redact-secret · Report
Access and platform token (dt0c01, dt0s..)
dt0 + c|s + 2 digits + . + 24 [A-Z2-7] + . + 64 [A-Z2-7] (96 in all); the token identifier alone is documented as safe to log and is not claimed.
Research record
3 events in the review history: 2 observed, 1 reviewed. Latest: observed on 2026-09-29 by automation, project maintainer. Project-maintained review is not independent validation. The family record at this release.
Format
What it looks like
- Descriptive pattern
^dt0[cs][0-9]{2}\.[A-Z2-7]{24}\.[A-Z2-7]{64}$
Parts are shown as recorded. Evidence classes belong to the facts below; no class is assigned to a part.
Format facts
Provider documented ·
provider-source· current · observed 2026-09-29Dynatrace docs "Token format" (updated 2026-08-04): three components separated by dots, a prefix that identifies the token type, a 24-character public portion and a 64-character secret portion; Dynatrace/dynatrace-operator pkg/util/dttoken/token.go (2a39d88, 2026-07-22): base32.StdEncoding truncated to each portion; re-checked 2026-09-29: dt0 + c|s + 2 digits + . + exactly 24 [A-Z2-7] + . + exactly 64 [A-Z2-7], 96 in all
- docs.dynatrace.com/docs/dynatrace-api/basics/dynatrace-api-authenticationprovider-documentation · last read 2026-09-29 · latest outcome read · supports dt0 + c|s + 2 digits + . + exactly 24 [A-Z2-7] + . + exactly 64 [A-Z2-7], 96 in all
Unresolved ·
tool-corroboration· current · observed 2026-09-29Pinned scanner rules are consistent with the contract grammar (1 artifact: gitleaks 8.30.1).
- gitleaks/gitleaks @ v8.30.1: config/gitleaks.tomlscanner-rule-source · last read 2026-10-04 · latest outcome read · supports gitleaks 8.30.1: dynatrace-api-token: dt0c01\.(?i)[a-z0-9]{24}\.[a-z0-9]{64} (dt0c01 only, case-insensitive alphanumeric)
Provider documented ·
field-prefix· current · observed 2026-09-29prefix: dt0 + c or s + two digits (the docs table lists dt0s01..dt0s16; dt0c01 is the classic prefix in the docs request examples)
- docs.dynatrace.com/docs/dynatrace-api/basics/dynatrace-api-authenticationprovider-documentation · last read 2026-09-29 · latest outcome read · supports prefix table and request examples
- github.com/redact-secret/redact-secret/issues/860issue-or-discussion · last read 2026-09-29 · latest outcome read · supports R4: a placeholder is T1 for its prefix · #issuecomment-5871306275
Provider documented ·
field-layout· current · observed 2026-09-29layout: <prefix>.<24-character public portion>.<64-character secret portion>; 96 in all
- docs.dynatrace.com/docs/dynatrace-api/basics/dynatrace-api-authenticationprovider-documentation · last read 2026-09-29 · latest outcome read · supports "three components separated by dots"; 24 and 64
- Dynatrace/dynatrace-operator @ 2a39d88a0ee1fbb61e2d22db02520b3dc92ffc80: pkg/util/dttoken/token.goprovider-documentation · last read 2026-09-29 · latest outcome read · supports the same format comment · #L14-L58
Provider documented ·
field-alphabet· current · observed 2026-09-29alphabet: uppercase base32 [A-Z2-7] in both portions
- docs.dynatrace.com/docs/dynatrace-api/basics/dynatrace-api-authenticationprovider-documentation · last read 2026-09-29 · latest outcome read · supports the full-length example uses only A-Z and 2-7
- Dynatrace/dynatrace-operator @ 2a39d88a0ee1fbb61e2d22db02520b3dc92ffc80: pkg/util/dttoken/token.goprovider-documentation · last read 2026-09-29 · latest outcome read · supports base32.StdEncoding · #L14-L58
- github.com/redact-secret/redact-secret/issues/860issue-or-discussion · last read 2026-09-29 · latest outcome read · supports R1 · #issuecomment-5852413851
Provider documented ·
field-token-identifier· current · observed 2026-09-29token-identifier: the prefix plus public portion "can be safely displayed in the UI and can be used for logging purposes" (A token identifier alone is a benign control; inside a full token it is part of the one span.)
- docs.dynatrace.com/docs/dynatrace-api/basics/dynatrace-api-authenticationprovider-documentation · last read 2026-09-29 · latest outcome read · supports token-identifier: the prefix plus public portion "can be safely displayed in the UI and can be used for logging purposes"
Unresolved ·
field-boundary· current · observed 2026-09-29boundary: the byte before dt0 and the byte after the secret portion are not [A-Za-z0-9_.-] (Handoff boundary decision, not a provider statement. Read literally it would reject the URL-encoded OpenTelemetry header Authorization=Api-Token%20<token>, where the byte before dt0 is 0; that form is a documented transport, so it is authored as a positive and measures whether an implementation handles it. A .x glued after the token leaves a contract-valid token before the dot, so it is not authored as a twin (#84); the trailing-glue twin appends _x.)
- redact-secret/redact-secret @ 4f220ea000b58fa2e0e431ad88dea4eccb393fb0: docs/audits/evidence/1014/dynatrace.mdprovider-documentation · last read 2026-09-29 · latest outcome read · supports implementation notes
Provider documented ·
field-transport· current · observed 2026-09-29transport: Authorization: Api-Token <token> (the documented scheme); DT_API_TOKEN; a DynaKube secret apiToken; an OpenTelemetry exporter header Authorization=Api-Token%20<token>
- docs.dynatrace.com/docs/dynatrace-api/basics/dynatrace-api-authenticationprovider-documentation · last read 2026-09-29 · latest outcome read · supports transport: Authorization: Api-Token <token> (the documented scheme); DT_API_TOKEN; a DynaKube secret apiToken; an OpenTelemetry exporter header Authorization=Api-Token%20<token>
- redact-secret/redact-secret @ 4f220ea000b58fa2e0e431ad88dea4eccb393fb0: docs/audits/evidence/1014/dynatrace.mdprovider-documentation · last read 2026-09-29 · latest outcome read · supports test axes
Tool corroborated ·
field-peer-lag· current · observed 2026-09-29peer-lag: gitleaks 8.30.1 dynatrace-api-token dt0c01\.(?i)[a-z0-9]{24}\.[a-z0-9]{64} (entropy 4, no boundary) reads dt0c01 only: it lags on every dt0s token and overreaches on lowercase and 0/1/8/9 bodies, leading glue and a 65-byte secret portion (it matches the first 64). Mapped to dynatrace-token. No Dynatrace rule in trufflehog 3.97.4
- gitleaks/gitleaks @ v8.30.1: config/gitleaks.tomlscanner-rule-source · last read 2026-10-04 · latest outcome read · supports dynatrace-api-token
- trufflesecurity/trufflehog @ v3.97.4: pkg/detectorsscanner-rule-source · last read 2026-09-29 · latest outcome read · supports no dynatrace detector directory at the pinned version
Unresolved ·
listed-references· current · observed 2026-09-29The legacy contract lists 10 references without stating which property each supports.
- docs.dynatrace.com/docs/dynatrace-api/basics/dynatrace-api-authenticationprovider-documentation · last read 2026-09-29 · latest outcome read · supports Listed as a reference by the legacy contract
- Dynatrace/dynatrace-operator @ 2a39d88a0ee1fbb61e2d22db02520b3dc92ffc80: pkg/util/dttoken/token.goprovider-documentation · last read 2026-09-29 · latest outcome read · supports Listed as a reference by the legacy contract · #L14-L58
- redact-secret/redact-secret @ 4f220ea000b58fa2e0e431ad88dea4eccb393fb0: docs/audits/evidence/1014/dynatrace.mdprovider-documentation · last read 2026-09-29 · latest outcome read · supports Listed as a reference by the legacy contract
- github.com/redact-secret/redact-secret/issues/1032issue-or-discussion · last read 2026-09-29 · latest outcome read · supports Listed as a reference by the legacy contract
- redact-secret/redact-secret @ 4f220ea000b58fa2e0e431ad88dea4eccb393fb0: docs/audits/evidence/1014/README.mdprovider-documentation · last read 2026-09-29 · latest outcome read · supports Listed as a reference by the legacy contract
- github.com/redact-secret/redact-secret/issues/1014issue-or-discussion · last read 2026-09-29 · latest outcome read · supports Listed as a reference by the legacy contract · #issuecomment-5900447540
- github.com/redact-secret/redact-secret/issues/1014issue-or-discussion · last read 2026-09-29 · latest outcome read · supports Listed as a reference by the legacy contract
- github.com/redact-secret/redact-secret/issues/860issue-or-discussion · last read 2026-09-29 · latest outcome read · supports Listed as a reference by the legacy contract · #issuecomment-5852413851
- github.com/redact-secret/redact-secret/issues/860issue-or-discussion · last read 2026-09-29 · latest outcome read · supports Listed as a reference by the legacy contract · #issuecomment-5871306275
- github.com/redact-secret/redact-secret-benchmarks/issues/528issue-or-discussion · last read 2026-09-29 · latest outcome read · supports Listed as a reference by the legacy contract
Provider documented ·
dossier-research· current · observed 2026-09-29Legacy dossier research (verdict ready, tier T1) cited 3 sources; the dossier does not attribute sources to individual properties.
- docs.dynatrace.com/docs/dynatrace-api/basics/dynatrace-api-authenticationprovider-documentation · last read 2026-09-29 · latest outcome read · supports Cited by the legacy dossier research for this family
- Dynatrace/dynatrace-operator @ 2a39d88a0ee1fbb61e2d22db02520b3dc92ffc80: pkg/util/dttoken/token.goprovider-documentation · last read 2026-09-29 · latest outcome read · supports Cited by the legacy dossier research for this family · #L14-L58
- redact-secret/redact-secret @ 378581770a87751d72e27529796c4f790649fd00: docs/audits/evidence/1014/dynatrace.mdproject-research-note · last read 2026-09-29 · latest outcome read · supports Final research evidence recorded by the legacy dossier
Provider documented ·
taxonomy-sources· current · observed 2026-09-29The legacy taxonomy lists 2 sources for this family. The taxonomy records no date; the dossier researchedAt is used as the observed-at date.
- docs.dynatrace.com/docs/dynatrace-api/basics/dynatrace-api-authenticationprovider-documentation · last read 2026-09-29 · latest outcome read · supports Listed as a source for this family in the legacy taxonomy
- redact-secret/redact-secret @ 4f220ea000b58fa2e0e431ad88dea4eccb393fb0: docs/audits/evidence/1014/dynatrace.mdprovider-documentation · last read 2026-09-29 · latest outcome read · supports Listed as a source for this family in the legacy taxonomy
Open questions
No open question is recorded for this revision.
Benchmark dossier notes
- Shape
dt0+c|s+ two digits +.+ 24[A-Z2-7]+.+ 64[A-Z2-7](96 in all).- Basis
- T1: structure, both lengths and the prefix table are the docs (
dt0c01by the docs placeholder, R4); the base32 alphabet is the provider operator generator (R1) and the docs example. - Issuance
- not attempted; the grammar is T1 from provider sources, so no key is needed.
- Contract in core
- detector-families.md (row on
main; the Beta.12 detector, redact-secret#1032, merged in redact-secret#1039 and is unreleased).
In this benchmark
- Fixtures
- 41
- Left readable
- 0
- Redacted too much
- 0
- False alarms
- 0
41 fixtures: 16 expect a redaction, 25 must stay quiet. See every row
| Evidence level | Fixtures | Left readable | Too much | False alarms |
|---|---|---|---|---|
| T1Provider-documented | 16 | 0 | 0 | 0 |
| T2Tool-corroborated | 17 | 0 | 0 | 0 |
| T3Project policy | 8 | 0 | 0 | 0 |
Every scanner on the same fixtures
In run order. Counts are what each scanner recorded on this family's fixtures, whichever rules it has; a scanner with no rule for the family has nothing to report on it.
| Scanner | Fixtures | Left readable | Too much | False alarms |
|---|---|---|---|---|
| flare-redactRuntime library · 1.6.1 · Published npm package · secrets-only (pii, generic_assignment disabled) · JavaScript engineNo rule maps to it | 41 | 15 | 1 | 0 |
| gitleaksRepository scanner · 8.30.1 · Directory scan · default rules1 rule targets it | 41 | 1 | 0 | 5 |
| redact-secretProduct measured here · 0.1.0-beta.14 · Published npm package · default detectors1 detector mapped | 41 | 0 | 0 | 0 |
| trufflehogRepository scanner · 3.97.4 · Filesystem scan · verification disabledNo rule maps to it | 41 | 16 | 0 | 0 |
Looks like it, but isn't
- Collisions
- the token identifier alone (prefix + public portion) is documented as safe to log (Q5).
Scanner rules for this family
| Scanner | Rule | What the rule matches |
|---|---|---|
| gitleaks · rules 8.30.1 | dynatrace-api-token | dt0c01. + 24 + . + 64 characters |
No rule maps to this family in flare-redact, openredaction, trufflehog.
Fixtures in this family
| Fixture | Kind and evidence | redact-secret |
|---|---|---|
dynatrace-token-api-token-headerdynatrace · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
dynatrace-token-bare-prosedynatrace · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
dynatrace-token-bearer-headerdynatrace · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
dynatrace-token-chat-pastedynatrace · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
dynatrace-token-collector-headersdynatrace · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
dynatrace-token-digit-outside-base32-twindynatrace · wrong-alphabet | Must not flagT2 · Tool-corroborated · twin | Quiet |
dynatrace-token-docs-placeholder-placeholderdynatrace · documentation-placeholder | Must not flagT3 · Project policy | Quiet |
dynatrace-token-dotenvdynatrace · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
dynatrace-token-dynakube-secretdynatrace · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
dynatrace-token-exportdynatrace · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
dynatrace-token-json-api-keydynatrace · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
dynatrace-token-json-tokendynatrace · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
dynatrace-token-key-shape-baredynatrace · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
dynatrace-token-key-shape-quoteddynatrace · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
dynatrace-token-key-shape-unicode-crlfdynatrace · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
dynatrace-token-leading-glue-twindynatrace · boundary-violation | Must not flagT2 · Tool-corroborated · twin | Quiet |
dynatrace-token-otel-env-headerdynatrace · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
dynatrace-token-sdk-kwargdynatrace · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
dynatrace-token-secret-65-twindynatrace · wrong-length | Must not flagT2 · Tool-corroborated · twin | Quiet |
dynatrace-token-trailing-underscore-twindynatrace · boundary-violation | Must not flagT2 · Tool-corroborated · twin | Quiet |
dynatrace-token-x-api-key-headerdynatrace · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
dynatrace-token-angle-brackets-placeholderdynatrace · documentation-placeholder | Must not flagT3 · Project policy | Quiet |
dynatrace-token-bare-base32-run-encoded-valuedynatrace · benign-encoded-value | Must not flagT2 · Tool-corroborated | Quiet |
dynatrace-token-env-reference-referencedynatrace · templated-reference | Must not flagT3 · Project policy | Quiet |
dynatrace-token-hyphen-separator-twindynatrace · wrong-alphabet | Must not flagT2 · Tool-corroborated · twin | Quiet |
dynatrace-token-label-prosedynatrace · benign-lookalike | Must not flagT3 · Project policy | Quiet |
dynatrace-token-lowercase-byte-twindynatrace · wrong-alphabet | Must not flagT2 · Tool-corroborated · twin | Quiet |
dynatrace-token-maskdynatrace · benign-lookalike | Must not flagT3 · Project policy | Quiet |
dynatrace-token-prefix-onlydynatrace · benign-lookalike | Must not flagT2 · Tool-corroborated | Quiet |
dynatrace-token-public-23-twindynatrace · wrong-length | Must not flagT2 · Tool-corroborated · twin | Quiet |
dynatrace-token-public-25-twindynatrace · wrong-length | Must not flagT2 · Tool-corroborated · twin | Quiet |
dynatrace-token-referencedynatrace · benign-lookalike | Must not flagT3 · Project policy | Quiet |
dynatrace-token-secret-63-twindynatrace · wrong-length | Must not flagT2 · Tool-corroborated · twin | Quiet |
dynatrace-token-secret-key-ref-referencedynatrace · templated-reference | Must not flagT3 · Project policy | Quiet |
dynatrace-token-short-bodydynatrace · benign-lookalike | Must not flagT2 · Tool-corroborated | Quiet |
dynatrace-token-token-guidance-prosedynatrace · prose-mention | Must not flagT3 · Project policy | Quiet |
dynatrace-token-token-identifier-log-public-iddynatrace · public-identifier | Must not flagT2 · Tool-corroborated | Quiet |
dynatrace-token-token-identifier-ui-public-iddynatrace · public-identifier | Must not flagT2 · Tool-corroborated | Quiet |
dynatrace-token-truncated-near-missdynatrace · format-near-miss | Must not flagT2 · Tool-corroborated | Quiet |
dynatrace-token-unknown-type-letter-twindynatrace · prefix-near-miss | Must not flagT2 · Tool-corroborated · twin | Quiet |
dynatrace-token-version-1-twindynatrace · prefix-near-miss | Must not flagT2 · Tool-corroborated · twin | Quiet |
Sources
Documentation and code
- docs.dynatrace.com/docs/dynatrace-api/basics/dynatrace-api-authentication
- github.com/redact-secret/redact-secret/blob/4f220ea000b58fa2e0e431ad88dea4eccb393fb0/docs/audits/evidence/1014/dynatrace.md
- github.com/Dynatrace/dynatrace-operator/blob/2a39d88a0ee1fbb61e2d22db02520b3dc92ffc80/pkg/util/dttoken/token.go#L14-L58
Research log
- redact-secret/redact-secret#1014Research issue
- redact-secret/redact-secret#1032Research issue
- redact-secret/redact-secret#1039Research issue
- redact-secret/redact-secret-benchmarks#528Research issue
- Final evidence, pinned to a commit/redact-secret/redact-secret/blob/378581770a87751d72e27529796c4f790649fd00/docs/audits/evidence/1014/dynatrace.md