.0 (2026-06-23); a post-release format change is an accepted false negative.

Looks like it, but isn't

Values the dossier records as resembling this credential without being one.
Collisions
without the prefix the body is SHA-256 hex (including Daytona's own stored key hash), so the prefix is load-bearing. dtn_secret_<random> Secrets placeholders and dtn_artifact_ markers are not credentials.

Scanner rules for this family

Mapped by hand (reviewed 2026-09-30) from each scanner's pinned rule file, never from what a scanner found on the fixtures.

No peer rule maps to this family

None of the reviewed peer scanners has a rule that can match a credential of this family.

None mapped

44 of 44 rows

Fixtures in this family

44 rows, redact-secret's outcome on each. Rows that need a look come first (0), then the rest in corpus order. Choose "Every scanner" to see each scanner's outcome for the same rows.
Fixtures in API key (dtn_)
FixtureKind and evidenceredact-secret
daytona-api-key-actions-envdaytona · documented-format-literalMust redactT1 · Provider-documentedRedacted
daytona-api-key-bare-prosedaytona · documented-format-literalMust redactT1 · Provider-documentedRedacted
daytona-api-key-bearer-headerdaytona · documented-format-literalMust redactT1 · Provider-documentedRedacted
daytona-api-key-chat-pastedaytona · documented-format-literalMust redactT1 · Provider-documentedRedacted
daytona-api-key-compose-envdaytona · documented-format-literalMust redactT1 · Provider-documentedRedacted
daytona-api-key-curl-bearerdaytona · documented-format-literalMust redactT1 · Provider-documentedRedacted
daytona-api-key-dotenvdaytona · documented-format-literalMust redactT1 · Provider-documentedRedacted
daytona-api-key-exportdaytona · documented-format-literalMust redactT1 · Provider-documentedRedacted
daytona-api-key-json-api-keydaytona · documented-format-literalMust redactT1 · Provider-documentedRedacted
daytona-api-key-json-tokendaytona · documented-format-literalMust redactT1 · Provider-documentedRedacted
daytona-api-key-key-shape-baredaytona · documented-format-literalMust redactT1 · Provider-documentedRedacted
daytona-api-key-key-shape-quoteddaytona · documented-format-literalMust redactT1 · Provider-documentedRedacted
daytona-api-key-key-shape-unicode-crlfdaytona · documented-format-literalMust redactT1 · Provider-documentedRedacted
daytona-api-key-openapi-example-placeholderdaytona · documentation-placeholderMust not flagT3 · Project policyQuiet
daytona-api-key-python-configdaytona · documented-format-literalMust redactT1 · Provider-documentedRedacted
daytona-api-key-sandbox-logdaytona · documented-format-literalMust redactT1 · Provider-documentedRedacted
daytona-api-key-sdk-kwargdaytona · documented-format-literalMust redactT1 · Provider-documentedRedacted
daytona-api-key-secret-then-hex-near-missdaytona · format-near-missMust not flagT2 · Tool-corroboratedQuiet
daytona-api-key-terraform-variabledaytona · documented-format-literalMust redactT1 · Provider-documentedRedacted
daytona-api-key-trailing-underscore-twindaytona · boundary-violationMust not flagT2 · Tool-corroborated · twinQuiet
daytona-api-key-ts-clientdaytona · documented-format-literalMust redactT1 · Provider-documentedRedacted
daytona-api-key-x-api-key-headerdaytona · documented-format-literalMust redactT1 · Provider-documentedRedacted
daytona-api-key-actions-secret-referencedaytona · templated-referenceMust not flagT3 · Project policyQuiet
daytona-api-key-artifact-marker-near-missdaytona · format-near-missMust not flagT2 · Tool-corroboratedQuiet
daytona-api-key-bare-sha256-encoded-valuedaytona · benign-encoded-valueMust not flagT2 · Tool-corroboratedQuiet
daytona-api-key-body-63-twindaytona · wrong-lengthMust not flagT2 · Tool-corroborated · twinQuiet
daytona-api-key-body-65-twindaytona · wrong-lengthMust not flagT2 · Tool-corroborated · twinQuiet
daytona-api-key-ellipsis-placeholderdaytona · documentation-placeholderMust not flagT3 · Project policyQuiet
daytona-api-key-env-reference-referencedaytona · templated-referenceMust not flagT3 · Project policyQuiet
daytona-api-key-hyphen-separator-twindaytona · boundary-violationMust not flagT2 · Tool-corroborated · twinQuiet
daytona-api-key-key-guidance-prosedaytona · prose-mentionMust not flagT3 · Project policyQuiet
daytona-api-key-label-prosedaytona · benign-lookalikeMust not flagT3 · Project policyQuiet
daytona-api-key-leading-glue-twindaytona · boundary-violationMust not flagT2 · Tool-corroborated · twinQuiet
daytona-api-key-leading-underscore-twindaytona · boundary-violationMust not flagT2 · Tool-corroborated · twinQuiet
daytona-api-key-maskdaytona · benign-lookalikeMust not flagT3 · Project policyQuiet
daytona-api-key-masked-placeholderdaytona · documentation-placeholderMust not flagT3 · Project policyQuiet
daytona-api-key-non-hex-letter-twindaytona · wrong-alphabetMust not flagT2 · Tool-corroborated · twinQuiet
daytona-api-key-prefix-onlydaytona · benign-lookalikeMust not flagT2 · Tool-corroboratedQuiet
daytona-api-key-referencedaytona · benign-lookalikeMust not flagT3 · Project policyQuiet
daytona-api-key-secret-placeholder-near-missdaytona · format-near-missMust not flagT2 · Tool-corroboratedQuiet
daytona-api-key-short-bodydaytona · benign-lookalikeMust not flagT2 · Tool-corroboratedQuiet
daytona-api-key-trailing-hyphen-twindaytona · boundary-violationMust not flagT2 · Tool-corroborated · twinQuiet
daytona-api-key-uppercase-hex-byte-twindaytona · wrong-alphabetMust not flagT2 · Tool-corroborated · twinQuiet
daytona-api-key-uppercase-prefix-twindaytona · prefix-near-missMust not flagT2 · Tool-corroborated · twinQuiet

Sources

Researched 2026-09-28.

Documentation and code

  • github.com/daytonaio/daytona/blob/01c502bb1f1ff8f2885d0cd490e043736083dca8/apps/api/src/common/utils/api-key.ts#L8-L18
  • github.com/redact-secret/redact-secret/blob/8b6a5fde52ecb4dfce13f09c7a947062d21483c7/docs/audits/evidence/860/daytona.md
  • github.com/redact-secret/redact-secret/blob/8b6a5fde52ecb4dfce13f09c7a947062d21483c7/docs/audits/evidence/860/issuance-research/daytona.md

Research log