redact-secret · Report
OTP seed
Base32 secret parameter of an otpauth:// key URI.
Research record
3 events in the review history: 2 observed, 1 reviewed. Latest: observed on 2026-10-03 by automation, project maintainer. Project-maintained review is not independent validation. The family record at this release.
Format
What it looks like
Shape not recorded.
Format facts
Provider documented ·
mutable-property-source· current · observed 2026-09-20Documentation for the one property varied in legacy twin fixtures (Key URI format, secret parameter): secret is REQUIRED and Base32 per RFC 3548 with padding omitted; no length is stated
- github.com/google/google-authenticator/wiki/Key-Uri-Formatprovider-documentation · last read 2026-10-03 · latest outcome read · supports secret is REQUIRED and Base32 per RFC 3548 with padding omitted; no length is stated
Unresolved ·
listed-references· current · observed 2026-09-20The legacy contract lists 1 reference without stating which property each supports.
- github.com/google/google-authenticator/wiki/Key-Uri-Formatprovider-documentation · last read 2026-10-03 · latest outcome read · supports Listed as a reference by the legacy contract
Project policy ·
legacy-contract-tier· current · observed 2026-09-20The legacy contract records this grammar as project masking policy (tier T3), not as a provider format.
Source not recorded.
Project policy ·
dossier-research· current · observed 2026-09-26Legacy dossier research (verdict ready, tier T3) cited 2 sources; the dossier does not attribute sources to individual properties.
- github.com/google/google-authenticator/wiki/Key-Uri-Formatprovider-documentation · last read 2026-10-03 · latest outcome read · supports Cited by the legacy dossier research for this family
- redact-secret/redact-secret @ 8b6a5fde52ecb4dfce13f09c7a947062d21483c7: docs/audits/evidence/652/README.mdproject-research-note · last read 2026-09-26 · latest outcome read · supports Final research evidence recorded by the legacy dossier
Open questions
No open question is recorded for this revision.
Benchmark dossier notes
- Shape
otpauth://TYPE/LABEL?PARAMETERSwith TYPEhotportotpand a REQUIREDsecretparameter in Base32 (alphabetA-Z,2-7,=padding). Core requires at least 16 characters and uppercase; the RFC 4226 §4 R6 floor is 128 bits and Google states no length.- Basis
- Google's Key Uri Format wiki (Google Code Archive copy) documents the envelope and Base32 secret; no RFC defines
otpauth. The boundary is project policy, not a provider grammar, so whether Google counts as the provider of a generic seed (the #652 condition) does not decide the verdict. The #650 record listsotpauth-uriamong the RFC-position contracts that "are T3 today", and benchmarks#365 and core #857 with the accepted decisiondocs/decisions/2026-09-26-qualify-bounded-t3-credential-policy.mdkeep it T3 with the 16-character floor, case rule, padding rule and first-parameter behaviour as project choices; the support matrix reads it T3. Provider-grammar research does not apply, so the verdict isreadyat T3. - Issuance
- not applicable.
- Contract in core
- detector-families.md; #652 record.
In this benchmark
- Fixtures
- 24
- Left readable
- 0
- Redacted too much
- 0
- False alarms
- 0
24 fixtures: 15 must stay quiet, 9 record project policy. See every row
| Evidence level | Fixtures | Left readable | Too much | False alarms |
|---|---|---|---|---|
| T1Provider-documented | 8 | 0 | 0 | 0 |
| T3Project policy | 16 | 0 | 0 | 0 |
Every scanner on the same fixtures
In run order. Counts are what each scanner recorded on this family's fixtures, whichever rules it has; a scanner with no rule for the family has nothing to report on it.
| Scanner | Fixtures | Left readable | Too much | False alarms |
|---|---|---|---|---|
| flare-redactRuntime library · 1.6.1 · Published npm package · secrets-only (pii, generic_assignment disabled) · JavaScript engineNo rule maps to it | 24 | 9 | 0 | 0 |
| gitleaksRepository scanner · 8.30.1 · Directory scan · default rulesNo rule maps to it | 24 | 9 | 0 | 0 |
| redact-secretProduct measured here · 0.1.0-beta.14 · Published npm package · default detectors1 detector mapped | 24 | 0 | 0 | 0 |
| trufflehogRepository scanner · 3.97.4 · Filesystem scan · verification disabledNo rule maps to it | 24 | 9 | 0 | 0 |
Looks like it, but isn't
- Collisions
apple-otpauth://and%3Dpadding are recorded false-negative variants.
Scanner rules for this family
No peer rule maps to this family
None of the reviewed peer scanners has a rule that can match a credential of this family.
None mapped
Fixtures in this family
| Fixture | Kind and evidence | redact-secret |
|---|---|---|
otpauth-uri-hotp-baregeneric · documented-format-literal | Project policyT3 · Project policy | Redacted |
otpauth-uri-hotp-quotedgeneric · documented-format-literal | Project policyT3 · Project policy | Redacted |
otpauth-uri-hotp-unicode-crlfgeneric · documented-format-literal | Project policyT3 · Project policy | Redacted |
otpauth-uri-query-ordergeneric · otp-seeds-in-otpauth-uris | Project policyT3 · Project policy | Redacted |
otpauth-uri-quoted-configgeneric · otp-seeds-in-otpauth-uris | Project policyT3 · Project policy | Redacted |
otpauth-uri-totp-baregeneric · documented-format-literal | Project policyT3 · Project policy | Redacted |
otpauth-uri-totp-quotedgeneric · documented-format-literal | Project policyT3 · Project policy | Redacted |
otpauth-uri-totp-unicode-crlfgeneric · documented-format-literal | Project policyT3 · Project policy | Redacted |
otpauth-uri-unicode-crlfgeneric · otp-seeds-in-otpauth-uris | Project policyT3 · Project policy | Redacted |
otpauth-uri-duplicate-first-controlgeneric · otpauth-seed-lookalikes | Must not flagT3 · Project policy | Quiet |
otpauth-uri-hotp-bare-twingeneric · wrong-alphabet | Must not flagT1 · Provider-documented · twin | Quiet |
otpauth-uri-hotp-quoted-twingeneric · wrong-alphabet | Must not flagT1 · Provider-documented · twin | Quiet |
otpauth-uri-hotp-unicode-crlf-twingeneric · wrong-alphabet | Must not flagT1 · Provider-documented · twin | Quiet |
otpauth-uri-label-prosegeneric · benign-lookalike | Must not flagT3 · Project policy | Quiet |
otpauth-uri-lowercase-controlgeneric · otpauth-seed-lookalikes | Must not flagT3 · Project policy | Quiet |
otpauth-uri-maskgeneric · benign-lookalike | Must not flagT3 · Project policy | Quiet |
otpauth-uri-missing-secretgeneric · benign-lookalike | Must not flagT1 · Provider-documented | Quiet |
otpauth-uri-query-order-twingeneric · wrong-alphabet | Must not flagT1 · Provider-documented · twin | Quiet |
otpauth-uri-referencegeneric · benign-lookalike | Must not flagT3 · Project policy | Quiet |
otpauth-uri-reference-controlgeneric · otpauth-seed-lookalikes | Must not flagT3 · Project policy | Quiet |
otpauth-uri-short-secretgeneric · benign-lookalike | Must not flagT3 · Project policy | Quiet |
otpauth-uri-totp-bare-twingeneric · wrong-alphabet | Must not flagT1 · Provider-documented · twin | Quiet |
otpauth-uri-totp-quoted-twingeneric · wrong-alphabet | Must not flagT1 · Provider-documented · twin | Quiet |
otpauth-uri-totp-unicode-crlf-twingeneric · wrong-alphabet | Must not flagT1 · Provider-documented · twin | Quiet |
Sources
Documentation and code
- github.com/google/google-authenticator/wiki/Key-Uri-Format
Research log
- redact-secret/redact-secret#857Research issue
- redact-secret/redact-secret-benchmarks#365Research issue
- redact-secret/redact-secret#652Research issue
- Final evidence, pinned to a commit/redact-secret/redact-secret/blob/8b6a5fde52ecb4dfce13f09c7a947062d21483c7/docs/audits/evidence/652/README.md