redact-secret · Report
API key (unprefixed)
40 lowercase hex characters recognised only beside a same-line Deepgram name, host or SDK constructor; sent as Authorization: Token, not Bearer.
Research record
3 events in the review history: 2 observed, 1 reviewed. Latest: observed on 2026-09-27 by automation, project maintainer. Project-maintained review is not independent validation. The family record at this release.
Format
What it looks like
- Descriptive pattern
^[0-9a-f]{40}$
Parts are shown as recorded. Evidence classes belong to the facts below; no class is assigned to a part.
Format facts
Tool corroborated ·
tool-corroboration· current · observed 2026-09-26Pinned scanner rules are consistent with the contract grammar (2 artifacts: betterleaks; trufflehog 3.97.4).
- betterleaks/betterleaks @ main: cmd/generate/config/rules/deepgram.goscanner-rule-source · last read 2026-09-26 · latest outcome read · supports betterleaks: deepgram-api-key: deepgram keyword + [a-f0-9]{40}, entropy filter
- trufflesecurity/trufflehog @ v3.97.4: pkg/detectors/deepgram/deepgram.goscanner-rule-source · last read 2026-09-27 · latest outcome read · supports trufflehog 3.97.4: Deepgram: deepgram keyword + \b([0-9a-z]{40})\b
Tool corroborated ·
field-shape· current · observed 2026-09-26shape: 40 lowercase hexadecimal characters, no prefix (The pinned tool and betterleaks agree on the length; the alphabet is the intersection of two tools.)
- betterleaks/betterleaks @ main: cmd/generate/config/rules/deepgram.goscanner-rule-source · last read 2026-09-26 · latest outcome read · supports shape: 40 lowercase hexadecimal characters, no prefix
- github.com/orgs/deepgram/discussions/577scanner-rule-source · last read 2026-09-26 · latest outcome read · supports a user reports a 40-character working key
- trufflesecurity/trufflehog @ v3.97.4: pkg/detectors/deepgram/deepgram.goscanner-rule-source · last read 2026-09-27 · latest outcome read · supports shape: 40 lowercase hexadecimal characters, no prefix
Unresolved ·
field-alphabet· current · observed 2026-09-26alphabet: hex (betterleaks [a-f0-9]) versus base36 (trufflehog [0-9a-z]) (The tools disagree and no provider source decides it, so no fixture asserts silence on a non-hex letter or on upper case (docs/decisions/2026-09-24-stop-asserting-provider-undecided-format-properties.md).)
- betterleaks/betterleaks @ main: cmd/generate/config/rules/deepgram.goscanner-rule-source · last read 2026-09-26 · latest outcome read · supports alphabet: hex (betterleaks [a-f0-9]) versus base36 (trufflehog [0-9a-z])
- trufflesecurity/trufflehog @ v3.97.4: pkg/detectors/deepgram/deepgram.goscanner-rule-source · last read 2026-09-27 · latest outcome read · supports alphabet: hex (betterleaks [a-f0-9]) versus base36 (trufflehog [0-9a-z])
Unresolved ·
field-docs-example-length· current · observed 2026-09-26docs-example-length: the 32-hex documentation example is a placeholder, not a length statement (Whether keys were ever 32 characters is untested; not claimed.)
- developers.deepgram.com/reference/manage/keys/createprovider-documentation · last read 2026-09-26 · latest outcome read · supports docs-example-length: the 32-hex documentation example is a placeholder, not a length statement
Tool corroborated ·
field-context· current · observed 2026-09-26context: a same-line deepgram name, host or SDK constructor
- betterleaks/betterleaks @ main: cmd/generate/config/rules/deepgram.goscanner-rule-source · last read 2026-09-26 · latest outcome read · supports context: a same-line deepgram name, host or SDK constructor
- trufflesecurity/trufflehog @ v3.97.4: pkg/detectors/deepgram/deepgram.goscanner-rule-source · last read 2026-09-27 · latest outcome read · supports deepgram keyword
Provider documented ·
field-header-scheme· current · observed 2026-09-26header-scheme: Authorization: Token <key> (not Bearer); temporary access tokens are JWTs sent as Bearer
- developers.deepgram.com/guides/fundamentals/authenticatingprovider-documentation · last read 2026-09-27 · latest outcome read · supports header-scheme: Authorization: Token <key> (not Bearer); temporary access tokens are JWTs sent as Bearer
- developers.deepgram.com/reference/auth/tokens/grantprovider-documentation · last read 2026-09-26 · latest outcome read · supports header-scheme: Authorization: Token <key> (not Bearer); temporary access tokens are JWTs sent as Bearer
Provider documented ·
field-transport· current · observed 2026-09-26transport: DEEPGRAM_API_KEY, DeepgramClient(api_key=...), createClient(key)
- github.com/deepgram/deepgram-python-sdkprovider-sdk-source · last read 2026-09-26 · latest outcome read · supports transport: DEEPGRAM_API_KEY, DeepgramClient(api_key=...), createClient(key)
Provider documented ·
field-public-ids· current · observed 2026-09-26public-ids: api_key_id, project ids and dg-request-id values are public identifiers (api_key_id is authored only as a context twin (the value kept, the assignment renamed), never as a benign control.)
- developers.deepgram.com/reference/manage/keys/createprovider-documentation · last read 2026-09-26 · latest outcome read · supports api_key_id and key share one example shape
Unresolved ·
listed-references· current · observed 2026-09-26The legacy contract lists 7 references without stating which property each supports.
- developers.deepgram.com/reference/manage/keys/createprovider-documentation · last read 2026-09-26 · latest outcome read · supports Listed as a reference by the legacy contract
- developers.deepgram.com/guides/fundamentals/authenticatingprovider-documentation · last read 2026-09-27 · latest outcome read · supports Listed as a reference by the legacy contract
- docs.gitguardian.com/secrets-detection/secrets-detection-engine/detectors/specifics/deepgram_api_keyother · last read 2026-09-26 · latest outcome read · supports Listed as a reference by the legacy contract
- github.com/deepgram/deepgram-python-sdkprovider-sdk-source · last read 2026-09-26 · latest outcome read · supports Listed as a reference by the legacy contract
- github.com/orgs/deepgram/discussions/577scanner-rule-source · last read 2026-09-26 · latest outcome read · supports Listed as a reference by the legacy contract
- github.com/redact-secret/redact-secret/issues/868issue-or-discussion · last read 2026-09-26 · latest outcome read · supports Listed as a reference by the legacy contract
- github.com/redact-secret/redact-secret/issues/789issue-or-discussion · last read 2026-09-26 · latest outcome read · supports Listed as a reference by the legacy contract
Tool corroborated ·
dossier-research· current · observed 2026-09-27Legacy dossier research (verdict ready, tier T2) cited 2 sources; the dossier does not attribute sources to individual properties.
- developers.deepgram.com/guides/fundamentals/authenticatingprovider-documentation · last read 2026-09-27 · latest outcome read · supports Cited by the legacy dossier research for this family
- trufflesecurity/trufflehog @ 363923b901c911a9164f50b6c423f47c15372b1c: pkg/detectors/deepgram/deepgram.goother · last read 2026-09-27 · latest outcome read · supports Cited by the legacy dossier research for this family
Tool corroborated ·
taxonomy-sources· current · observed 2026-09-27The legacy taxonomy lists 2 sources for this family. The taxonomy records no date; the dossier researchedAt is used as the observed-at date.
- developers.deepgram.com/guides/fundamentals/authenticatingprovider-documentation · last read 2026-09-27 · latest outcome read · supports Listed as a source for this family in the legacy taxonomy
- trufflesecurity/trufflehog @ v3.97.4: pkg/detectors/deepgram/deepgram.goscanner-rule-source · last read 2026-09-27 · latest outcome read · supports Listed as a source for this family in the legacy taxonomy
Open questions
No open question is recorded for this revision.
Benchmark dossier notes
- Shape
- no prefix; 40 characters, lowercase hexadecimal in the benchmark taxonomy and
[0-9a-z]in core's spec (see Open questions), recognised only beside a same-line Deepgram name, host or SDK constructor. Never a bare 40-character run (a Git SHA-1 has the same shape). Length and alphabet are not provider-stated. - Basis
- T2 at best; #868 records no provider T1. The docs' create-key example shows 32 ascending hex digits for both
keyandapi_key_id, which reads as a placeholder and conflicts with every other source, pointing to 40. trufflehog ([0-9a-z]{40}, keyworddeepgram) and betterleaks ([a-f0-9]{40}, entropy filter; Kingfisher aliases it) agree on length and disagree on alphabet. A GitHub discussion user reports a working 40-character key, and one archived Reddit post held three 40-hex runs. GitGuardian says "Prefixed: No" with no length. gitleaks, noseyparker, secretlint and osv-scalibr have no rule. - Issuance
- not attempted. The #789 checklist records total length (32 versus 40), charset class, a second key, the shape of the visible key id, an expiring or temporary key, and the grant JWT structure.
- Contract in core
- detector-families.md, section Keyword-gated provider keys (#868). The spec keeps
[0-9a-z]{40}, the wider of the two tools. #932 recognised the HTTPieAuthorization:Tokenand Godeepgram.NewRESTWithDefaultsforms, and #936 made theTokenheader high confidence when the line names a Deepgram API host.
In this benchmark
- Fixtures
- 82
- Left readable
- 0
- Redacted too much
- 0
- False alarms
- 0
82 fixtures: 53 must stay quiet, 29 record project policy. See every row
| Evidence level | Fixtures | Left readable | Too much | False alarms |
|---|---|---|---|---|
| T2Tool-corroborated | 20 | 0 | 0 | 0 |
| T3Project policy | 61 | 0 | 0 | 0 |
| T0Pending review | 1 | 0 | 0 | 0 |
Every scanner on the same fixtures
In run order. Counts are what each scanner recorded on this family's fixtures, whichever rules it has; a scanner with no rule for the family has nothing to report on it.
| Scanner | Fixtures | Left readable | Too much | False alarms |
|---|---|---|---|---|
| flare-redactRuntime library · 1.6.1 · Published npm package · secrets-only (pii, generic_assignment disabled) · JavaScript engineNo rule maps to it | 82 | 29 | 0 | 0 |
| gitleaksRepository scanner · 8.30.1 · Directory scan · default rulesNo rule maps to it | 82 | 6 | 0 | 1 |
| redact-secretProduct measured here · 0.1.0-beta.14 · Published npm package · default detectors1 detector mapped | 82 | 0 | 0 | 0 |
| trufflehogRepository scanner · 3.97.4 · Filesystem scan · verification disabled1 rule targets it | 82 | 5 | 0 | 6 |
Benchmark dossier questions
- Open caveat
- No provider source states length or alphabet; the docs example is a 32-hex placeholder that contradicts the observed 40. Hex versus base36 is disputed between tools. Needs one issued key (checklist in #789).
Looks like it, but isn't
- Collisions
api_key_iduses the same example shape askey, so a stored key id is a lookalike. Project ids and request ids are UUIDs. The grantaccess_tokenis a JWT, a different credential.
Scanner rules for this family
| Scanner | Rule | What the rule matches |
|---|---|---|
| trufflehog · rules 3.97.4 | deepgram | deepgram keyword + 40 alphanumerics |
No rule maps to this family in flare-redact, gitleaks, openredaction.
Fixtures in this family
| Fixture | Kind and evidence | redact-secret |
|---|---|---|
deepgram-api-key-actions-env-literaldeepgram · documented-format-literal | Project policyT3 · Project policy | Redacted |
deepgram-api-key-agent-stt-yamldeepgram · documented-format-literal | Project policyT3 · Project policy | Redacted |
deepgram-api-key-auth-failure-logdeepgram · documented-format-literal | Project policyT3 · Project policy | Redacted |
deepgram-api-key-compose-envdeepgram · documented-format-literal | Project policyT3 · Project policy | Redacted |
deepgram-api-key-create-clientdeepgram · documented-format-literal | Project policyT3 · Project policy | Redacted |
deepgram-api-key-curl-headerdeepgram · documented-format-literal | Project policyT3 · Project policy | Redacted |
deepgram-api-key-docker-run-envdeepgram · documented-format-literal | Project policyT3 · Project policy | Redacted |
deepgram-api-key-docker-run-env-documented-format-literaldeepgram · documented-format-literal | Project policyT3 · Project policy | Redacted |
deepgram-api-key-dotenvdeepgram · documented-format-literal | Project policyT3 · Project policy | Redacted |
deepgram-api-key-dotenv-altdeepgram · documented-format-literal | Project policyT3 · Project policy | Redacted |
deepgram-api-key-exportdeepgram · documented-format-literal | Project policyT3 · Project policy | Redacted |
deepgram-api-key-gitlab-ci-variablesdeepgram · documented-format-literal | Project policyT3 · Project policy | Redacted |
deepgram-api-key-go-client-literaldeepgram · documented-format-literal | Project policyT3 · Project policy | Redacted |
deepgram-api-key-http-request-headerdeepgram · documented-format-literal | Project policyT3 · Project policy | Redacted |
deepgram-api-key-httpie-tokendeepgram · documented-format-literal | Project policyT3 · Project policy | Redacted |
deepgram-api-key-id-named-compose-twindeepgram · missing-context-marker | Must not flagT3 · Project policy · twin | Quiet |
deepgram-api-key-id-named-env-twindeepgram · missing-context-marker | Must not flagT3 · Project policy · twin | Quiet |
deepgram-api-key-id-named-export-twindeepgram · missing-context-marker | Must not flagT3 · Project policy · twin | Quiet |
deepgram-api-key-id-named-tool-call-twindeepgram · missing-context-marker | Must not flagT3 · Project policy · twin | Quiet |
deepgram-api-key-inline-env-commanddeepgram · documented-format-literal | Project policyT3 · Project policy | Redacted |
deepgram-api-key-json-header-tokendeepgram · documented-format-literal | Project policyT3 · Project policy | Redacted |
deepgram-api-key-k8s-env-valuedeepgram · documented-format-literal | Project policyT3 · Project policy | Redacted |
deepgram-api-key-key-shape-baredeepgram · documented-format-literal | Project policyT3 · Project policy | Redacted |
deepgram-api-key-key-shape-quoteddeepgram · documented-format-literal | Project policyT3 · Project policy | Redacted |
deepgram-api-key-key-shape-unicode-crlfdeepgram · documented-format-literal | Project policyT3 · Project policy | Redacted |
deepgram-api-key-model-revision-field-twindeepgram · missing-context-marker | Must not flagT3 · Project policy · twin | Quiet |
deepgram-api-key-other-host-curl-twindeepgram · missing-context-marker | Must not flagT3 · Project policy · twin | Quiet |
deepgram-api-key-printenv-outputdeepgram · documented-format-literal | Project policyT3 · Project policy | Redacted |
deepgram-api-key-proxy-logdeepgram · documented-format-literal | Project policyT3 · Project policy | Redacted |
deepgram-api-key-python-ctordeepgram · documented-format-literal | Project policyT3 · Project policy | Redacted |
deepgram-api-key-toml-config-keydeepgram · documented-format-literal | Project policyT3 · Project policy | Redacted |
deepgram-api-key-tool-calldeepgram · documented-format-literal | Project policyT3 · Project policy | Redacted |
deepgram-api-key-ts-ctordeepgram · documented-format-literal | Project policyT3 · Project policy | Redacted |
deepgram-api-key-unrelated-python-ctor-twindeepgram · missing-context-marker | Must not flagT3 · Project policy · twin | Quiet |
deepgram-api-key-websocket-subprotocoldeepgram · documented-format-literal | Project policyT3 · Project policy | Redacted |
deepgram-api-key-worker-json-logdeepgram · documented-format-literal | Project policyT3 · Project policy | Redacted |
sdk-bump-commit-lineauthored-prefixless-key-shape-discrimination · git-object-name-on-a-line-naming-a-provider | Pending reviewT0 · Pending | Unscored |
deepgram-api-key-actions-secret-expression-placeholderdeepgram · documentation-placeholder | Must not flagT3 · Project policy | Quiet |
deepgram-api-key-actions-secret-referencedeepgram · templated-reference | Must not flagT3 · Project policy | Quiet |
deepgram-api-key-angle-key-placeholderdeepgram · documentation-placeholder | Must not flagT3 · Project policy | Quiet |
deepgram-api-key-assemblyai-keyword-twindeepgram · missing-context-marker | Must not flagT3 · Project policy · twin | Quiet |
deepgram-api-key-bare-in-prose-near-missdeepgram · format-near-miss | Must not flagT2 · Tool-corroborated | Quiet |
deepgram-api-key-bare-line-near-missdeepgram · format-near-miss | Must not flagT2 · Tool-corroborated | Quiet |
deepgram-api-key-base64-text-encoded-valuedeepgram · benign-encoded-value | Must not flagT2 · Tool-corroborated | Quiet |
deepgram-api-key-bearer-scheme-twindeepgram · missing-context-marker | Must not flagT3 · Project policy · twin | Quiet |
deepgram-api-key-data-uri-encoded-valuedeepgram · benign-encoded-value | Must not flagT2 · Tool-corroborated | Quiet |
deepgram-api-key-docs-ctor-placeholderdeepgram · documentation-placeholder | Must not flagT3 · Project policy | Quiet |
deepgram-api-key-embedded-run-near-missdeepgram · format-near-miss | Must not flagT2 · Tool-corroborated | Quiet |
deepgram-api-key-env-reference-referencedeepgram · templated-reference | Must not flagT3 · Project policy | Quiet |
deepgram-api-key-id-named-env-alt-twindeepgram · missing-context-marker | Must not flagT3 · Project policy · twin | Quiet |
Sources
Documentation and code
- developers.deepgram.com/guides/fundamentals/authenticating
- github.com/trufflesecurity/trufflehog/blob/v3.97.4/pkg/detectors/deepgram/deepgram.go
- github.com/trufflesecurity/trufflehog/blob/363923b901c911a9164f50b6c423f47c15372b1c/pkg/detectors/deepgram/deepgram.go
Research log
- redact-secret/redact-secret#789Research issue
- redact-secret/redact-secret#774Research issue
- redact-secret/redact-secret#868Research issue
- redact-secret/redact-secret#932Research issue
- redact-secret/redact-secret#936Research issue
- redact-secret/redact-secret-benchmarks#384Research issue