Skip to content
Benchmarks

redact-secret · Report

Bot token

Three-segment base64url bot token.

  • Discord
  • Detectors: discord-bot-token
  • Run 2026-10-07
  • Mode published · redact-secret 0.1.0-beta.14
  • Dossier verdictReady
  • Dossier evidence levelT2 · Tool-corroborated
  • Dossier researched2026-09-24

Research record

From credential-evidence snapshot-2026.10.06.4 · records at 77ce761 · schema 1.8.0. It describes the research on the format, not what any scanner or the product does, and not a support status.
  • Review stateDraft, not reviewed
  • Format revision1 · current
  • ResearchResearched
  • Researched2026-09-24

3 events in the review history: 1 authored, 1 observed, 1 reviewed. Latest: authored on 2026-10-03 by automation, project maintainer. Project-maintained review is not independent validation. The family record at this release.

Format

Provider format research from credential-evidence snapshot-2026.10.06.4 · records at 77ce761 · schema 1.8.0.

What it looks like

Descriptive pattern
^(?:[A-Za-z0-9_-]{24}\.[A-Za-z0-9_-]{6}\.[A-Za-z0-9_-]{27}|[A-Za-z0-9_-]{24}\.[A-Za-z0-9_-]{6}\.[A-Za-z0-9_-]{38}|[A-Za-z0-9_-]{26}\.[A-Za-z0-9_-]{6}\.[A-Za-z0-9_-]{38})$

Parts are shown as recorded. Evidence classes belong to the facts below; no class is assigned to a part.

Format facts

  • Provider documented · mutable-property-source · current · observed 2026-09-24

    Documentation for the one property varied in legacy twin fixtures (three base64url segments: 24|26 . 6 . 27|38): Un-probeable record lifted 2026-09-24 (#207): twins mutate only segment widths no issued shape has (segment 3 of 37, segment 1 of 25), the dot delimiter, and a byte outside the base64url alphabet. The widths rest on community and dated empirical reports plus TruffleHog's 24/6/27 rule, never on Discord documentation, so every twin stays T2.

    • github.com/redact-secret/redact-secret/issues/646provider-documentation · last read 2026-09-24 · latest outcome read · supports Un-probeable record lifted 2026-09-24 (#207): twins mutate only segment widths no issued shape has (segment 3 of 37, segment 1 of 25), the dot delimiter, and a byte outside the base64url alphabet. The widths rest on community and dated empirical reports plus TruffleHog's 24/6/27 rule, never on Discord documentation, so every twin stays T2.
  • Unresolved · tool-corroboration · current · observed 2026-09-22

    Pinned scanner rules are consistent with the contract grammar (1 artifact: trufflehog 3.97.4).

  • Unresolved · field-segments · current · observed 2026-09-22

    segments: three base64url segments joined by two dots, no = padding

  • Unresolved · field-segment-1 · current · observed 2026-09-22

    segment 1: base64url of the bot user id as decimal ASCII: 24 characters for an 18-digit id, 26 for a 19-digit id (every bot created since 2022-07-22)

    • github.com/redact-secret/redact-secret/issues/646provider-documentation · last read 2026-09-24 · latest outcome read · supports segment 1: base64url of the bot user id as decimal ASCII: 24 characters for an 18-digit id, 26 for a 19-digit id (every bot created since 2022-07-22)
  • Unresolved · field-segment-2 · current · observed 2026-09-22

    segment 2: 6 characters (a timestamp)

  • Unresolved · field-segment-3 · current · observed 2026-09-22

    segment 3: 27 characters before about May 2022, 38 since; older tokens keep 27 until reset

  • Tool corroborated · dossier-research · current · observed 2026-09-24

    Legacy dossier research (verdict ready, tier T2) cited 4 sources; the dossier does not attribute sources to individual properties.

Open questions

No open question is recorded for this revision.

Benchmark dossier notes

From the provider dossier, as written. The evidence level above says how well the format is backed; a fact the dossier does not record is not shown.
Shape
three base64url segments joined by two dots, no padding. Segment 1 is the base64url of the bot user id in decimal ASCII (24 characters for an 18-digit id, 26 for a 19-digit id, the latter for bots created since 2022-07-22). Segment 2 is 6 characters. Segment 3 is 27 characters for tokens issued before about May 2022 and 38 since; old tokens keep 27 until reset. Alphabet [A-Za-z0-9_-].
Basis
the only provider-domain evidence is the API reference's example header, measured 24/6/27 (legacy shape); an example is not a grammar, so T1 is not met. T2 corroboration: Discord.Net token utilities (segment 1 decodes to a ulong id, no padding), detect-secrets, sif, botstrap and TruffleHog (legacy branch only, keyword-gated). The 38-character segment and 26-character head rest on dated community reports and third-party regexes, and neither pinned peer scanner covers them. Discord gives no stability guarantee.
Issuance
not attempted. A fresh token (expected 26/6/38 for a new application) is the open empirical check.
Contract in core
detector-families.md; evidence #646 record. The three-shape acceptance was added in redact-secret#670.

In this benchmark

Fixture rows on the current run. Counts are for redact-secret in published · redact-secret 0.1.0-beta.14 mode.
Fixtures
46
Left readable
0
Redacted too much
0
False alarms
0

46 fixtures: 24 expect a redaction, 22 must stay quiet. See every row

redact-secret fixture counts by evidence level
Evidence levelFixturesLeft readableToo muchFalse alarms
T1Provider-documented1000
T2Tool-corroborated32000
T3Project policy13000

Every scanner on the same fixtures

In run order. Counts are what each scanner recorded on this family's fixtures, whichever rules it has; a scanner with no rule for the family has nothing to report on it.

Counts per scanner on this family's fixtures
ScannerFixturesLeft readableToo muchFalse alarms
flare-redactRuntime library · 1.6.1 · Published npm package · secrets-only (pii, generic_assignment disabled) · JavaScript engine1 rule targets it46801
gitleaksRepository scanner · 8.30.1 · Directory scan · default rulesNo rule maps to it461201
redact-secretProduct measured here · 0.1.0-beta.14 · Published npm package · default detectors1 detector mapped46000
trufflehogRepository scanner · 3.97.4 · Filesystem scan · verification disabled1 rule targets it462400

Benchmark dossier questions

Things the sources do not settle. They are listed so nobody reads them as settled.
Open caveat
Discord documents no grammar (one legacy-shape example only); the 26/6/38 and 24/6/38 widths rest on dated empirical reports and third-party code; no freshly issued token has been measured.

Looks like it, but isn't

Values the dossier records as resembling this credential without being one.
Collisions
none with a fixed prefix; the shape is three dotted base64url runs, so ordinary dotted identifiers and other JWT-like values are the confusable class. detect-secrets additionally requires the first character to be M, N or O, which follows from base64 of a digit string.

Scanner rules for this family

Mapped by hand (reviewed 2026-09-30) from each scanner's pinned rule file, never from what a scanner found on the fixtures.
Peer scanner rules that target this family
ScannerRuleWhat the rule matches
flare-redact · rules 1.6.1discord_bot_tokenM, N or O + 23 . 6 . 27 characters
trufflehog · rules 3.97.4discordbottokendiscord keyword + 24.6.27 character segments

No rule maps to this family in gitleaks, openredaction.

46 of 46 rows

Fixtures in this family

46 rows, redact-secret's outcome on each. Rows that need a look come first (0), then the rest in corpus order. Choose "Every scanner" to see each scanner's outcome for the same rows.
Fixtures in Bot token
FixtureKind and evidenceredact-secret
discord-bot-token-actions-envdiscord · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
discord-bot-token-bomdiscord · multibyte-text-offsetsMust redactT2 · Tool-corroboratedRedacted
discord-bot-token-bot-authorizationdiscord · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
discord-bot-token-client-rundiscord · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
discord-bot-token-compose-envdiscord · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
discord-bot-token-config-jsondiscord · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
discord-bot-token-envdiscord · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
discord-bot-token-interactions-public-key-public-iddiscord · public-identifierMust not flagT1 · Provider-documentedQuiet
discord-bot-token-jsondiscord · structured-text-valueMust redactT2 · Tool-corroboratedRedacted
discord-bot-token-markdowndiscord · markdown-and-comment-valueMust redactT2 · Tool-corroboratedRedacted
discord-bot-token-no-final-newlinediscord · value-at-input-edgesMust redactT2 · Tool-corroboratedRedacted
discord-bot-token-pythondiscord · source-code-string-literalMust redactT2 · Tool-corroboratedRedacted
discord-bot-token-short-hmac-json-twindiscord · wrong-lengthMust not flagT3 · Project policy · twinQuiet
discord-bot-token-single-quotesdiscord · quoted-value-extentMust redactT2 · Tool-corroboratedRedacted
discord-bot-token-startup-logdiscord · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
discord-bot-token-three-segments-barediscord · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
discord-bot-token-three-segments-current-new-bot-barediscord · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
discord-bot-token-three-segments-current-new-bot-quoteddiscord · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
discord-bot-token-three-segments-current-new-bot-unicode-crlfdiscord · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
discord-bot-token-three-segments-current-reset-bot-barediscord · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
discord-bot-token-three-segments-current-reset-bot-quoteddiscord · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
discord-bot-token-three-segments-current-reset-bot-unicode-crlfdiscord · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
discord-bot-token-three-segments-quoteddiscord · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
discord-bot-token-three-segments-unicode-crlfdiscord · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
discord-bot-token-tomldiscord · structured-text-valueMust redactT2 · Tool-corroboratedRedacted
discord-bot-token-yamldiscord · structured-text-valueMust redactT2 · Tool-corroboratedRedacted
discord-bot-token-actions-secret-referencediscord · templated-referenceMust not flagT3 · Project policyQuiet
discord-bot-token-application-id-public-iddiscord · public-identifierMust not flagT3 · Project policyQuiet
discord-bot-token-bang-hmac-twindiscord · wrong-alphabetMust not flagT2 · Tool-corroborated · twinQuiet
discord-bot-token-bang-id-twindiscord · wrong-alphabetMust not flagT2 · Tool-corroborated · twinQuiet
discord-bot-token-dash-delimiter-twindiscord · boundary-violationMust not flagT2 · Tool-corroborated · twinQuiet
discord-bot-token-encoded-user-id-encoded-valuediscord · benign-encoded-valueMust not flagT2 · Tool-corroboratedQuiet
discord-bot-token-label-prosediscord · benign-lookalikeMust not flagT3 · Project policyQuiet
discord-bot-token-maskdiscord · benign-lookalikeMust not flagT3 · Project policyQuiet
discord-bot-token-missing-segmentdiscord · benign-lookalikeMust not flagT2 · Tool-corroboratedQuiet
discord-bot-token-plus-timestamp-twindiscord · wrong-alphabetMust not flagT2 · Tool-corroborated · twinQuiet
discord-bot-token-referencediscord · benign-lookalikeMust not flagT3 · Project policyQuiet
discord-bot-token-reset-note-prosediscord · prose-mentionMust not flagT3 · Project policyQuiet
discord-bot-token-short-current-final-segmentdiscord · benign-lookalikeMust not flagT3 · Project policyQuiet
discord-bot-token-short-current-first-segmentdiscord · benign-lookalikeMust not flagT3 · Project policyQuiet
discord-bot-token-short-final-segmentdiscord · benign-lookalikeMust not flagT2 · Tool-corroboratedQuiet
discord-bot-token-short-hmac-twindiscord · wrong-lengthMust not flagT3 · Project policy · twinQuiet
discord-bot-token-short-id-segment-twindiscord · wrong-lengthMust not flagT3 · Project policy · twinQuiet
discord-bot-token-underscore-delimiter-twindiscord · boundary-violationMust not flagT2 · Tool-corroborated · twinQuiet
discord-bot-token-user-mention-public-iddiscord · public-identifierMust not flagT3 · Project policyQuiet
discord-bot-token-your-token-here-placeholderdiscord · documentation-placeholderMust not flagT3 · Project policyQuiet

Sources

Researched 2026-09-24.

Documentation and code

  • docs.discord.com/developers/reference
  • github.com/discord/discord-api-docs/blob/0eb810206eecc4562899c4c9ca2bd2d354e31e25/developers/reference.mdx
  • github.com/discord-net/Discord.Net/blob/d34a50eeabb39699a2329fbdac735b7d2b069824/src/Discord.Net.Core/Utils/TokenUtils.cs

Research log