Skip to content
Benchmarks

redact-secret · Report

API key (sk_)

sk_ + 48 lowercase hex, with an optional provider-code-evidenced _residency_<region> suffix, sent in the xi-api-key header.

  • ElevenLabs
  • Detectors: elevenlabs-api-key
  • Run 2026-10-07
  • Mode published · redact-secret 0.1.0-beta.14
  • Dossier verdictReady
  • Dossier evidence levelT1 · Provider-documented
  • Dossier researched2026-09-27
Registry detector elevenlabs-api-key since redact-secret#865 (registry pinned at cfe2aec); graduated from a Beta.10 arrival family (#384, research #788), contract in benchmarks/lib/beta8/384c.ts. T1 by maintainer ruling of 2026-09-27 (redact-secret#788) on ElevenLabs SDK code for the sk_ prefix and the _residency_[a-z0-9]+ suffix grammar; the 48-lowercase-hex body stays T2 and no fixture asserts it. sk_ is shared with Stripe (sk_live_, sk_test_, sk_org_) and Pollinations.

Research record

From credential-evidence snapshot-2026.10.06.4 · records at 77ce761 · schema 1.8.0. It describes the research on the format, not what any scanner or the product does, and not a support status.
  • Review stateDraft, not reviewed
  • Format revision1 · current
  • ResearchResearched
  • Researched2026-09-27

3 events in the review history: 2 observed, 1 reviewed. Latest: observed on 2026-09-27 by automation, project maintainer. Project-maintained review is not independent validation. The family record at this release.

Format

Provider format research from credential-evidence snapshot-2026.10.06.4 · records at 77ce761 · schema 1.8.0.

What it looks like

Descriptive pattern
^sk_[0-9a-f]{48}$

Parts are shown as recorded. Evidence classes belong to the facts below; no class is assigned to a part.

Format facts

Open questions

No open question is recorded for this revision.

Benchmark dossier notes

From the provider dossier, as written. The evidence level above says how well the format is backed; a fact the dossier does not record is not shown.
Shape
sk_ followed by 48 lowercase hexadecimal characters (51 in all), with an optional _residency_<region> suffix matching _residency_[a-z0-9]+ (regions seen: in, eu). The suffix belongs to the key, so a residency key is redacted whole. Body length and alphabet are stated by no provider source.
Basis
T1 by maintainer ruling of 2026-09-27, on provider SDK code (the huggingface:api-token precedent): a docstring api_key="sk_..." in speech_engine/server.py, and _RESIDENCY_KEY_SUFFIX in resource.py and the JS SpeechEngineResource.ts. The docs pages state neither prefix nor length. The body is T2: trufflehog v2, betterleaks (Kingfisher aliases it) and about 35 code-search fragments, all 48 lowercase hex where fully formed.
Issuance
not attempted. The #788 checklist covers user and service-account keys, an isolated-environment key and its suffix, the displayed hint, and whether an old account still holds a 32-hex key.
Contract in core
detector-families.md; the spec row records the T1 ruling and the T2 body. #866 covers the single-line SDK-argument form generically.

In this benchmark

Fixture rows on the current run. Counts are for redact-secret in published · redact-secret 0.1.0-beta.14 mode.
Fixtures
38
Left readable
0
Redacted too much
0
False alarms
0

38 fixtures: 13 expect a redaction, 25 must stay quiet. See every row

redact-secret fixture counts by evidence level
Evidence levelFixturesLeft readableToo muchFalse alarms
T1Provider-documented13000
T2Tool-corroborated14000
T3Project policy8000
T0Pending review3000

Every scanner on the same fixtures

In run order. Counts are what each scanner recorded on this family's fixtures, whichever rules it has; a scanner with no rule for the family has nothing to report on it.

Counts per scanner on this family's fixtures
ScannerFixturesLeft readableToo muchFalse alarms
flare-redactRuntime library · 1.6.1 · Published npm package · secrets-only (pii, generic_assignment disabled) · JavaScript engineNo rule maps to it381300
gitleaksRepository scanner · 8.30.1 · Directory scan · default rulesNo rule maps to it38501
redact-secretProduct measured here · 0.1.0-beta.14 · Published npm package · default detectors1 detector mapped38000
trufflehogRepository scanner · 3.97.4 · Filesystem scan · verification disabled1 rule targets it38500

Benchmark dossier questions

Things the sources do not settle. They are listed so nobody reads them as settled.
Open caveat
T1 covers the sk_ prefix and _residency_ suffix (SDK code, by ruling); the 48-lowercase-hex body is T2 with no provider statement. The legacy 32-hex form is unresearched; needs issued keys (checklist in #788).

Looks like it, but isn't

Values the dossier records as resembling this credential without being one.
Collisions
sk_ is shared with Stripe (sk_live_, sk_test_, sk_org_) and with a planned Pollinations sk_ plus 32 characters key, so the prefix alone cannot attribute a key. The response fields key_id, hint and hashed_xi_api_key are non-secret; so are voice ids.

Scanner rules for this family

Mapped by hand (reviewed 2026-09-30) from each scanner's pinned rule file, never from what a scanner found on the fixtures.
Peer scanner rules that target this family
ScannerRuleWhat the rule matches
trufflehog · rules 3.97.4elevenlabs/v2sk_ + 48 hex

No rule maps to this family in flare-redact, gitleaks, openredaction.

38 of 38 rows

Fixtures in this family

38 rows, redact-secret's outcome on each. Rows that need a look come first (0), then the rest in corpus order. Choose "Every scanner" to see each scanner's outcome for the same rows.
Fixtures in API key (sk_)
FixtureKind and evidenceredact-secret
elevenlabs-api-key-curl-xi-api-keyelevenlabs · documented-format-literalMust redactT1 · Provider-documentedRedacted
elevenlabs-api-key-dotenvelevenlabs · documented-format-literalMust redactT1 · Provider-documentedRedacted
elevenlabs-api-key-export-xi-api-keyelevenlabs · documented-format-literalMust redactT1 · Provider-documentedRedacted
elevenlabs-api-key-hashed-key-encoded-valueelevenlabs · benign-encoded-valueMust not flagT2 · Tool-corroboratedQuiet
elevenlabs-api-key-js-clientelevenlabs · documented-format-literalMust redactT1 · Provider-documentedRedacted
elevenlabs-api-key-key-shape-bareelevenlabs · documented-format-literalMust redactT1 · Provider-documentedRedacted
elevenlabs-api-key-key-shape-quotedelevenlabs · documented-format-literalMust redactT1 · Provider-documentedRedacted
elevenlabs-api-key-key-shape-unicode-crlfelevenlabs · documented-format-literalMust redactT1 · Provider-documentedRedacted
elevenlabs-api-key-pasted-keyelevenlabs · documented-format-literalMust redactT1 · Provider-documentedRedacted
elevenlabs-api-key-python-multi-lineelevenlabs · documented-format-literalMust redactT1 · Provider-documentedRedacted
elevenlabs-api-key-python-single-lineelevenlabs · documented-format-literalMust redactT1 · Provider-documentedRedacted
elevenlabs-api-key-residency-suffixelevenlabs · documented-format-literalMust redactT1 · Provider-documentedRedacted
elevenlabs-api-key-tool-callelevenlabs · documented-format-literalMust redactT1 · Provider-documentedRedacted
elevenlabs-api-key-yaml-configelevenlabs · documented-format-literalMust redactT1 · Provider-documentedRedacted
elevenlabs-api-key-stripe-shaped-twincross-provider · prefix-near-missMust not flagT2 · Tool-corroborated · twinQuiet
elevenlabs-api-key-stripe-test-shaped-twincross-provider · prefix-near-missMust not flagT2 · Tool-corroborated · twinQuiet
elevenlabs-api-key-ak-prefix-twinelevenlabs · prefix-near-missMust not flagT2 · Tool-corroborated · twinQuiet
elevenlabs-api-key-docs-ellipsis-placeholderelevenlabs · documentation-placeholderMust not flagT3 · Project policyQuiet
elevenlabs-api-key-embedded-leading-twinelevenlabs · boundary-violationMust not flagT2 · Tool-corroborated · twinQuiet
elevenlabs-api-key-env-reference-referenceelevenlabs · templated-referenceMust not flagT3 · Project policyQuiet
elevenlabs-api-key-hyphen-prefix-twinelevenlabs · prefix-near-missMust not flagT2 · Tool-corroborated · twinQuiet
elevenlabs-api-key-key-hint-public-idelevenlabs · public-identifierMust not flagT2 · Tool-corroboratedQuiet
elevenlabs-api-key-key-id-public-idelevenlabs · public-identifierMust not flagT2 · Tool-corroboratedQuiet
elevenlabs-api-key-label-proseelevenlabs · benign-lookalikeMust not flagT3 · Project policyQuiet
elevenlabs-api-key-long-body-twinelevenlabs · unsettled-evidence-inputPending reviewT0 · Pending · twinUnscored
elevenlabs-api-key-maskelevenlabs · benign-lookalikeMust not flagT3 · Project policyQuiet
elevenlabs-api-key-masked-stars-placeholderelevenlabs · documentation-placeholderMust not flagT3 · Project policyQuiet
elevenlabs-api-key-missing-underscore-twinelevenlabs · prefix-near-missMust not flagT2 · Tool-corroborated · twinQuiet
elevenlabs-api-key-non-hex-body-twinelevenlabs · unsettled-evidence-inputPending reviewT0 · Pending · twinUnscored
elevenlabs-api-key-pk-prefix-twinelevenlabs · prefix-near-missMust not flagT2 · Tool-corroborated · twinQuiet
elevenlabs-api-key-prefix-onlyelevenlabs · benign-lookalikeMust not flagT2 · Tool-corroboratedQuiet
elevenlabs-api-key-referenceelevenlabs · benign-lookalikeMust not flagT3 · Project policyQuiet
elevenlabs-api-key-residency-hosts-proseelevenlabs · prose-mentionMust not flagT3 · Project policyQuiet
elevenlabs-api-key-short-bodyelevenlabs · benign-lookalikeMust not flagT2 · Tool-corroboratedQuiet
elevenlabs-api-key-short-body-twinelevenlabs · unsettled-evidence-inputPending reviewT0 · Pending · twinUnscored
elevenlabs-api-key-unprefixed-hex-near-misselevenlabs · format-near-missMust not flagT2 · Tool-corroboratedQuiet
elevenlabs-api-key-voice-id-public-idelevenlabs · public-identifierMust not flagT2 · Tool-corroboratedQuiet
elevenlabs-api-key-your-api-key-placeholderelevenlabs · documentation-placeholderMust not flagT3 · Project policyQuiet

Sources

Researched 2026-09-27.

Documentation and code

  • github.com/elevenlabs/elevenlabs-python/blob/main/src/elevenlabs/speech_engine/server.py
  • elevenlabs.io/docs/api-reference/authentication
  • github.com/elevenlabs/elevenlabs-python/blob/1b45413e916fda868341ad48225c4b7211017849/src/elevenlabs/speech_engine/server.py
  • github.com/elevenlabs/elevenlabs-python/blob/fd6d5c29f7d22402420c17b27968f9c861f1b394/src/elevenlabs/speech_engine/resource.py
  • github.com/elevenlabs/elevenlabs-js/blob/a46177b4888e542efa8ae2ae3b6bd68b6a0979f4/src/wrapper/speech-engine/SpeechEngineResource.ts