redact-secret · Report
Bearer credential
RFC 6750 Authorization: Bearer value; a transport scheme, not a provider-specific format.
Research record
5 events in the review history: 1 corrected, 3 observed, 1 reviewed. Latest: corrected on 2026-10-04 by automation, project maintainer. Project-maintained review is not independent validation. The family record at this release.
Format
What it looks like
Shape not recorded.
Format facts
Provider documented ·
mutable-property-source· current · observed 2026-09-20Documentation for the one property varied in legacy twin fixtures (RFC 6750 b64token ABNF): credentials = "Bearer" 1*SP b64token, with b64token limited to ALPHA / DIGIT / "-" / "." / "_" / "~" / "+" / "/" and trailing "="; no length is stated
- www.rfc-editor.org/rfc/rfc6750provider-documentation · last read 2026-10-03 · latest outcome read · supports credentials = "Bearer" 1*SP b64token, with b64token limited to ALPHA / DIGIT / "-" / "." / "_" / "~" / "+" / "/" and trailing "="; no length is stated · #section-2.1
Provider documented ·
field-scheme· current · observed 2026-09-22scheme: case-insensitive "Bearer" followed by one or more spaces; the identifying element sits outside the secret span
- www.rfc-editor.org/rfc/rfc6750provider-documentation · last read 2026-10-03 · latest outcome read · supports scheme: case-insensitive "Bearer" followed by one or more spaces; the identifying element sits outside the secret span · #section-2.1
- www.rfc-editor.org/rfc/rfc9110provider-documentation · last read 2026-10-03 · latest outcome read · supports scheme: case-insensitive "Bearer" followed by one or more spaces; the identifying element sits outside the secret span · #section-11.1
Provider documented ·
field-alphabet· current · observed 2026-09-22alphabet: b64token: ALPHA / DIGIT / - . _ ~ + / with trailing = only
- www.rfc-editor.org/rfc/rfc6750provider-documentation · last read 2026-10-03 · latest outcome read · supports alphabet: b64token: ALPHA / DIGIT / - . _ ~ + / with trailing = only · #section-2.1
Unresolved ·
field-length· current · observed 2026-09-22length: none stated; RFC 6750 §5.2 leaves the token contents unspecified
- www.rfc-editor.org/rfc/rfc6750provider-documentation · last read 2026-10-03 · latest outcome read · supports length: none stated; RFC 6750 §5.2 leaves the token contents unspecified · #section-5.2
Unresolved ·
listed-references· current · observed 2026-09-20The legacy contract lists 1 reference without stating which property each supports.
- www.rfc-editor.org/rfc/rfc6750provider-documentation · last read 2026-10-03 · latest outcome read · supports Listed as a reference by the legacy contract · #section-2.1
Project policy ·
legacy-contract-tier· current · observed 2026-09-20The legacy contract records this grammar as project masking policy (tier T3), not as a provider format.
Source not recorded.
Project policy ·
dossier-research· current · observed 2026-09-26Legacy dossier research (verdict ready, tier T3) cited 2 sources; the dossier does not attribute sources to individual properties.
- redact-secret/redact-secret @ 8b6a5fde52ecb4dfce13f09c7a947062d21483c7: docs/audits/evidence/650/README.mdproject-research-note · last read 2026-09-26 · latest outcome read · supports Final research evidence recorded by the legacy dossier
- www.rfc-editor.org/rfc/rfc6750provider-documentation · last read 2026-10-03 · latest outcome read · supports Cited by the legacy dossier research for this family
Open questions
No open question is recorded for this revision.
Benchmark dossier notes
- Shape
- RFC 6750 §2.1: scheme keyword
Bearer(case-insensitive per RFC 9110), one or more spaces, thenb64token= letters, digits and-._~+/followed by trailing=padding. The keyword sits outside the secret span. §5.2 leaves the token's contents unspecified and no RFC states a length; core's 16-byte floor (12 under an explicitAuthorization:orProxy-Authorization:header), cap of two=and HTAB acceptance are project policy. - Basis
- carrier grammar only (RFC 6750, RFC 9110 §11.1, RFC 6749 §5.1). The #650 issue found no identifying element inside the span (history only). The boundary is project policy, not a provider grammar: the RFC 6750
b64tokenABNF is the carrier syntax and the floors, padding cap and free-text scope are project choices. Benchmarks #365 and core #857 freeze that contract, and the accepted decisiondocs/decisions/2026-09-26-qualify-bounded-t3-credential-policy.mdnames this family as one of fourT3/project-policyfamilies; the support matrix reads it T3. Provider-grammar research does not apply, so the verdict isreadyat T3. - Contract in core
- detector-families.md; #650 record.
In this benchmark
- Fixtures
- 52
- Left readable
- 2
- Redacted too much
- 0
- False alarms
- 0
52 fixtures: 3 expect a redaction, 33 must stay quiet, 16 record project policy. See every row
| Evidence level | Fixtures | Left readable | Too much | False alarms |
|---|---|---|---|---|
| T1Provider-documented | 10 | 2 | 0 | 0 |
| T3Project policy | 42 | 0 | 0 | 0 |
Every scanner on the same fixtures
In run order. Counts are what each scanner recorded on this family's fixtures, whichever rules it has; a scanner with no rule for the family has nothing to report on it.
| Scanner | Fixtures | Left readable | Too much | False alarms |
|---|---|---|---|---|
| flare-redactRuntime library · 1.6.1 · Published npm package · secrets-only (pii, generic_assignment disabled) · JavaScript engine1 rule targets it | 52 | 4 | 12 | 5 |
| gitleaksRepository scanner · 8.30.1 · Directory scan · default rules1 rule targets it | 52 | 17 | 0 | 1 |
| redact-secretProduct measured here · 0.1.0-beta.14 · Published npm package · default detectors1 detector mapped | 52 | 2 | 0 | 0 |
| trufflehogRepository scanner · 3.97.4 · Filesystem scan · verification disabledNo rule maps to it | 52 | 19 | 0 | 0 |
Looks like it, but isn't
- Collisions
- the value may be a JWT, a provider-prefixed key or an opaque string; providers' own families win when a prefix matches.
Scanner rules for this family
| Scanner | Rule | What the rule matches |
|---|---|---|
| flare-redact · rules 1.6.1 | bearer_token | Bearer + 8 or more characters |
| gitleaks · rules 8.30.1 | curl-auth-header | curl -H Authorization Bearer, Basic or Token value |
| openredaction · rules 1.1.5 | BEARER_TOKEN | Bearer + 20 or more characters |
No rule maps to this family in trufflehog.
Fixtures in this family
| Fixture | Kind and evidence | redact-secret |
|---|---|---|
bearer-token-in-postdata-paramshar-exports-authored · har-bearer-token-in-url-query-and-form-body-beside-removed-headers | Must redactT1 · Provider-documented | Left readable |
bearer-token-in-url-and-querystring-arrayhar-exports-authored · har-bearer-token-in-url-query-and-form-body-beside-removed-headers | Must redactT1 · Provider-documented | Left readable |
bearer-headerauthored-generic · early-filler-token-contexts | Project policyT3 · Project policy | Redacted |
bearer-token-authorization-headergeneric · bearer-credentials-in-authorization-headers | Project policyT3 · Project policy | Redacted |
bearer-token-authorization-header-twingeneric · wrong-length | Must not flagT3 · Project policy · twin | Quiet |
bearer-token-client-yamlgeneric · documented-format-literal | Project policyT3 · Project policy | Redacted |
bearer-token-curlgeneric · documented-format-literal | Project policyT3 · Project policy | Redacted |
bearer-token-fetchgeneric · documented-format-literal | Project policyT3 · Project policy | Redacted |
bearer-token-har-entrygeneric · documented-format-literal | Project policyT3 · Project policy | Redacted |
bearer-token-header-baregeneric · documented-format-literal | Project policyT3 · Project policy | Redacted |
bearer-token-header-bare-twingeneric · wrong-alphabet | Must not flagT1 · Provider-documented · twin | Quiet |
bearer-token-header-quotedgeneric · documented-format-literal | Project policyT3 · Project policy | Redacted |
bearer-token-header-quoted-twingeneric · wrong-alphabet | Must not flagT1 · Provider-documented · twin | Quiet |
bearer-token-header-unicode-crlfgeneric · documented-format-literal | Project policyT3 · Project policy | Redacted |
bearer-token-header-unicode-crlf-twingeneric · wrong-alphabet | Must not flagT1 · Provider-documented · twin | Quiet |
bearer-token-httpie-verbosegeneric · documented-format-literal | Project policyT3 · Project policy | Redacted |
bearer-token-lowercase-schemegeneric · documented-format-literal | Project policyT3 · Project policy | Redacted |
bearer-token-proxy-headergeneric · bearer-credentials-in-authorization-headers | Project policyT3 · Project policy | Redacted |
bearer-token-raw-requestgeneric · documented-format-literal | Project policyT3 · Project policy | Redacted |
bearer-token-request-loggeneric · documented-format-literal | Project policyT3 · Project policy | Redacted |
bearer-token-runbookgeneric · documented-format-literal | Project policyT3 · Project policy | Redacted |
bearer-token-workflow-stepgeneric · documented-format-literal | Project policyT3 · Project policy | Redacted |
bearer-token-your-access-token-placeholdergeneric · documentation-placeholder | Must not flagT3 · Project policy | Quiet |
bearer-token-in-postdata-text-percent-escapedhar-exports-authored · har-bearer-token-in-url-query-and-form-body-beside-removed-headers | Must redactT1 · Provider-documented | Redacted |
bearer-token-angle-token-placeholdergeneric · documentation-placeholder | Must not flagT3 · Project policy | Quiet |
bearer-token-challenge-near-missgeneric · format-near-miss | Must not flagT1 · Provider-documented | Quiet |
bearer-token-client-id-public-idgeneric · public-identifier | Must not flagT1 · Provider-documented | Quiet |
bearer-token-client-yaml-context-twingeneric · missing-context-marker | Must not flagT3 · Project policy · twin | Quiet |
bearer-token-command-substitution-referencegeneric · templated-reference | Must not flagT3 · Project policy | Quiet |
bearer-token-content-md5-encoded-valuegeneric · benign-encoded-value | Must not flagT3 · Project policy | Quiet |
bearer-token-curl-context-twingeneric · missing-context-marker | Must not flagT3 · Project policy · twin | Quiet |
bearer-token-etag-encoded-valuegeneric · benign-encoded-value | Must not flagT3 · Project policy | Quiet |
bearer-token-fetch-context-twingeneric · missing-context-marker | Must not flagT3 · Project policy · twin | Quiet |
bearer-token-har-entry-context-twingeneric · missing-context-marker | Must not flagT3 · Project policy · twin | Quiet |
bearer-token-httpie-verbose-context-twingeneric · missing-context-marker | Must not flagT3 · Project policy · twin | Quiet |
bearer-token-label-prosegeneric · benign-lookalike | Must not flagT3 · Project policy | Quiet |
bearer-token-lowercase-scheme-context-twingeneric · missing-context-marker | Must not flagT3 · Project policy · twin | Quiet |
bearer-token-maskgeneric · benign-lookalike | Must not flagT3 · Project policy | Quiet |
bearer-token-missing-valuegeneric · benign-lookalike | Must not flagT1 · Provider-documented | Quiet |
bearer-token-ordinary-prosegeneric · benign-lookalike | Must not flagT3 · Project policy | Quiet |
bearer-token-postman-variable-referencegeneric · templated-reference | Must not flagT3 · Project policy | Quiet |
bearer-token-raw-request-context-twingeneric · missing-context-marker | Must not flagT3 · Project policy · twin | Quiet |
bearer-token-redacted-placeholdergeneric · documentation-placeholder | Must not flagT3 · Project policy | Quiet |
bearer-token-referencegeneric · benign-lookalike | Must not flagT3 · Project policy | Quiet |
bearer-token-reference-variable-reference-in-credential-positiongeneric · variable-reference-in-credential-position | Must not flagT3 · Project policy | Quiet |
bearer-token-request-id-public-idgeneric · public-identifier | Must not flagT3 · Project policy | Quiet |
bearer-token-request-log-context-twingeneric · missing-context-marker | Must not flagT3 · Project policy · twin | Quiet |
bearer-token-rfc-note-prosegeneric · prose-mention | Must not flagT3 · Project policy | Quiet |
bearer-token-runbook-context-twingeneric · missing-context-marker | Must not flagT3 · Project policy · twin | Quiet |
bearer-token-token-type-only-near-missgeneric · format-near-miss | Must not flagT1 · Provider-documented | Quiet |
Sources
Documentation and code
- www.rfc-editor.org/rfc/rfc6750
Research log
- redact-secret/redact-secret#857Research issue
- redact-secret/redact-secret-benchmarks#365Research issue
- redact-secret/redact-secret#650Research issue
- Final evidence, pinned to a commit/redact-secret/redact-secret/blob/8b6a5fde52ecb4dfce13f09c7a947062d21483c7/docs/audits/evidence/650/README.md