redact-secret · Report
CLI token (dp.ct.)
dp.ct. then 40–44 bytes of [A-Za-z0-9] (user-wide); per-type regex on the provider page.
Research record
3 events in the review history: 2 observed, 1 reviewed. Latest: observed on 2026-09-28 by automation, project maintainer. Project-maintained review is not independent validation. The family record at this release.
Format
What it looks like
- Descriptive pattern
^dp\.ct\.[A-Za-z0-9]{40,44}$
Parts are shown as recorded. Evidence classes belong to the facts below; no class is assigned to a part.
Format facts
Provider documented ·
provider-source· current · observed 2026-09-28auth-token-formats regex for dp.ct. (page dateModified 2025-05-29, re-checked 2026-09-28): the provider states the dp.ct. prefix, a 40–44 byte [A-Za-z0-9] body and the . separators as a regex; no checksum is documented
- docs.doppler.com/reference/auth-token-formatsprovider-documentation · last read 2026-09-28 · latest outcome read · supports the provider states the dp.ct. prefix, a 40–44 byte [A-Za-z0-9] body and the . separators as a regex; no checksum is documented
Tool corroborated ·
tool-corroboration· current · observed 2026-09-28Pinned scanner rules are consistent with the contract grammar (2 artifacts: gitleaks 8.30.1; trufflehog 3.97.4).
- gitleaks/gitleaks @ v8.30.1: config/gitleaks.tomlscanner-rule-source · last read 2026-10-04 · latest outcome read · supports gitleaks 8.30.1: doppler-api-token: dp\.pt\.(?i)[a-z0-9]{43} (personal token only, one width)
- trufflesecurity/trufflehog @ v3.97.4: pkg/detectors/doppler/doppler.goscanner-rule-source · last read 2026-09-28 · latest outcome read · supports trufflehog 3.97.4: Doppler: \b(dp\.(?:ct|pt|st(?:\.[a-z0-9\-_]{2,35})?|sa|scim|audit)\.[a-zA-Z0-9]{40,44})\b (no said)
Provider documented ·
field-prefix· current · observed 2026-09-28prefix: dp.ct.
- docs.doppler.com/reference/auth-token-formatsprovider-documentation · last read 2026-09-28 · latest outcome read · supports regex for the CLI token (user-wide)
- redact-secret/redact-secret @ 270faf84dc12f6a4a4cf61fe3ffab7aadc4f7262: docs/audits/evidence/860/doppler.mdprovider-documentation · last read 2026-09-28 · latest outcome read · supports prefix: dp.ct.
Provider documented ·
field-body· current · observed 2026-09-28body: 40–44 bytes of [A-Za-z0-9]; no _ or - inside the body (Every documentation example and the one empirical observation in the research table have 43; the band stays as documented.)
- docs.doppler.com/reference/auth-token-formatsprovider-documentation · last read 2026-09-28 · latest outcome read · supports body: 40–44 bytes of [A-Za-z0-9]; no _ or - inside the body
Provider documented ·
field-separators· current · observed 2026-09-28separators: . after dp, after the type and after the optional segment; none inside the body
- docs.doppler.com/reference/auth-token-formatsprovider-documentation · last read 2026-09-28 · latest outcome read · supports separators: . after dp, after the type and after the optional segment; none inside the body
Unresolved ·
field-checksum· current · observed 2026-09-28checksum: none documented (No fixture relies on a checksum either way.)
- docs.doppler.com/reference/auth-token-formatsprovider-documentation · last read 2026-09-28 · latest outcome read · supports checksum: none documented
Unresolved ·
field-boundary· current · observed 2026-09-28boundary: a value glued to an identifier on either side ([A-Za-z0-9_-] after the body, [A-Za-z0-9_.-] before dp) is not a key; a following . is sentence punctuation (The handoff's precision choice, shared by every prefixed family; backs the glue twins.)
- redact-secret/redact-secret @ 270faf84dc12f6a4a4cf61fe3ffab7aadc4f7262: docs/audits/evidence/860/doppler.mdprovider-documentation · last read 2026-09-28 · latest outcome read · supports implementation notes and accepted false negatives
Tool corroborated ·
field-peer-lag· current · observed 2026-09-28peer-lag: gitleaks 8.30.1 covers dp.pt. only (Corroboration only; never used to narrow or widen the documented grammar.)
- docs.github.com/en/code-security/secret-scanning/introduction/supported-secret-scanning-patternsprovider-documentation · last read 2026-10-05 · latest outcome read · supports peer-lag: gitleaks 8.30.1 covers dp.pt. only
- gitleaks/gitleaks @ v8.30.1: config/gitleaks.tomlscanner-rule-source · last read 2026-10-04 · latest outcome read · supports doppler-api-token
- trufflesecurity/trufflehog @ v3.97.4: pkg/detectors/doppler/doppler.goscanner-rule-source · last read 2026-09-28 · latest outcome read · supports peer-lag: gitleaks 8.30.1 covers dp.pt. only
Provider documented ·
field-non-secrets· current · observed 2026-09-28non-secrets: the dp.st… preview, service-token slugs and token names are not credentials
- redact-secret/redact-secret @ 270faf84dc12f6a4a4cf61fe3ffab7aadc4f7262: docs/audits/evidence/860/doppler.mdprovider-documentation · last read 2026-09-28 · latest outcome read · supports excluded shapes
Unresolved ·
listed-references· current · observed 2026-09-28The legacy contract lists 7 references without stating which property each supports.
- docs.doppler.com/reference/auth-token-formatsprovider-documentation · last read 2026-09-28 · latest outcome read · supports Listed as a reference by the legacy contract
- docs.github.com/en/code-security/secret-scanning/introduction/supported-secret-scanning-patternsprovider-documentation · last read 2026-10-05 · latest outcome read · supports Listed as a reference by the legacy contract
- redact-secret/redact-secret @ 270faf84dc12f6a4a4cf61fe3ffab7aadc4f7262: docs/audits/evidence/860/doppler.mdprovider-documentation · last read 2026-09-28 · latest outcome read · supports Listed as a reference by the legacy contract
- redact-secret/redact-secret @ 270faf84dc12f6a4a4cf61fe3ffab7aadc4f7262: docs/audits/evidence/860/README.mdproject-research-note · last read 2026-09-28 · latest outcome read · supports Listed as a reference by the legacy contract
- github.com/redact-secret/redact-secret/issues/903issue-or-discussion · last read 2026-09-28 · latest outcome read · supports Listed as a reference by the legacy contract
- github.com/redact-secret/redact-secret/issues/860issue-or-discussion · last read 2026-09-29 · latest outcome read · supports Listed as a reference by the legacy contract
- github.com/redact-secret/redact-secret-benchmarks/issues/434issue-or-discussion · last read 2026-09-28 · latest outcome read · supports Listed as a reference by the legacy contract
Provider documented ·
dossier-research· current · observed 2026-09-28Legacy dossier research (verdict ready, tier T1) cited 2 sources; the dossier does not attribute sources to individual properties.
- docs.doppler.com/reference/auth-token-formatsprovider-documentation · last read 2026-09-28 · latest outcome read · supports Cited by the legacy dossier research for this family
- redact-secret/redact-secret @ 8b6a5fde52ecb4dfce13f09c7a947062d21483c7: docs/audits/evidence/860/doppler.mdproject-research-note · last read 2026-09-28 · latest outcome read · supports Final research evidence recorded by the legacy dossier
Provider documented ·
taxonomy-sources· current · observed 2026-09-28The legacy taxonomy lists 2 sources for this family. The taxonomy records no date; the dossier researchedAt is used as the observed-at date.
- docs.doppler.com/reference/auth-token-formatsprovider-documentation · last read 2026-09-28 · latest outcome read · supports Listed as a source for this family in the legacy taxonomy
- redact-secret/redact-secret @ 270faf84dc12f6a4a4cf61fe3ffab7aadc4f7262: docs/audits/evidence/860/doppler.mdprovider-documentation · last read 2026-09-28 · latest outcome read · supports Listed as a source for this family in the legacy taxonomy
Open questions
No open question is recorded for this revision.
Benchmark dossier notes
- Shape
dp.ct.+ 40 to 44 alphanumerics. Role: user-wide scope.- Basis
- T1, per-type regex on the provider page.
- Contract in core
- detector-families.md.
In this benchmark
- Fixtures
- 36
- Left readable
- 0
- Redacted too much
- 0
- False alarms
- 0
36 fixtures: 14 expect a redaction, 22 must stay quiet. See every row
| Evidence level | Fixtures | Left readable | Too much | False alarms |
|---|---|---|---|---|
| T1Provider-documented | 14 | 0 | 0 | 0 |
| T2Tool-corroborated | 17 | 0 | 0 | 0 |
| T3Project policy | 5 | 0 | 0 | 0 |
Every scanner on the same fixtures
In run order. Counts are what each scanner recorded on this family's fixtures, whichever rules it has; a scanner with no rule for the family has nothing to report on it.
| Scanner | Fixtures | Left readable | Too much | False alarms |
|---|---|---|---|---|
| flare-redactRuntime library · 1.6.1 · Published npm package · secrets-only (pii, generic_assignment disabled) · JavaScript engine1 rule targets it | 36 | 0 | 1 | 0 |
| gitleaksRepository scanner · 8.30.1 · Directory scan · default rulesNo rule maps to it | 36 | 6 | 0 | 0 |
| redact-secretProduct measured here · 0.1.0-beta.14 · Published npm package · default detectors1 detector mapped | 36 | 0 | 0 | 0 |
| trufflehogRepository scanner · 3.97.4 · Filesystem scan · verification disabled1 rule targets it | 36 | 0 | 0 | 0 |
Looks like it, but isn't
- Collisions
- no other issuer using
dp.was found.
Scanner rules for this family
| Scanner | Rule | What the rule matches |
|---|---|---|
| flare-redact · rules 1.6.1 | doppler_token | dp.ct., dp.pt. or dp.st. + 40-44 characters |
| trufflehog · rules 3.97.4 | doppler | dp.st., dp.pt., dp.ct., dp.sa., dp.scim. or dp.audit. + 40-44 characters |
No rule maps to this family in gitleaks, openredaction.
Fixtures in this family
| Fixture | Kind and evidence | redact-secret |
|---|---|---|
doppler-cli-token-bare-prosedoppler · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
doppler-cli-token-bearer-headerdoppler · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
doppler-cli-token-chat-pastedoppler · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
doppler-cli-token-code-fencedoppler · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
doppler-cli-token-dotenvdoppler · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
doppler-cli-token-sentence-perioddoppler · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
doppler-cli-token-actions-secret-referencedoppler · templated-reference | Must not flagT3 · Project policy | Quiet |
doppler-cli-token-body-39-twindoppler · wrong-length | Must not flagT2 · Tool-corroborated · twin | Quiet |
doppler-cli-token-body-45-twindoppler · wrong-length | Must not flagT2 · Tool-corroborated · twin | Quiet |
doppler-cli-token-ci-logdoppler · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
doppler-cli-token-cli-commands-prosedoppler · prose-mention | Must not flagT3 · Project policy | Quiet |
doppler-cli-token-cli-env-reference-referencedoppler · templated-reference | Must not flagT3 · Project policy | Quiet |
doppler-cli-token-cli-preview-public-iddoppler · public-identifier | Must not flagT2 · Tool-corroborated | Quiet |
doppler-cli-token-config-wildcard-placeholderdoppler · documentation-placeholder | Must not flagT3 · Project policy | Quiet |
doppler-cli-token-digest-encoded-valuedoppler · benign-encoded-value | Must not flagT2 · Tool-corroborated | Quiet |
doppler-cli-token-exportdoppler · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
doppler-cli-token-hyphen-in-body-twindoppler · wrong-alphabet | Must not flagT2 · Tool-corroborated · twin | Quiet |
doppler-cli-token-json-api-keydoppler · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
doppler-cli-token-json-tokendoppler · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
doppler-cli-token-k8s-string-datadoppler · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
doppler-cli-token-leading-glue-twindoppler · boundary-violation | Must not flagT2 · Tool-corroborated · twin | Quiet |
doppler-cli-token-leading-underscore-twindoppler · boundary-violation | Must not flagT2 · Tool-corroborated · twin | Quiet |
doppler-cli-token-missing-first-dot-twindoppler · boundary-violation | Must not flagT2 · Tool-corroborated · twin | Quiet |
doppler-cli-token-missing-type-dot-twindoppler · boundary-violation | Must not flagT2 · Tool-corroborated · twin | Quiet |
doppler-cli-token-prefix-only-near-missdoppler · format-near-miss | Must not flagT2 · Tool-corroborated | Quiet |
doppler-cli-token-sdk-kwargdoppler · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
doppler-cli-token-token-slug-public-iddoppler · public-identifier | Must not flagT2 · Tool-corroborated | Quiet |
doppler-cli-token-trailing-glue-twindoppler · boundary-violation | Must not flagT2 · Tool-corroborated · twin | Quiet |
doppler-cli-token-truncated-near-missdoppler · format-near-miss | Must not flagT2 · Tool-corroborated | Quiet |
doppler-cli-token-underscore-in-body-twindoppler · wrong-alphabet | Must not flagT2 · Tool-corroborated · twin | Quiet |
doppler-cli-token-unknown-type-twindoppler · prefix-near-miss | Must not flagT2 · Tool-corroborated · twin | Quiet |
doppler-cli-token-uppercase-prefix-twindoppler · prefix-near-miss | Must not flagT2 · Tool-corroborated · twin | Quiet |
doppler-cli-token-uppercase-type-twindoppler · prefix-near-miss | Must not flagT2 · Tool-corroborated · twin | Quiet |
doppler-cli-token-x-api-key-headerdoppler · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
doppler-cli-token-x-run-placeholderdoppler · documentation-placeholder | Must not flagT3 · Project policy | Quiet |
doppler-cli-token-yamldoppler · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
Sources
Documentation and code
- docs.doppler.com/reference/auth-token-formats
- github.com/redact-secret/redact-secret/blob/270faf84dc12f6a4a4cf61fe3ffab7aadc4f7262/docs/audits/evidence/860/doppler.md
Research log
- redact-secret/redact-secret#860Research issue
- redact-secret/redact-secret#903Research issue
- redact-secret/redact-secret-benchmarks#434Research issue
- Final evidence, pinned to a commit/redact-secret/redact-secret/blob/8b6a5fde52ecb4dfce13f09c7a947062d21483c7/docs/audits/evidence/860/doppler.md