Skip to content
Benchmarks

redact-secret · Report

OTP seed

Base32 secret parameter of an otpauth:// key URI.

  • Not provider-specific
  • Detectors: otpauth-uri
  • Run 2026-10-07
  • Mode published · redact-secret 0.1.0-beta.14
  • Dossier verdictReady
  • Dossier evidence levelT3 · Project policy
  • Dossier researched2026-09-26

Research record

From credential-evidence snapshot-2026.10.06.4 · records at 77ce761 · schema 1.8.0. It describes the research on the format, not what any scanner or the product does, and not a support status.
  • Review stateDraft, not reviewed
  • Format revision1 · current
  • ResearchResearched
  • Researched2026-09-26

3 events in the review history: 2 observed, 1 reviewed. Latest: observed on 2026-10-03 by automation, project maintainer. Project-maintained review is not independent validation. The family record at this release.

Format

Provider format research from credential-evidence snapshot-2026.10.06.4 · records at 77ce761 · schema 1.8.0.

What it looks like

Shape not recorded.

Format facts

  • Provider documented · mutable-property-source · current · observed 2026-09-20

    Documentation for the one property varied in legacy twin fixtures (Key URI format, secret parameter): secret is REQUIRED and Base32 per RFC 3548 with padding omitted; no length is stated

  • Unresolved · listed-references · current · observed 2026-09-20

    The legacy contract lists 1 reference without stating which property each supports.

  • Project policy · legacy-contract-tier · current · observed 2026-09-20

    The legacy contract records this grammar as project masking policy (tier T3), not as a provider format.

    Source not recorded.

  • Project policy · dossier-research · current · observed 2026-09-26

    Legacy dossier research (verdict ready, tier T3) cited 2 sources; the dossier does not attribute sources to individual properties.

Open questions

No open question is recorded for this revision.

Benchmark dossier notes

From the provider dossier, as written. The evidence level above says how well the format is backed; a fact the dossier does not record is not shown.
Shape
otpauth://TYPE/LABEL?PARAMETERS with TYPE hotp or totp and a REQUIRED secret parameter in Base32 (alphabet A-Z, 2-7, = padding). Core requires at least 16 characters and uppercase; the RFC 4226 §4 R6 floor is 128 bits and Google states no length.
Basis
Google's Key Uri Format wiki (Google Code Archive copy) documents the envelope and Base32 secret; no RFC defines otpauth. The boundary is project policy, not a provider grammar, so whether Google counts as the provider of a generic seed (the #652 condition) does not decide the verdict. The #650 record lists otpauth-uri among the RFC-position contracts that "are T3 today", and benchmarks#365 and core #857 with the accepted decision docs/decisions/2026-09-26-qualify-bounded-t3-credential-policy.md keep it T3 with the 16-character floor, case rule, padding rule and first-parameter behaviour as project choices; the support matrix reads it T3. Provider-grammar research does not apply, so the verdict is ready at T3.
Issuance
not applicable.

In this benchmark

Fixture rows on the current run. Counts are for redact-secret in published · redact-secret 0.1.0-beta.14 mode.
Fixtures
24
Left readable
0
Redacted too much
0
False alarms
0

24 fixtures: 15 must stay quiet, 9 record project policy. See every row

redact-secret fixture counts by evidence level
Evidence levelFixturesLeft readableToo muchFalse alarms
T1Provider-documented8000
T3Project policy16000

Every scanner on the same fixtures

In run order. Counts are what each scanner recorded on this family's fixtures, whichever rules it has; a scanner with no rule for the family has nothing to report on it.

Counts per scanner on this family's fixtures
ScannerFixturesLeft readableToo muchFalse alarms
flare-redactRuntime library · 1.6.1 · Published npm package · secrets-only (pii, generic_assignment disabled) · JavaScript engineNo rule maps to it24900
gitleaksRepository scanner · 8.30.1 · Directory scan · default rulesNo rule maps to it24900
redact-secretProduct measured here · 0.1.0-beta.14 · Published npm package · default detectors1 detector mapped24000
trufflehogRepository scanner · 3.97.4 · Filesystem scan · verification disabledNo rule maps to it24900

Looks like it, but isn't

Values the dossier records as resembling this credential without being one.
Collisions
apple-otpauth:// and %3D padding are recorded false-negative variants.

Scanner rules for this family

Mapped by hand (reviewed 2026-09-30) from each scanner's pinned rule file, never from what a scanner found on the fixtures.

No peer rule maps to this family

None of the reviewed peer scanners has a rule that can match a credential of this family.

None mapped

24 of 24 rows

Fixtures in this family

24 rows, redact-secret's outcome on each. Rows that need a look come first (0), then the rest in corpus order. Choose "Every scanner" to see each scanner's outcome for the same rows.
Fixtures in OTP seed
FixtureKind and evidenceredact-secret
otpauth-uri-hotp-baregeneric · documented-format-literalProject policyT3 · Project policyRedacted
otpauth-uri-hotp-quotedgeneric · documented-format-literalProject policyT3 · Project policyRedacted
otpauth-uri-hotp-unicode-crlfgeneric · documented-format-literalProject policyT3 · Project policyRedacted
otpauth-uri-query-ordergeneric · otp-seeds-in-otpauth-urisProject policyT3 · Project policyRedacted
otpauth-uri-quoted-configgeneric · otp-seeds-in-otpauth-urisProject policyT3 · Project policyRedacted
otpauth-uri-totp-baregeneric · documented-format-literalProject policyT3 · Project policyRedacted
otpauth-uri-totp-quotedgeneric · documented-format-literalProject policyT3 · Project policyRedacted
otpauth-uri-totp-unicode-crlfgeneric · documented-format-literalProject policyT3 · Project policyRedacted
otpauth-uri-unicode-crlfgeneric · otp-seeds-in-otpauth-urisProject policyT3 · Project policyRedacted
otpauth-uri-duplicate-first-controlgeneric · otpauth-seed-lookalikesMust not flagT3 · Project policyQuiet
otpauth-uri-hotp-bare-twingeneric · wrong-alphabetMust not flagT1 · Provider-documented · twinQuiet
otpauth-uri-hotp-quoted-twingeneric · wrong-alphabetMust not flagT1 · Provider-documented · twinQuiet
otpauth-uri-hotp-unicode-crlf-twingeneric · wrong-alphabetMust not flagT1 · Provider-documented · twinQuiet
otpauth-uri-label-prosegeneric · benign-lookalikeMust not flagT3 · Project policyQuiet
otpauth-uri-lowercase-controlgeneric · otpauth-seed-lookalikesMust not flagT3 · Project policyQuiet
otpauth-uri-maskgeneric · benign-lookalikeMust not flagT3 · Project policyQuiet
otpauth-uri-missing-secretgeneric · benign-lookalikeMust not flagT1 · Provider-documentedQuiet
otpauth-uri-query-order-twingeneric · wrong-alphabetMust not flagT1 · Provider-documented · twinQuiet
otpauth-uri-referencegeneric · benign-lookalikeMust not flagT3 · Project policyQuiet
otpauth-uri-reference-controlgeneric · otpauth-seed-lookalikesMust not flagT3 · Project policyQuiet
otpauth-uri-short-secretgeneric · benign-lookalikeMust not flagT3 · Project policyQuiet
otpauth-uri-totp-bare-twingeneric · wrong-alphabetMust not flagT1 · Provider-documented · twinQuiet
otpauth-uri-totp-quoted-twingeneric · wrong-alphabetMust not flagT1 · Provider-documented · twinQuiet
otpauth-uri-totp-unicode-crlf-twingeneric · wrong-alphabetMust not flagT1 · Provider-documented · twinQuiet

Sources

Researched 2026-09-26.

Documentation and code

  • github.com/google/google-authenticator/wiki/Key-Uri-Format

Research log