Skip to content
Benchmarks

redact-secret · Report

Fine-grained personal access token

Repository- and permission-scoped PAT, prefixed github_pat_.

  • GitHub
  • Detectors: github-fine-grained-pat
  • Run 2026-10-07
  • Mode published · redact-secret 0.1.0-beta.14
  • Dossier verdictReady
  • Dossier evidence levelT2 · Tool-corroborated
  • Dossier researched2026-09-29
Named explicitly in issue #502 as a family the github-token detector does not cover: its pattern only matches the ghp_/gho_/ghu_/ghs_/ghr_ underscore-plus-36-character-body shape, which github_pat_ does not fit. Measured as the Beta.8 arrival family github-fine-grained-pat (#211, research #223): only the github_pat_ prefix is provider-documented; the 22 + _ + 59 body is community/tool evidence kept provisional, with no checksum or fixed 11 lead claimed. Scored as the arrival family github-fine-grained-pat (#730; docs/decisions/2026-09-24-score-arrival-families-by-finding-type.md): the product types it inside the shared github-token detector as github_fine_grained_personal_access_token, so its findings carry the arrival id and its status comes from its own contract, profile and ledger rows. github-fine-grained-pat is not a registry detector id.

Research record

From credential-evidence snapshot-2026.10.06.4 · records at 77ce761 · schema 1.8.0. It describes the research on the format, not what any scanner or the product does, and not a support status.
  • Review stateDraft, not reviewed
  • Format revision1 · current
  • ResearchResearched
  • Researched2026-09-29

What blocks the research

  • Issuance-gatedExact body length, underscore position, checksum and GHES body parity of github_pat_ tokens are not provider-documented; only an issued token or a provider statement would settle them.

4 events in the review history: 3 observed, 1 reviewed. Latest: observed on 2026-10-04 by automation, project maintainer. Project-maintained review is not independent validation. The family record at this release.

Format

Provider format research from credential-evidence snapshot-2026.10.06.4 · records at 77ce761 · schema 1.8.0.

What it looks like

Descriptive pattern
^github_pat_[A-Za-z0-9]{22}_[A-Za-z0-9]{59}$

Parts are shown as recorded. Evidence classes belong to the facts below; no class is assigned to a part.

Format facts

Open questions

  • github:fine-grained-personal-access-token@1#body-length-exact-or-range · raised 2026-10-04

    Is the github_pat_ body always exactly 82 characters (22 + underscore + 59), or may GitHub issue other lengths? Only an issued token or a provider statement would settle it; the 2021 notice that tokens may grow toward 255 characters names other token types.

  • github:fine-grained-personal-access-token@1#underscore-position-fixed · raised 2026-10-04

    Is the single underscore after the prefix always at body offset 22, and may a body ever contain further underscores? No provider page states it; tools that accept an underscore anywhere in the body are supersets, not evidence.

  • github:fine-grained-personal-access-token@1#checksum-applies-to-fine-grained · raised 2026-10-04

    Does the 2021 CRC32 Base62 checksum in the last six characters apply to github_pat_ tokens? The sources that describe it do not name this token.

  • github:fine-grained-personal-access-token@1#ghes-body-parity · raised 2026-10-04

    Does GitHub Enterprise Server 3.17 or later issue the same github_pat_ body shape as github.com? Only the prefix is documented for GHES.

Benchmark dossier notes

From the provider dossier, as written. The evidence level above says how well the format is backed; a fact the dossier does not record is not shown.
Shape
prefix github_pat_, then 22 alphanumeric characters, _, and 59 alphanumeric characters (93 in all). No checksum and no fixed leading digits are claimed. GitHub's docs state no length, alphabet or segment split.
Basis
T1 for the prefix only (the token-formats table). The 22 + 59 split was first a community regex in GitHub community discussion 36441, which a GitHub product manager for identity endorsed on 2022-10-24 ("purely a high-entropy string that's looked up on our backend … Your regex looks good though"). The redact-secret#1013 pass (2026-09-29) found the split in GitHub's own sources: three GitHub-owned redaction and DLP rules (CopilotForXcode since 2025-02-12, gh-aw-firewall, gh-aw-mcpg) match exactly github_pat_ + 22 + _ + 59 alphanumerics, and the REST "Revoke a list of credentials" example carries one full-length value with that layout. Two pinned peer rules (osv-scalibr, trivy) and four independent validators (eks-anywhere, gitingest, slintpad, Electron Fiddle) state the same grammar. That is 9 references, 6 owners and 3 non-summary classes, so the corroborated route clears; the references are in empirical-observations.json. Scanner rules that admit other widths (gitleaks, Nosey Parker, secretlint: github_pat_ + 82 word characters; trufflehog v2: 36 to 255) are supersets. The tier is T2. Whether the staff endorsement (R3) or the GitHub-owned code (R1/R9; it redacts, never generates or validates) is a T1 grammar statement is maintainer ruling Q-GH, pending. A third-party README claims a body checksum; no provider source does, and the staff comment reads against it.
Issuance
Settings > Developer settings > Personal access tokens > Fine-grained tokens. Not attempted. The token exists before organization approval; a leaked one is revoked by the owner, or by GitHub after a report.
Contract in core
detector-families.md (Beta.8 arrival contracts, wave 1); the freeze is in the #726 evidence linked above.

In this benchmark

Fixture rows on the current run. Counts are for redact-secret in published · redact-secret 0.1.0-beta.14 mode.
Fixtures
40
Left readable
0
Redacted too much
0
False alarms
0

40 fixtures: 17 expect a redaction, 23 must stay quiet. See every row

redact-secret fixture counts by evidence level
Evidence levelFixturesLeft readableToo muchFalse alarms
T2Tool-corroborated32000
T3Project policy8000

Every scanner on the same fixtures

In run order. Counts are what each scanner recorded on this family's fixtures, whichever rules it has; a scanner with no rule for the family has nothing to report on it.

Counts per scanner on this family's fixtures
ScannerFixturesLeft readableToo muchFalse alarms
flare-redactRuntime library · 1.6.1 · Published npm package · secrets-only (pii, generic_assignment disabled) · JavaScript engine1 rule targets it40000
gitleaksRepository scanner · 8.30.1 · Directory scan · default rules1 rule targets it40003
redact-secretProduct measured here · 0.1.0-beta.14 · Published npm package · default detectors1 detector mapped40000
trufflehogRepository scanner · 3.97.4 · Filesystem scan · verification disabled1 rule targets it40001

Benchmark dossier questions

Things the sources do not settle. They are listed so nobody reads them as settled.
Open caveat
Only the prefix is provider-documented in prose; the 22 + 59 split rests on GitHub-owned redaction code, one GitHub API example, a staff endorsement, peer rules and independent validators. T1 needs ruling Q-GH or a provider statement; issued-key observations would strengthen the T2 basis but are not required.

Looks like it, but isn't

Values the dossier records as resembling this credential without being one.
Collisions
classic ghp_ and the App ghs_ JWT form are separate secret families, not benign twins. Snake_case identifiers that contain github_pat_ (for example a function name) false-positive open-ended rules. Token ids in audit logs are public identifiers.

Scanner rules for this family

Mapped by hand (reviewed 2026-09-30) from each scanner's pinned rule file, never from what a scanner found on the fixtures.
Peer scanner rules that target this family
ScannerRuleWhat the rule matches
flare-redact · rules 1.6.1github_tokenghp_, gho_, ghu_, ghs_, ghr_ + 36 or github_pat_ + 82 characters
gitleaks · rules 8.30.1github-fine-grained-patgithub_pat_ + 82 characters
trufflehog · rules 3.97.4github/v2ghp_, gho_, ghu_, ghs_, ghr_ or github_pat_ + 36-255 characters

No rule maps to this family in openredaction.

40 of 40 rows

Fixtures in this family

40 rows, redact-secret's outcome on each. Rows that need a look come first (0), then the rest in corpus order. Choose "Every scanner" to see each scanner's outcome for the same rows.
Fixtures in Fine-grained personal access token
FixtureKind and evidenceredact-secret
github-fine-grained-pat-audit-log-hashed-token-encoded-valuegithub · benign-encoded-valueMust not flagT2 · Tool-corroboratedQuiet
github-fine-grained-pat-git-remote-userinfo-boundary-twingithub · boundary-violationMust not flagT2 · Tool-corroborated · twinQuiet
github-fine-grained-pat-revocation-fingerprint-log-encoded-valuegithub · benign-encoded-valueMust not flagT2 · Tool-corroboratedQuiet
github-fine-grained-pat-terraform-provider-alphabet-twingithub · wrong-alphabetMust not flagT2 · Tool-corroborated · twinQuiet
github-fine-grained-pat-actions-envgithub · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
github-fine-grained-pat-actions-secret-reference-referencegithub · templated-referenceMust not flagT3 · Project policyQuiet
github-fine-grained-pat-angle-placeholder-placeholdergithub · documentation-placeholderMust not flagT3 · Project policyQuiet
github-fine-grained-pat-audit-log-token-id-public-idgithub · public-identifierMust not flagT2 · Tool-corroboratedQuiet
github-fine-grained-pat-bearer-headergithub · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
github-fine-grained-pat-bearer-header-case-twingithub · prefix-near-missMust not flagT2 · Tool-corroborated · twinQuiet
github-fine-grained-pat-bearer-header-plus-alphabet-twingithub · wrong-alphabetMust not flagT2 · Tool-corroborated · twinQuiet
github-fine-grained-pat-command-substitution-referencegithub · templated-referenceMust not flagT3 · Project policyQuiet
github-fine-grained-pat-compose-renovategithub · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
github-fine-grained-pat-composer-auth-jsongithub · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
github-fine-grained-pat-composer-auth-json-separator-twingithub · wrong-alphabetMust not flagT2 · Tool-corroborated · twinQuiet
github-fine-grained-pat-curl-basic-authgithub · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
github-fine-grained-pat-docs-sentence-prosegithub · prose-mentionMust not flagT3 · Project policyQuiet
github-fine-grained-pat-dotenv-gh-tokengithub · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
github-fine-grained-pat-dotenv-gh-token-hyphen-prefix-twingithub · prefix-near-missMust not flagT2 · Tool-corroborated · twinQuiet
github-fine-grained-pat-dotenv-gh-token-prefix-twingithub · prefix-near-missMust not flagT2 · Tool-corroborated · twinQuiet
github-fine-grained-pat-expiry-variable-near-missgithub · format-near-missMust not flagT2 · Tool-corroboratedQuiet
github-fine-grained-pat-export-github-patgithub · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
github-fine-grained-pat-gh-auth-logingithub · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
github-fine-grained-pat-git-credential-fillgithub · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
github-fine-grained-pat-git-remote-userinfogithub · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
github-fine-grained-pat-gitlab-ci-mirrorgithub · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
github-fine-grained-pat-go-oauth2-staticgithub · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
github-fine-grained-pat-hub-configgithub · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
github-fine-grained-pat-identifier-name-near-missgithub · format-near-missMust not flagT2 · Tool-corroboratedQuiet
github-fine-grained-pat-k8s-secret-stringdatagithub · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
github-fine-grained-pat-masked-list-entry-placeholdergithub · documentation-placeholderMust not flagT3 · Project policyQuiet
github-fine-grained-pat-octokit-debug-loggithub · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
github-fine-grained-pat-org-token-requests-listing-public-idgithub · public-identifierMust not flagT2 · Tool-corroboratedQuiet
github-fine-grained-pat-pygithub-auth-tokengithub · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
github-fine-grained-pat-redacted-dotenv-placeholdergithub · documentation-placeholderMust not flagT3 · Project policyQuiet
github-fine-grained-pat-request-id-header-public-idgithub · public-identifierMust not flagT2 · Tool-corroboratedQuiet
github-fine-grained-pat-rotation-policy-prosegithub · prose-mentionMust not flagT3 · Project policyQuiet
github-fine-grained-pat-terraform-providergithub · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
github-fine-grained-pat-terraform-provider-prefix-separator-twingithub · prefix-near-missMust not flagT2 · Tool-corroborated · twinQuiet
github-fine-grained-pat-vault-kv-lookup-referencegithub · templated-referenceMust not flagT3 · Project policyQuiet

Sources

Researched 2026-09-29.

Documentation and code

  • docs.github.com/en/authentication/keeping-your-account-and-data-secure/about-authentication-to-github#githubs-token-formats
  • github.com/github/docs/blob/e4859a83ac13c5715b723b3d17e273beba5c4572/src/rest/data/fpt-2026-03-10/credentials.json#L29
  • github.com/github/CopilotForXcode/blob/258d4577dcf8fba0e9131b514dbe45b5dbb8906c/Tool/Sources/TelemetryService/TelemetryCleaner.swift#L65
  • github.com/github/gh-aw-firewall/blob/8f9b21bf756e3a9a46819dc29118b92e96c1b7a8/src/dlp.ts#L64-L65
  • github.com/github/gh-aw-mcpg/blob/4576c3e06752aae7d50502883db294b468844dc5/internal/sanitize/sanitize.go#L44
  • github.com/community/community/discussions/36441#discussioncomment-3951965

Research log

Other GitHub families