Skip to content
Benchmarks

redact-secret · Report

Bearer credential

RFC 6750 Authorization: Bearer value; a transport scheme, not a provider-specific format.

  • Not provider-specific
  • Detectors: bearer-token
  • Run 2026-10-07
  • Mode published · redact-secret 0.1.0-beta.14
  • Dossier verdictReady
  • Dossier evidence levelT3 · Project policy
  • Dossier researched2026-09-26

Research record

From credential-evidence snapshot-2026.10.06.4 · records at 77ce761 · schema 1.8.0. It describes the research on the format, not what any scanner or the product does, and not a support status.
  • Review stateDraft, not reviewed
  • Format revision1 · current
  • ResearchResearched
  • Researched2026-09-26

5 events in the review history: 1 corrected, 3 observed, 1 reviewed. Latest: corrected on 2026-10-04 by automation, project maintainer. Project-maintained review is not independent validation. The family record at this release.

Format

Provider format research from credential-evidence snapshot-2026.10.06.4 · records at 77ce761 · schema 1.8.0.

What it looks like

Shape not recorded.

Format facts

  • Provider documented · mutable-property-source · current · observed 2026-09-20

    Documentation for the one property varied in legacy twin fixtures (RFC 6750 b64token ABNF): credentials = "Bearer" 1*SP b64token, with b64token limited to ALPHA / DIGIT / "-" / "." / "_" / "~" / "+" / "/" and trailing "="; no length is stated

    • www.rfc-editor.org/rfc/rfc6750provider-documentation · last read 2026-10-03 · latest outcome read · supports credentials = "Bearer" 1*SP b64token, with b64token limited to ALPHA / DIGIT / "-" / "." / "_" / "~" / "+" / "/" and trailing "="; no length is stated · #section-2.1
  • Provider documented · field-scheme · current · observed 2026-09-22

    scheme: case-insensitive "Bearer" followed by one or more spaces; the identifying element sits outside the secret span

    • www.rfc-editor.org/rfc/rfc6750provider-documentation · last read 2026-10-03 · latest outcome read · supports scheme: case-insensitive "Bearer" followed by one or more spaces; the identifying element sits outside the secret span · #section-2.1
    • www.rfc-editor.org/rfc/rfc9110provider-documentation · last read 2026-10-03 · latest outcome read · supports scheme: case-insensitive "Bearer" followed by one or more spaces; the identifying element sits outside the secret span · #section-11.1
  • Provider documented · field-alphabet · current · observed 2026-09-22

    alphabet: b64token: ALPHA / DIGIT / - . _ ~ + / with trailing = only

    • www.rfc-editor.org/rfc/rfc6750provider-documentation · last read 2026-10-03 · latest outcome read · supports alphabet: b64token: ALPHA / DIGIT / - . _ ~ + / with trailing = only · #section-2.1
  • Unresolved · field-length · current · observed 2026-09-22

    length: none stated; RFC 6750 §5.2 leaves the token contents unspecified

    • www.rfc-editor.org/rfc/rfc6750provider-documentation · last read 2026-10-03 · latest outcome read · supports length: none stated; RFC 6750 §5.2 leaves the token contents unspecified · #section-5.2
  • Unresolved · listed-references · current · observed 2026-09-20

    The legacy contract lists 1 reference without stating which property each supports.

    • www.rfc-editor.org/rfc/rfc6750provider-documentation · last read 2026-10-03 · latest outcome read · supports Listed as a reference by the legacy contract · #section-2.1
  • Project policy · legacy-contract-tier · current · observed 2026-09-20

    The legacy contract records this grammar as project masking policy (tier T3), not as a provider format.

    Source not recorded.

  • Project policy · dossier-research · current · observed 2026-09-26

    Legacy dossier research (verdict ready, tier T3) cited 2 sources; the dossier does not attribute sources to individual properties.

Open questions

No open question is recorded for this revision.

Benchmark dossier notes

From the provider dossier, as written. The evidence level above says how well the format is backed; a fact the dossier does not record is not shown.
Shape
RFC 6750 §2.1: scheme keyword Bearer (case-insensitive per RFC 9110), one or more spaces, then b64token = letters, digits and -._~+/ followed by trailing = padding. The keyword sits outside the secret span. §5.2 leaves the token's contents unspecified and no RFC states a length; core's 16-byte floor (12 under an explicit Authorization: or Proxy-Authorization: header), cap of two = and HTAB acceptance are project policy.
Basis
carrier grammar only (RFC 6750, RFC 9110 §11.1, RFC 6749 §5.1). The #650 issue found no identifying element inside the span (history only). The boundary is project policy, not a provider grammar: the RFC 6750 b64token ABNF is the carrier syntax and the floors, padding cap and free-text scope are project choices. Benchmarks #365 and core #857 freeze that contract, and the accepted decision docs/decisions/2026-09-26-qualify-bounded-t3-credential-policy.md names this family as one of four T3 / project-policy families; the support matrix reads it T3. Provider-grammar research does not apply, so the verdict is ready at T3.

In this benchmark

Fixture rows on the current run. Counts are for redact-secret in published · redact-secret 0.1.0-beta.14 mode.
Fixtures
52
Left readable
2
Redacted too much
0
False alarms
0

52 fixtures: 3 expect a redaction, 33 must stay quiet, 16 record project policy. See every row

redact-secret fixture counts by evidence level
Evidence levelFixturesLeft readableToo muchFalse alarms
T1Provider-documented10200
T3Project policy42000

Every scanner on the same fixtures

In run order. Counts are what each scanner recorded on this family's fixtures, whichever rules it has; a scanner with no rule for the family has nothing to report on it.

Counts per scanner on this family's fixtures
ScannerFixturesLeft readableToo muchFalse alarms
flare-redactRuntime library · 1.6.1 · Published npm package · secrets-only (pii, generic_assignment disabled) · JavaScript engine1 rule targets it524125
gitleaksRepository scanner · 8.30.1 · Directory scan · default rules1 rule targets it521701
redact-secretProduct measured here · 0.1.0-beta.14 · Published npm package · default detectors1 detector mapped52200
trufflehogRepository scanner · 3.97.4 · Filesystem scan · verification disabledNo rule maps to it521900

Looks like it, but isn't

Values the dossier records as resembling this credential without being one.
Collisions
the value may be a JWT, a provider-prefixed key or an opaque string; providers' own families win when a prefix matches.

Scanner rules for this family

Mapped by hand (reviewed 2026-09-30) from each scanner's pinned rule file, never from what a scanner found on the fixtures.
Peer scanner rules that target this family
ScannerRuleWhat the rule matches
flare-redact · rules 1.6.1bearer_tokenBearer + 8 or more characters
gitleaks · rules 8.30.1curl-auth-headercurl -H Authorization Bearer, Basic or Token value
openredaction · rules 1.1.5BEARER_TOKENBearer + 20 or more characters

No rule maps to this family in trufflehog.

52 of 52 rows

Fixtures in this family

52 rows, redact-secret's outcome on each. Rows that need a look come first (2), then the rest in corpus order. Choose "Every scanner" to see each scanner's outcome for the same rows.
Fixtures in Bearer credential
FixtureKind and evidenceredact-secret
bearer-token-in-postdata-paramshar-exports-authored · har-bearer-token-in-url-query-and-form-body-beside-removed-headersMust redactT1 · Provider-documentedLeft readable
bearer-token-in-url-and-querystring-arrayhar-exports-authored · har-bearer-token-in-url-query-and-form-body-beside-removed-headersMust redactT1 · Provider-documentedLeft readable
bearer-headerauthored-generic · early-filler-token-contextsProject policyT3 · Project policyRedacted
bearer-token-authorization-headergeneric · bearer-credentials-in-authorization-headersProject policyT3 · Project policyRedacted
bearer-token-authorization-header-twingeneric · wrong-lengthMust not flagT3 · Project policy · twinQuiet
bearer-token-client-yamlgeneric · documented-format-literalProject policyT3 · Project policyRedacted
bearer-token-curlgeneric · documented-format-literalProject policyT3 · Project policyRedacted
bearer-token-fetchgeneric · documented-format-literalProject policyT3 · Project policyRedacted
bearer-token-har-entrygeneric · documented-format-literalProject policyT3 · Project policyRedacted
bearer-token-header-baregeneric · documented-format-literalProject policyT3 · Project policyRedacted
bearer-token-header-bare-twingeneric · wrong-alphabetMust not flagT1 · Provider-documented · twinQuiet
bearer-token-header-quotedgeneric · documented-format-literalProject policyT3 · Project policyRedacted
bearer-token-header-quoted-twingeneric · wrong-alphabetMust not flagT1 · Provider-documented · twinQuiet
bearer-token-header-unicode-crlfgeneric · documented-format-literalProject policyT3 · Project policyRedacted
bearer-token-header-unicode-crlf-twingeneric · wrong-alphabetMust not flagT1 · Provider-documented · twinQuiet
bearer-token-httpie-verbosegeneric · documented-format-literalProject policyT3 · Project policyRedacted
bearer-token-lowercase-schemegeneric · documented-format-literalProject policyT3 · Project policyRedacted
bearer-token-proxy-headergeneric · bearer-credentials-in-authorization-headersProject policyT3 · Project policyRedacted
bearer-token-raw-requestgeneric · documented-format-literalProject policyT3 · Project policyRedacted
bearer-token-request-loggeneric · documented-format-literalProject policyT3 · Project policyRedacted
bearer-token-runbookgeneric · documented-format-literalProject policyT3 · Project policyRedacted
bearer-token-workflow-stepgeneric · documented-format-literalProject policyT3 · Project policyRedacted
bearer-token-your-access-token-placeholdergeneric · documentation-placeholderMust not flagT3 · Project policyQuiet
bearer-token-in-postdata-text-percent-escapedhar-exports-authored · har-bearer-token-in-url-query-and-form-body-beside-removed-headersMust redactT1 · Provider-documentedRedacted
bearer-token-angle-token-placeholdergeneric · documentation-placeholderMust not flagT3 · Project policyQuiet
bearer-token-challenge-near-missgeneric · format-near-missMust not flagT1 · Provider-documentedQuiet
bearer-token-client-id-public-idgeneric · public-identifierMust not flagT1 · Provider-documentedQuiet
bearer-token-client-yaml-context-twingeneric · missing-context-markerMust not flagT3 · Project policy · twinQuiet
bearer-token-command-substitution-referencegeneric · templated-referenceMust not flagT3 · Project policyQuiet
bearer-token-content-md5-encoded-valuegeneric · benign-encoded-valueMust not flagT3 · Project policyQuiet
bearer-token-curl-context-twingeneric · missing-context-markerMust not flagT3 · Project policy · twinQuiet
bearer-token-etag-encoded-valuegeneric · benign-encoded-valueMust not flagT3 · Project policyQuiet
bearer-token-fetch-context-twingeneric · missing-context-markerMust not flagT3 · Project policy · twinQuiet
bearer-token-har-entry-context-twingeneric · missing-context-markerMust not flagT3 · Project policy · twinQuiet
bearer-token-httpie-verbose-context-twingeneric · missing-context-markerMust not flagT3 · Project policy · twinQuiet
bearer-token-label-prosegeneric · benign-lookalikeMust not flagT3 · Project policyQuiet
bearer-token-lowercase-scheme-context-twingeneric · missing-context-markerMust not flagT3 · Project policy · twinQuiet
bearer-token-maskgeneric · benign-lookalikeMust not flagT3 · Project policyQuiet
bearer-token-missing-valuegeneric · benign-lookalikeMust not flagT1 · Provider-documentedQuiet
bearer-token-ordinary-prosegeneric · benign-lookalikeMust not flagT3 · Project policyQuiet
bearer-token-postman-variable-referencegeneric · templated-referenceMust not flagT3 · Project policyQuiet
bearer-token-raw-request-context-twingeneric · missing-context-markerMust not flagT3 · Project policy · twinQuiet
bearer-token-redacted-placeholdergeneric · documentation-placeholderMust not flagT3 · Project policyQuiet
bearer-token-referencegeneric · benign-lookalikeMust not flagT3 · Project policyQuiet
bearer-token-reference-variable-reference-in-credential-positiongeneric · variable-reference-in-credential-positionMust not flagT3 · Project policyQuiet
bearer-token-request-id-public-idgeneric · public-identifierMust not flagT3 · Project policyQuiet
bearer-token-request-log-context-twingeneric · missing-context-markerMust not flagT3 · Project policy · twinQuiet
bearer-token-rfc-note-prosegeneric · prose-mentionMust not flagT3 · Project policyQuiet
bearer-token-runbook-context-twingeneric · missing-context-markerMust not flagT3 · Project policy · twinQuiet
bearer-token-token-type-only-near-missgeneric · format-near-missMust not flagT1 · Provider-documentedQuiet

Sources

Researched 2026-09-26.

Documentation and code

Research log