Skip to content
Benchmarks

redact-secret · Report

API key (no evidenced shape)

No identifying prefix, length or alphabet is evidenced; only the key id, team id and user id are documented, as UUIDs.

  • Exa
  • Detectors: none mapped
  • Run 2026-10-07
  • Mode published · redact-secret 0.1.0-beta.14
  • Dossier verdictNot found
  • Dossier evidence levelT0 · Pending
  • Dossier researched2026-09-27
Beta.10 context-gated arrival family exa-api-key (#384, research redact-secret#787, product #868). T0: measures the keyword gate and the SDK-call-argument forms only; no value grammar is claimed and none is fabricated.

Research record

From credential-evidence snapshot-2026.10.06.4 · records at 77ce761 · schema 1.8.0. It describes the research on the format, not what any scanner or the product does, and not a support status.
  • Review stateDraft, not reviewed
  • Format revision1 · proposed, none current
  • ResearchNot found
  • Researched2026-09-27

What blocks the research

  • Documentation-gatedNo source states a prefix, length or alphabet for the secret; one issued key would show whether it is a UUID (checklist in

3 events in the review history: 2 observed, 1 reviewed. Latest: observed on 2026-09-27 by automation, project maintainer. Project-maintained review is not independent validation. The family record at this release.

Format

Provider format research from credential-evidence snapshot-2026.10.06.4 · records at 77ce761 · schema 1.8.0.

What it looks like

Shape not recorded.

Format facts

  • Provider documented · mutable-property-source · current · observed 2026-09-26

    Documentation for the one property varied in legacy twin fixtures (Team Management API key id, teamId and userId (format: uuid)): Exa documents the key id, the team id and the user id as UUIDs, and lists a key's id, name, rate limit and budget in its response with no field for the secret value. Context twins keep the UUID-shaped value and rename the assignment to one of those identifier names (EXA_KEY_ID, EXA_API_KEY_ID, EXA_TEAM_ID) or a request id, so silence follows from the documented identifier role

    • exa.ai/docs/reference/team-management/update-api-keyprovider-documentation · last read 2026-09-27 · latest outcome read · supports Exa documents the key id, the team id and the user id as UUIDs, and lists a key's id, name, rate limit and budget in its response with no field for the secret value. Context twins keep the UUID-shaped value and rename the assignment to one of those identifier names (EXA_KEY_ID, EXA_API_KEY_ID, EXA_TEAM_ID) or a request id, so silence follows from the documented identifier role
  • Unresolved · field-secret-shape · current · observed 2026-09-26

    secret-shape: no identifying prefix, length or alphabet is evidenced (Not claimed. A UUID-shaped carrier value is used only because one weak fragment suggests it.)

  • Provider documented · field-identifier-fields · current · observed 2026-09-26

    identifier-fields: key id, teamId and userId are UUIDs and public identifiers (Backs the id-like sibling twins.)

  • Provider documented · field-context · current · observed 2026-09-26

    context: EXA_API_KEY, the api_key constructor argument, x-api-key or Authorization: Bearer, and the hosted-MCP exaApiKey query parameter

  • Unresolved · field-service-keys · current · observed 2026-09-26

    service-keys: service keys created through the Team Management API are a second credential class of unknown shape (Not claimed.)

  • Unresolved · field-exa-prefix · current · observed 2026-09-26

    exa-prefix: an exa- prefix (Not evidence; not asserted either way.)

  • Unresolved · listed-references · current · observed 2026-09-26

    The legacy contract lists 6 references without stating which property each supports.

  • Unresolved · legacy-contract-tier · current · observed 2026-09-26

    The legacy contract records no adequate evidence for a grammar (tier T0).

    Source not recorded.

  • Unresolved · dossier-research · current · observed 2026-09-27

    Legacy dossier research (verdict not-found, tier T0) cited 0 sources; the dossier does not attribute sources to individual properties.

    Source not recorded.

  • Unresolved · taxonomy-sources · current · observed 2026-09-27

    The legacy taxonomy lists 2 sources for this family. The taxonomy records no date; the dossier researchedAt is used as the observed-at date.

Open questions

No open question is recorded for this revision.

Benchmark dossier notes

From the provider dossier, as written. The evidence level above says how well the format is backed; a fact the dossier does not record is not shown.
Shape
none established. The Team Management API documents the key id, teamId and userId as UUIDs, but the create response has no secret field and the docs do not say whether the secret equals the id. One weak code-search measurement found a UUID-shaped value in 1 of 10 assignments, and 0 of 15 in a second pass; that is not a distribution. A claimed exa- prefix came from an untraceable search summary and is contradicted by the provider pages.
Basis
none. No provider page, staff statement, SDK code or scanner rule states a secret grammar. exa-py does no validation. No scanner has an Exa rule (tree and path checks; rule contents inside multi-rule files were not read). The Exa docs, including the update key reference, document only the identifiers.
Issuance
not attempted. The #787 checklist asks for total length, whether the secret matches the UUID layout, whether it differs from the key id, and whether a service key has the same shape.
Contract in core
none. #868 did not land Exa; it stays with generic-token, and its SDK keyword-argument form is read by generic-token since #866. A positional Exa("...") stays out. See detector-families.md, section Keyword-gated provider keys (#868).

In this benchmark

Fixture rows on the current run. Counts are for redact-secret in published · redact-secret 0.1.0-beta.14 mode.
Fixtures
30
Left readable
2
Redacted too much
0
False alarms
0

30 fixtures: 22 must stay quiet, 8 record project policy. See every row

redact-secret fixture counts by evidence level
Evidence levelFixturesLeft readableToo muchFalse alarms
T2Tool-corroborated7000
T3Project policy23200

Every scanner on the same fixtures

In run order. Counts are what each scanner recorded on this family's fixtures, whichever rules it has; a scanner with no rule for the family has nothing to report on it.

Counts per scanner on this family's fixtures
ScannerFixturesLeft readableToo muchFalse alarms
flare-redactRuntime library · 1.6.1 · Published npm package · secrets-only (pii, generic_assignment disabled) · JavaScript engineNo rule maps to it30800
gitleaksRepository scanner · 8.30.1 · Directory scan · default rulesNo rule maps to it30201
redact-secretProduct measured here · 0.1.0-beta.14 · Published npm package · default detectorsNo detector mapped30200
trufflehogRepository scanner · 3.97.4 · Filesystem scan · verification disabledNo rule maps to it30800

Benchmark dossier questions

Things the sources do not settle. They are listed so nobody reads them as settled.
Blocked by
No source states a prefix, length or alphabet for the secret; one issued key would show whether it is a UUID (checklist in

Looks like it, but isn't

Values the dossier records as resembling this credential without being one.
Collisions
every UUID in Exa responses and logs (key id, team id, user id, request ids) shares the possible shape, so a bare-UUID rule would be unusable. Placeholders your-api-key and YOUR-EXA-API-KEY are benign.

Scanner rules for this family

Mapped by hand (reviewed 2026-09-30) from each scanner's pinned rule file, never from what a scanner found on the fixtures.

No peer rule maps to this family

None of the reviewed peer scanners has a rule that can match a credential of this family.

None mapped

30 of 30 rows

Fixtures in this family

30 rows, redact-secret's outcome on each. Rows that need a look come first (2), then the rest in corpus order. Choose "Every scanner" to see each scanner's outcome for the same rows.
Fixtures in API key (no evidenced shape)
FixtureKind and evidenceredact-secret
exa-api-key-js-positionalexa · documented-format-literalProject policyT3 · Project policyLeft readable
exa-api-key-python-positionalexa · documented-format-literalProject policyT3 · Project policyLeft readable
exa-api-key-curl-x-api-keyexa · documented-format-literalProject policyT3 · Project policyRedacted
exa-api-key-dotenvexa · documented-format-literalProject policyT3 · Project policyRedacted
exa-api-key-exportexa · documented-format-literalProject policyT3 · Project policyRedacted
exa-api-key-hosted-mcp-queryexa · documented-format-literalProject policyT3 · Project policyRedacted
exa-api-key-langchain-kwargexa · documented-format-literalProject policyT3 · Project policyRedacted
exa-api-key-other-host-twinexa · missing-context-markerMust not flagT3 · Project policy · twinQuiet
exa-api-key-python-kwargexa · documented-format-literalProject policyT3 · Project policyRedacted
exa-api-key-angle-key-placeholderexa · documentation-placeholderMust not flagT3 · Project policyQuiet
exa-api-key-api-key-id-export-twinexa · missing-context-markerMust not flagT3 · Project policy · twinQuiet
exa-api-key-bare-in-prose-near-missexa · format-near-missMust not flagT2 · Tool-corroboratedQuiet
exa-api-key-bare-line-near-missexa · format-near-missMust not flagT2 · Tool-corroboratedQuiet
exa-api-key-bearer-docs-proseexa · prose-mentionMust not flagT3 · Project policyQuiet
exa-api-key-content-length-setting-near-missexa · format-near-missMust not flagT2 · Tool-corroboratedQuiet
exa-api-key-docs-ctor-placeholderexa · documentation-placeholderMust not flagT3 · Project policyQuiet
exa-api-key-env-reference-referenceexa · templated-referenceMust not flagT3 · Project policyQuiet
exa-api-key-key-id-env-twinexa · missing-context-markerMust not flagT3 · Project policy · twinQuiet
exa-api-key-model-id-public-idexa · public-identifierMust not flagT2 · Tool-corroboratedQuiet
exa-api-key-python-environ-referenceexa · templated-referenceMust not flagT3 · Project policyQuiet
exa-api-key-quickstart-key-placeholderexa · documentation-placeholderMust not flagT3 · Project policyQuiet
exa-api-key-request-id-query-twinexa · missing-context-markerMust not flagT3 · Project policy · twinQuiet
exa-api-key-request-uuid-public-idexa · public-identifierMust not flagT2 · Tool-corroboratedQuiet
exa-api-key-sha256-digest-encoded-valueexa · benign-encoded-valueMust not flagT2 · Tool-corroboratedQuiet
exa-api-key-team-id-kwarg-twinexa · missing-context-markerMust not flagT3 · Project policy · twinQuiet
exa-api-key-team-management-ids-public-idexa · public-identifierMust not flagT2 · Tool-corroboratedQuiet
exa-api-key-unrelated-js-positional-twinexa · missing-context-markerMust not flagT3 · Project policy · twinQuiet
exa-api-key-unrelated-python-ctor-twinexa · missing-context-markerMust not flagT3 · Project policy · twinQuiet
exa-api-key-unrelated-python-positional-twinexa · missing-context-markerMust not flagT3 · Project policy · twinQuiet
exa-api-key-your-key-here-placeholderexa · documentation-placeholderMust not flagT3 · Project policyQuiet

Sources

Researched 2026-09-27.

Documentation and code