redact-secret · Report
API key (no evidenced shape)
No identifying prefix, length or alphabet is evidenced; only the key id, team id and user id are documented, as UUIDs.
Research record
What blocks the research
- Documentation-gatedNo source states a prefix, length or alphabet for the secret; one issued key would show whether it is a UUID (checklist in
3 events in the review history: 2 observed, 1 reviewed. Latest: observed on 2026-09-27 by automation, project maintainer. Project-maintained review is not independent validation. The family record at this release.
Format
What it looks like
Shape not recorded.
Format facts
Provider documented ·
mutable-property-source· current · observed 2026-09-26Documentation for the one property varied in legacy twin fixtures (Team Management API key id, teamId and userId (format: uuid)): Exa documents the key id, the team id and the user id as UUIDs, and lists a key's id, name, rate limit and budget in its response with no field for the secret value. Context twins keep the UUID-shaped value and rename the assignment to one of those identifier names (EXA_KEY_ID, EXA_API_KEY_ID, EXA_TEAM_ID) or a request id, so silence follows from the documented identifier role
- exa.ai/docs/reference/team-management/update-api-keyprovider-documentation · last read 2026-09-27 · latest outcome read · supports Exa documents the key id, the team id and the user id as UUIDs, and lists a key's id, name, rate limit and budget in its response with no field for the secret value. Context twins keep the UUID-shaped value and rename the assignment to one of those identifier names (EXA_KEY_ID, EXA_API_KEY_ID, EXA_TEAM_ID) or a request id, so silence follows from the documented identifier role
Unresolved ·
field-secret-shape· current · observed 2026-09-26secret-shape: no identifying prefix, length or alphabet is evidenced (Not claimed. A UUID-shaped carrier value is used only because one weak fragment suggests it.)
- github.com/exa-labs/exa-pyprovider-sdk-source · last read 2026-09-27 · latest outcome read · supports the SDK does no validation
- github.com/redact-secret/redact-secret/issues/787third-party-writeup · last read 2026-09-26 · latest outcome read · supports no provider, tool or community source states a shape
Provider documented ·
field-identifier-fields· current · observed 2026-09-26identifier-fields: key id, teamId and userId are UUIDs and public identifiers (Backs the id-like sibling twins.)
- exa.ai/docs/reference/team-management/update-api-keyprovider-documentation · last read 2026-09-27 · latest outcome read · supports format: uuid
- exa.ai/docs/reference/team-management/get-api-keyprovider-documentation · last read 2026-09-26 · latest outcome read · supports identifier-fields: key id, teamId and userId are UUIDs and public identifiers
Provider documented ·
field-context· current · observed 2026-09-26context: EXA_API_KEY, the api_key constructor argument, x-api-key or Authorization: Bearer, and the hosted-MCP exaApiKey query parameter
- github.com/exa-labs/exa-mcp-serverprovider-sdk-source · last read 2026-09-26 · latest outcome read · supports exaApiKey query, Bearer or x-api-key
- github.com/exa-labs/exa-pyprovider-sdk-source · last read 2026-09-27 · latest outcome read · supports reads EXA_API_KEY, sends x-api-key
Unresolved ·
field-service-keys· current · observed 2026-09-26service-keys: service keys created through the Team Management API are a second credential class of unknown shape (Not claimed.)
- exa.ai/docs/reference/team-management/get-api-keyprovider-documentation · last read 2026-09-26 · latest outcome read · supports service-keys: service keys created through the Team Management API are a second credential class of unknown shape
Unresolved ·
field-exa-prefix· current · observed 2026-09-26exa-prefix: an exa- prefix (Not evidence; not asserted either way.)
- github.com/redact-secret/redact-secret/issues/787third-party-writeup · last read 2026-09-26 · latest outcome read · supports row 8: an untraceable search-summary claim, contradicted by the provider docs
Unresolved ·
listed-references· current · observed 2026-09-26The legacy contract lists 6 references without stating which property each supports.
- exa.ai/docs/reference/team-management/get-api-keyprovider-documentation · last read 2026-09-26 · latest outcome read · supports Listed as a reference by the legacy contract
- exa.ai/docs/get-started/quickstartprovider-documentation · last read 2026-09-26 · latest outcome read · supports Listed as a reference by the legacy contract
- github.com/exa-labs/exa-mcp-serverprovider-sdk-source · last read 2026-09-26 · latest outcome read · supports Listed as a reference by the legacy contract
- github.com/exa-labs/exa-pyprovider-sdk-source · last read 2026-09-27 · latest outcome read · supports Listed as a reference by the legacy contract
- github.com/redact-secret/redact-secret/issues/787third-party-writeup · last read 2026-09-26 · latest outcome read · supports Listed as a reference by the legacy contract
- github.com/redact-secret/redact-secret/issues/868issue-or-discussion · last read 2026-09-26 · latest outcome read · supports Listed as a reference by the legacy contract
Unresolved ·
legacy-contract-tier· current · observed 2026-09-26The legacy contract records no adequate evidence for a grammar (tier T0).
Source not recorded.
Unresolved ·
dossier-research· current · observed 2026-09-27Legacy dossier research (verdict not-found, tier T0) cited 0 sources; the dossier does not attribute sources to individual properties.
Source not recorded.
Unresolved ·
taxonomy-sources· current · observed 2026-09-27The legacy taxonomy lists 2 sources for this family. The taxonomy records no date; the dossier researchedAt is used as the observed-at date.
- exa.ai/docs/reference/team-management/update-api-keyprovider-documentation · last read 2026-09-27 · latest outcome read · supports Listed as a source for this family in the legacy taxonomy
- github.com/exa-labs/exa-pyprovider-sdk-source · last read 2026-09-27 · latest outcome read · supports Listed as a source for this family in the legacy taxonomy
Open questions
No open question is recorded for this revision.
Benchmark dossier notes
- Shape
- none established. The Team Management API documents the key
id,teamIdanduserIdas UUIDs, but the create response has no secret field and the docs do not say whether the secret equals the id. One weak code-search measurement found a UUID-shaped value in 1 of 10 assignments, and 0 of 15 in a second pass; that is not a distribution. A claimedexa-prefix came from an untraceable search summary and is contradicted by the provider pages. - Basis
- none. No provider page, staff statement, SDK code or scanner rule states a secret grammar.
exa-pydoes no validation. No scanner has an Exa rule (tree and path checks; rule contents inside multi-rule files were not read). The Exa docs, including the update key reference, document only the identifiers. - Issuance
- not attempted. The #787 checklist asks for total length, whether the secret matches the UUID layout, whether it differs from the key id, and whether a service key has the same shape.
- Contract in core
- none. #868 did not land Exa; it stays with
generic-token, and its SDK keyword-argument form is read bygeneric-tokensince #866. A positionalExa("...")stays out. See detector-families.md, section Keyword-gated provider keys (#868).
In this benchmark
- Fixtures
- 30
- Left readable
- 2
- Redacted too much
- 0
- False alarms
- 0
30 fixtures: 22 must stay quiet, 8 record project policy. See every row
| Evidence level | Fixtures | Left readable | Too much | False alarms |
|---|---|---|---|---|
| T2Tool-corroborated | 7 | 0 | 0 | 0 |
| T3Project policy | 23 | 2 | 0 | 0 |
Every scanner on the same fixtures
In run order. Counts are what each scanner recorded on this family's fixtures, whichever rules it has; a scanner with no rule for the family has nothing to report on it.
| Scanner | Fixtures | Left readable | Too much | False alarms |
|---|---|---|---|---|
| flare-redactRuntime library · 1.6.1 · Published npm package · secrets-only (pii, generic_assignment disabled) · JavaScript engineNo rule maps to it | 30 | 8 | 0 | 0 |
| gitleaksRepository scanner · 8.30.1 · Directory scan · default rulesNo rule maps to it | 30 | 2 | 0 | 1 |
| redact-secretProduct measured here · 0.1.0-beta.14 · Published npm package · default detectorsNo detector mapped | 30 | 2 | 0 | 0 |
| trufflehogRepository scanner · 3.97.4 · Filesystem scan · verification disabledNo rule maps to it | 30 | 8 | 0 | 0 |
Benchmark dossier questions
- Blocked by
- No source states a prefix, length or alphabet for the secret; one issued key would show whether it is a UUID (checklist in
Looks like it, but isn't
- Collisions
- every UUID in Exa responses and logs (key id, team id, user id, request ids) shares the possible shape, so a bare-UUID rule would be unusable. Placeholders
your-api-keyandYOUR-EXA-API-KEYare benign.
Scanner rules for this family
No peer rule maps to this family
None of the reviewed peer scanners has a rule that can match a credential of this family.
None mapped
Fixtures in this family
| Fixture | Kind and evidence | redact-secret |
|---|---|---|
exa-api-key-js-positionalexa · documented-format-literal | Project policyT3 · Project policy | Left readable |
exa-api-key-python-positionalexa · documented-format-literal | Project policyT3 · Project policy | Left readable |
exa-api-key-curl-x-api-keyexa · documented-format-literal | Project policyT3 · Project policy | Redacted |
exa-api-key-dotenvexa · documented-format-literal | Project policyT3 · Project policy | Redacted |
exa-api-key-exportexa · documented-format-literal | Project policyT3 · Project policy | Redacted |
exa-api-key-hosted-mcp-queryexa · documented-format-literal | Project policyT3 · Project policy | Redacted |
exa-api-key-langchain-kwargexa · documented-format-literal | Project policyT3 · Project policy | Redacted |
exa-api-key-other-host-twinexa · missing-context-marker | Must not flagT3 · Project policy · twin | Quiet |
exa-api-key-python-kwargexa · documented-format-literal | Project policyT3 · Project policy | Redacted |
exa-api-key-angle-key-placeholderexa · documentation-placeholder | Must not flagT3 · Project policy | Quiet |
exa-api-key-api-key-id-export-twinexa · missing-context-marker | Must not flagT3 · Project policy · twin | Quiet |
exa-api-key-bare-in-prose-near-missexa · format-near-miss | Must not flagT2 · Tool-corroborated | Quiet |
exa-api-key-bare-line-near-missexa · format-near-miss | Must not flagT2 · Tool-corroborated | Quiet |
exa-api-key-bearer-docs-proseexa · prose-mention | Must not flagT3 · Project policy | Quiet |
exa-api-key-content-length-setting-near-missexa · format-near-miss | Must not flagT2 · Tool-corroborated | Quiet |
exa-api-key-docs-ctor-placeholderexa · documentation-placeholder | Must not flagT3 · Project policy | Quiet |
exa-api-key-env-reference-referenceexa · templated-reference | Must not flagT3 · Project policy | Quiet |
exa-api-key-key-id-env-twinexa · missing-context-marker | Must not flagT3 · Project policy · twin | Quiet |
exa-api-key-model-id-public-idexa · public-identifier | Must not flagT2 · Tool-corroborated | Quiet |
exa-api-key-python-environ-referenceexa · templated-reference | Must not flagT3 · Project policy | Quiet |
exa-api-key-quickstart-key-placeholderexa · documentation-placeholder | Must not flagT3 · Project policy | Quiet |
exa-api-key-request-id-query-twinexa · missing-context-marker | Must not flagT3 · Project policy · twin | Quiet |
exa-api-key-request-uuid-public-idexa · public-identifier | Must not flagT2 · Tool-corroborated | Quiet |
exa-api-key-sha256-digest-encoded-valueexa · benign-encoded-value | Must not flagT2 · Tool-corroborated | Quiet |
exa-api-key-team-id-kwarg-twinexa · missing-context-marker | Must not flagT3 · Project policy · twin | Quiet |
exa-api-key-team-management-ids-public-idexa · public-identifier | Must not flagT2 · Tool-corroborated | Quiet |
exa-api-key-unrelated-js-positional-twinexa · missing-context-marker | Must not flagT3 · Project policy · twin | Quiet |
exa-api-key-unrelated-python-ctor-twinexa · missing-context-marker | Must not flagT3 · Project policy · twin | Quiet |
exa-api-key-unrelated-python-positional-twinexa · missing-context-marker | Must not flagT3 · Project policy · twin | Quiet |
exa-api-key-your-key-here-placeholderexa · documentation-placeholder | Must not flagT3 · Project policy | Quiet |
Sources
Documentation and code
- exa.ai/docs/reference/team-management/update-api-key
- github.com/exa-labs/exa-py
Research log
- redact-secret/redact-secret#787Research issue
- redact-secret/redact-secret#774Research issue
- redact-secret/redact-secret#868Research issue
- redact-secret/redact-secret#866Research issue
- redact-secret/redact-secret-benchmarks#384Research issue