redact-secret · Report
Fine-grained personal access token
Repository- and permission-scoped PAT, prefixed github_pat_.
Research record
What blocks the research
- Issuance-gatedExact body length, underscore position, checksum and GHES body parity of github_pat_ tokens are not provider-documented; only an issued token or a provider statement would settle them.
4 events in the review history: 3 observed, 1 reviewed. Latest: observed on 2026-10-04 by automation, project maintainer. Project-maintained review is not independent validation. The family record at this release.
Format
What it looks like
- Descriptive pattern
^github_pat_[A-Za-z0-9]{22}_[A-Za-z0-9]{59}$
Parts are shown as recorded. Evidence classes belong to the facts below; no class is assigned to a part.
Format facts
Unresolved ·
candidate-source· current · observed 2026-09-24Candidate provider source, not accepted as the provider source by the legacy contract (github_pat_ fine-grained PAT prefix): the github_pat_ prefix only; no length, alphabet, segment or checksum
- docs.github.com/en/authentication/keeping-your-account-and-data-secure/about-authentication-to-githubprovider-documentation · last read 2026-10-04 · latest outcome read · supports the github_pat_ prefix only; no length, alphabet, segment or checksum · #githubs-token-formats
Tool corroborated ·
tool-corroboration· current · observed 2026-09-24Pinned scanner rules are consistent with the contract grammar (4 artifacts: gitleaks 8.30.1; noseyparker; secretlint; trufflehog 3.97.4).
- gitleaks/gitleaks @ v8.30.1: config/gitleaks.tomlscanner-rule-source · last read 2026-10-04 · latest outcome read · supports gitleaks 8.30.1: github-fine-grained-pat
- praetorian-inc/noseyparker @ main: crates/noseyparker/data/default/builtin/rules/github.ymlscanner-rule-source · last read 2026-09-24 · latest outcome read · supports noseyparker: np.github.7
- secretlint/secretlint @ master: packages/%40secretlint/secretlint-rule-github/src/index.tsscanner-rule-source · last read 2026-09-24 · latest outcome read · supports secretlint: secretlint-rule-github
- trufflesecurity/trufflehog @ v3.97.4: pkg/detectors/github/v2/github.goscanner-rule-source · last read 2026-09-24 · latest outcome read · supports trufflehog 3.97.4: github v2 (github_pat_ in a 36–255 range)
Provider documented ·
field-prefix· current · observed 2026-09-24prefix: Fine-grained personal access tokens begin with the literal github_pat_.
- docs.github.com/en/authentication/keeping-your-account-and-data-secure/about-authentication-to-githubprovider-documentation · last read 2026-10-04 · latest outcome read · supports Token-formats table lists github_pat_ as the fine-grained PAT prefix; it gives no length, alphabet, segment or checksum for it. · #githubs-token-formats
Unresolved ·
field-segments· current · observed 2026-09-24segments: After the prefix: 22 characters, one underscore, 59 characters (93 in total). (Recorded as community evidence with a staff endorsement. Kept visibly below the provider-documented prefix; the #223 hands-on checklist (93 total, one underscore at body offset 22) is human corroboration.)
- gist.github.com/magnetikonline/073afe7909ffdd6f10ef06a00bc3bc88third-party-writeup · last read 2026-09-24 · latest outcome read · supports Community gist: ^github_pat_[a-zA-Z0-9]{22}_[a-zA-Z0-9]{59}$. The product decision behind redact-secret#517 cites this gist and GitGuardian; the product implementation is therefore downstream of this community grammar, not independent evidence.
- github.com/orgs/community/discussions/36441third-party-writeup · last read 2026-09-24 · latest outcome read · supports csine-pro 2022-10-19 proposed github_pat_[a-zA-Z-0-9]{22}_[a-zA-Z-0-9]{59} (the class admits a literal "-", probably a typo). hpsin (fine-grained PAT PM by content; authorAssociation NONE) replied 2022-10-24 "Your regex looks good" — a provider-staff endorsement in a community thread, not documentation.
Tool corroborated ·
field-body-length· current · observed 2026-09-24body-length: The body after github_pat_ is 82 characters. (Three exact-82 tool rules (not independent of the community grammar they cite) against tolerant ranges (TruffleHog 36–255, r-lib/gh 36–244). No length twin is authored.)
- gitleaks/gitleaks @ v8.30.1: config/gitleaks.tomlscanner-rule-source · last read 2026-10-04 · latest outcome read · supports gitleaks 8.30.1 github-fine-grained-pat: github_pat_\w{82} (no right boundary).
- praetorian-inc/noseyparker @ main: crates/noseyparker/data/default/builtin/rules/github.ymlscanner-rule-source · last read 2026-09-24 · latest outcome read · supports np.github.7: \b(github_pat_[0-9a-zA-Z_]{82})\b.
- secretlint/secretlint @ master: packages/%40secretlint/secretlint-rule-github/src/index.tsscanner-rule-source · last read 2026-09-24 · latest outcome read · supports secretlint: (?<!\p{L})github_pat_[A-Za-z0-9_]{82}(?![A-Za-z0-9_]).
- trufflesecurity/trufflehog @ v3.97.4: pkg/detectors/github/v2/github.goscanner-rule-source · last read 2026-09-24 · latest outcome read · supports trufflehog 3.97.4 github v2: (?:…|github_pat)_[a-zA-Z0-9_]{36,255} — a tolerant range, not a width claim.
Unresolved ·
field-alphabet· current · observed 2026-09-24alphabet: Each segment is [A-Za-z0-9]; the only underscore after the prefix is the separator. (Tools accept an underscore anywhere in the 82-character body (\w / [A-Za-z0-9_]). No fixture asserts silence on an underscore-shifted body; the separator twin uses ".", which no source admits.)
- gist.github.com/magnetikonline/073afe7909ffdd6f10ef06a00bc3bc88third-party-writeup · last read 2026-09-24 · latest outcome read · supports alphabet: Each segment is [A-Za-z0-9]; the only underscore after the prefix is the separator.
- github.blog/changelog/2021-03-04-authentication-token-format-updates/third-party-writeup · last read 2026-10-04 · latest outcome unchanged · supports Provider changelog for the 2021 gh?_ scheme: [A-Za-z0-9_] and "up to 255 characters". It predates github_pat_ and names only the five gh?_ prefixes.
Unresolved ·
field-checksum· current · observed 2026-09-24checksum: Whether the last characters of segment 2 carry a CRC32/Base62 checksum like the 2021 gh?_ scheme. (No checksum is claimed or computed; positives are random synthetic bodies.)
- github.blog/engineering/platform-security/behind-githubs-new-authentication-token-formats/third-party-writeup · last read 2026-10-04 · latest outcome unchanged · supports Documents CRC32/Base62 only for the 2021 gh?_ scheme.
- github.com/odomojuli/regextokensthird-party-writeup · last read 2026-09-24 · latest outcome read · supports Community claim that all GitHub v2 tokens carry a checksum; no provider source for github_pat_.
- github.com/orgs/community/discussions/36441third-party-writeup · last read 2026-09-24 · latest outcome read · supports hpsin 2022-10-24: "purely a high-entropy string that's looked up on our backend" — denies embedded data, says nothing explicit about a checksum.
Unresolved ·
field-segment-1-lead· current · observed 2026-09-24segment-1-lead: Whether segment 1 always begins "11". (Not claimed. Some positives start segment 1 with "11" and some do not, so no fixture depends on it either way.)
- github.com/openhoo/hooray/issues/171third-party-writeup · last read 2026-09-24 · latest outcome read · supports Anecdotal "github_pat_11AAAAAA0…" shape.
- github.com/orgs/community/discussions/36441third-party-writeup · last read 2026-09-24 · latest outcome read · supports jasontempleman-eaton 2024-02-22 hypothetical masked display github_pat_11AS***.
Unresolved ·
field-ghes-parity· current · observed 2026-09-24ghes-parity: Whether GHES (GA from 3.17) issues the same github_pat_ shape.
- github.blog/changelog/2025-03-18-fine-grained-pats-are-now-generally-available/provider-documentation · last read 2026-10-04 · latest outcome unchanged · supports GA; GHES expected in 3.17; token_id appears in API calls and audit logs. Format parity is not stated.
Unresolved ·
listed-references· current · observed 2026-09-24The legacy contract lists 3 references without stating which property each supports.
- gist.github.com/magnetikonline/073afe7909ffdd6f10ef06a00bc3bc88third-party-writeup · last read 2026-09-24 · latest outcome read · supports Listed as a reference by the legacy contract
- github.com/orgs/community/discussions/36441third-party-writeup · last read 2026-09-24 · latest outcome read · supports Listed as a reference by the legacy contract
- github.com/redact-secret/redact-secret-benchmarks/issues/223issue-or-discussion · last read 2026-09-24 · latest outcome read · supports Listed as a reference by the legacy contract
Tool corroborated ·
dossier-research· current · observed 2026-09-29Legacy dossier research (verdict ready, tier T2) cited 7 sources; the dossier does not attribute sources to individual properties.
- docs.github.com/en/authentication/keeping-your-account-and-data-secure/about-authentication-to-githubprovider-documentation · last read 2026-10-04 · latest outcome read · supports Cited by the legacy dossier research for this family · #githubs-token-formats
- github.com/community/community/discussions/36441issue-or-discussion · last read 2026-09-29 · latest outcome read · supports Cited by the legacy dossier research for this family · #discussioncomment-3951965
- github/CopilotForXcode @ 258d4577dcf8fba0e9131b514dbe45b5dbb8906c: Tool/Sources/TelemetryService/TelemetryCleaner.swiftother · last read 2026-09-29 · latest outcome read · supports Cited by the legacy dossier research for this family · #L65
- github/docs @ e4859a83ac13c5715b723b3d17e273beba5c4572: src/rest/data/fpt-2026-03-10/credentials.jsonother · last read 2026-09-29 · latest outcome read · supports Cited by the legacy dossier research for this family · #L29
- github/gh-aw-firewall @ 8f9b21bf756e3a9a46819dc29118b92e96c1b7a8: src/dlp.tsother · last read 2026-09-29 · latest outcome read · supports Cited by the legacy dossier research for this family · #L64-L65
- github/gh-aw-mcpg @ 4576c3e06752aae7d50502883db294b468844dc5: internal/sanitize/sanitize.goother · last read 2026-09-29 · latest outcome read · supports Cited by the legacy dossier research for this family · #L44
- redact-secret/redact-secret @ add1188fed9993723c59fbce8c867086b9d2049a: docs/audits/evidence/1013/github-fine-grained-personal-access-token.mdproject-research-note · last read 2026-09-29 · latest outcome read · supports Final research evidence recorded by the legacy dossier
Unresolved ·
taxonomy-sources· current · observed 2026-09-29The legacy taxonomy lists 1 source for this family. The taxonomy records no date; the dossier researchedAt is used as the observed-at date.
- docs.github.com/en/authentication/keeping-your-account-and-data-secure/about-authentication-to-githubprovider-documentation · last read 2026-10-04 · latest outcome read · supports Listed as a source for this family in the legacy taxonomy · #githubs-token-formats
Provider documented ·
ghes-3-17-prefix· current · observed 2026-10-04The GitHub Enterprise Server 3.17 documentation lists github_pat_ as the prefix of the fine-grained personal access token in its token-formats table, and its managing-tokens page documents fine-grained personal access tokens; neither page states a length, alphabet, segment split or checksum for the token.
- About authentication to GitHub - GitHub Enterprise Server 3.17 Docsprovider-documentation · last read 2026-10-04 · latest outcome read · supports the GHES 3.17 token-formats table lists Fine-grained personal access token with prefix github_pat_; no length, alphabet, segment or checksum · #githubs-token-formats
- Managing your personal access tokens - GitHub Enterprise Server 3.17 Docsprovider-documentation · last read 2026-10-04 · latest outcome read · supports the GHES 3.17 page describes fine-grained personal access tokens (advantages, limitations); it states no token format · #fine-grained-personal-access-tokens
Unresolved ·
ghes-shape-beyond-prefix· current · observed 2026-10-04Whether GitHub Enterprise Server issues the same 22 + underscore + 59 body as github.com is not stated by the GHES 3.17 pages read, which give the prefix only; the general-availability announcement says only that GHES customers should expect the changes in version 3.17.
- About authentication to GitHub - GitHub Enterprise Server 3.17 Docsprovider-documentation · last read 2026-10-04 · latest outcome read · supports prefix only; the page is silent on the body · #githubs-token-formats
- github.blog/changelog/2025-03-18-fine-grained-pats-are-now-generally-available/provider-documentation · last read 2026-10-04 · latest outcome unchanged · supports GHES customers should expect these changes to arrive in version 3.17; no token format is stated
Unresolved ·
2021-format-sources-scope· current · observed 2026-10-04The 2021 token-format changelog and engineering post describe the ghp_, gho_, ghu_, ghs_ and ghr_ token types; read raw on 2026-10-04, neither names github_pat_ or fine-grained tokens, so their statements about a [A-Za-z0-9_] character set, tokens up to 255 characters, an underscore separator and a 32-bit CRC32 Base62 checksum in the last six characters are not evidence about the github_pat_ body, its length, underscore position or checksum.
- github.blog/changelog/2021-03-04-authentication-token-format-updates/third-party-writeup · last read 2026-10-04 · latest outcome unchanged · supports character set [A-Za-z0-9_] and a 255-character allowance are stated for the 2021 prefixed types; github_pat_ is not named
- github.blog/engineering/platform-security/behind-githubs-new-authentication-token-formats/third-party-writeup · last read 2026-10-04 · latest outcome unchanged · supports separator and CRC32 Base62 checksum in the last six characters are described for the 2021 prefixed types; github_pat_ is not named
Unresolved ·
no-provider-length-or-segment-statement· current · observed 2026-10-04No GitHub documentation page read raw on 2026-10-04 (github.com and GHES 3.17 token-formats tables, the GHES 3.17 managing-tokens page, the general-availability changelog) states the total or body length, the position of the underscore after the prefix, the alphabet or a checksum of the github_pat_ token; the 93-character and 22 + 59 statements remain community or tool-corroborated only.
- docs.github.com/en/authentication/keeping-your-account-and-data-secure/about-authentication-to-githubprovider-documentation · last read 2026-10-04 · latest outcome read · supports token-formats table gives the prefix only · #githubs-token-formats
- About authentication to GitHub - GitHub Enterprise Server 3.17 Docsprovider-documentation · last read 2026-10-04 · latest outcome read · supports GHES token-formats table gives the prefix only · #githubs-token-formats
- Managing your personal access tokens - GitHub Enterprise Server 3.17 Docsprovider-documentation · last read 2026-10-04 · latest outcome read · supports GHES managing-tokens page states no token format · #fine-grained-personal-access-tokens
- github.blog/changelog/2025-03-18-fine-grained-pats-are-now-generally-available/provider-documentation · last read 2026-10-04 · latest outcome unchanged · supports general-availability announcement states no token format
Open questions
github:fine-grained-personal-access-token@1#body-length-exact-or-range· raised 2026-10-04Is the github_pat_ body always exactly 82 characters (22 + underscore + 59), or may GitHub issue other lengths? Only an issued token or a provider statement would settle it; the 2021 notice that tokens may grow toward 255 characters names other token types.
github:fine-grained-personal-access-token@1#underscore-position-fixed· raised 2026-10-04Is the single underscore after the prefix always at body offset 22, and may a body ever contain further underscores? No provider page states it; tools that accept an underscore anywhere in the body are supersets, not evidence.
github:fine-grained-personal-access-token@1#checksum-applies-to-fine-grained· raised 2026-10-04Does the 2021 CRC32 Base62 checksum in the last six characters apply to github_pat_ tokens? The sources that describe it do not name this token.
github:fine-grained-personal-access-token@1#ghes-body-parity· raised 2026-10-04Does GitHub Enterprise Server 3.17 or later issue the same github_pat_ body shape as github.com? Only the prefix is documented for GHES.
Benchmark dossier notes
- Shape
- prefix
github_pat_, then 22 alphanumeric characters,_, and 59 alphanumeric characters (93 in all). No checksum and no fixed leading digits are claimed. GitHub's docs state no length, alphabet or segment split. - Basis
- T1 for the prefix only (the token-formats table). The 22 + 59 split was first a community regex in GitHub community discussion 36441, which a GitHub product manager for identity endorsed on 2022-10-24 ("purely a high-entropy string that's looked up on our backend … Your regex looks good though"). The redact-secret#1013 pass (2026-09-29) found the split in GitHub's own sources: three GitHub-owned redaction and DLP rules (CopilotForXcode since 2025-02-12, gh-aw-firewall, gh-aw-mcpg) match exactly
github_pat_+ 22 +_+ 59 alphanumerics, and the REST "Revoke a list of credentials" example carries one full-length value with that layout. Two pinned peer rules (osv-scalibr, trivy) and four independent validators (eks-anywhere, gitingest, slintpad, Electron Fiddle) state the same grammar. That is 9 references, 6 owners and 3 non-summary classes, so the corroborated route clears; the references are inempirical-observations.json. Scanner rules that admit other widths (gitleaks, Nosey Parker, secretlint:github_pat_+ 82 word characters; trufflehog v2: 36 to 255) are supersets. The tier is T2. Whether the staff endorsement (R3) or the GitHub-owned code (R1/R9; it redacts, never generates or validates) is a T1 grammar statement is maintainer ruling Q-GH, pending. A third-party README claims a body checksum; no provider source does, and the staff comment reads against it. - Issuance
- Settings > Developer settings > Personal access tokens > Fine-grained tokens. Not attempted. The token exists before organization approval; a leaked one is revoked by the owner, or by GitHub after a report.
- Contract in core
- detector-families.md (Beta.8 arrival contracts, wave 1); the freeze is in the #726 evidence linked above.
In this benchmark
- Fixtures
- 40
- Left readable
- 0
- Redacted too much
- 0
- False alarms
- 0
40 fixtures: 17 expect a redaction, 23 must stay quiet. See every row
| Evidence level | Fixtures | Left readable | Too much | False alarms |
|---|---|---|---|---|
| T2Tool-corroborated | 32 | 0 | 0 | 0 |
| T3Project policy | 8 | 0 | 0 | 0 |
Every scanner on the same fixtures
In run order. Counts are what each scanner recorded on this family's fixtures, whichever rules it has; a scanner with no rule for the family has nothing to report on it.
| Scanner | Fixtures | Left readable | Too much | False alarms |
|---|---|---|---|---|
| flare-redactRuntime library · 1.6.1 · Published npm package · secrets-only (pii, generic_assignment disabled) · JavaScript engine1 rule targets it | 40 | 0 | 0 | 0 |
| gitleaksRepository scanner · 8.30.1 · Directory scan · default rules1 rule targets it | 40 | 0 | 0 | 3 |
| redact-secretProduct measured here · 0.1.0-beta.14 · Published npm package · default detectors1 detector mapped | 40 | 0 | 0 | 0 |
| trufflehogRepository scanner · 3.97.4 · Filesystem scan · verification disabled1 rule targets it | 40 | 0 | 0 | 1 |
Benchmark dossier questions
- Open caveat
- Only the prefix is provider-documented in prose; the 22 + 59 split rests on GitHub-owned redaction code, one GitHub API example, a staff endorsement, peer rules and independent validators. T1 needs ruling Q-GH or a provider statement; issued-key observations would strengthen the T2 basis but are not required.
Looks like it, but isn't
- Collisions
- classic
ghp_and the Appghs_JWT form are separate secret families, not benign twins. Snake_case identifiers that containgithub_pat_(for example a function name) false-positive open-ended rules. Token ids in audit logs are public identifiers.
Scanner rules for this family
| Scanner | Rule | What the rule matches |
|---|---|---|
| flare-redact · rules 1.6.1 | github_token | ghp_, gho_, ghu_, ghs_, ghr_ + 36 or github_pat_ + 82 characters |
| gitleaks · rules 8.30.1 | github-fine-grained-pat | github_pat_ + 82 characters |
| trufflehog · rules 3.97.4 | github/v2 | ghp_, gho_, ghu_, ghs_, ghr_ or github_pat_ + 36-255 characters |
No rule maps to this family in openredaction.
Fixtures in this family
| Fixture | Kind and evidence | redact-secret |
|---|---|---|
github-fine-grained-pat-audit-log-hashed-token-encoded-valuegithub · benign-encoded-value | Must not flagT2 · Tool-corroborated | Quiet |
github-fine-grained-pat-git-remote-userinfo-boundary-twingithub · boundary-violation | Must not flagT2 · Tool-corroborated · twin | Quiet |
github-fine-grained-pat-revocation-fingerprint-log-encoded-valuegithub · benign-encoded-value | Must not flagT2 · Tool-corroborated | Quiet |
github-fine-grained-pat-terraform-provider-alphabet-twingithub · wrong-alphabet | Must not flagT2 · Tool-corroborated · twin | Quiet |
github-fine-grained-pat-actions-envgithub · documented-format-literal | Must redactT2 · Tool-corroborated | Redacted |
github-fine-grained-pat-actions-secret-reference-referencegithub · templated-reference | Must not flagT3 · Project policy | Quiet |
github-fine-grained-pat-angle-placeholder-placeholdergithub · documentation-placeholder | Must not flagT3 · Project policy | Quiet |
github-fine-grained-pat-audit-log-token-id-public-idgithub · public-identifier | Must not flagT2 · Tool-corroborated | Quiet |
github-fine-grained-pat-bearer-headergithub · documented-format-literal | Must redactT2 · Tool-corroborated | Redacted |
github-fine-grained-pat-bearer-header-case-twingithub · prefix-near-miss | Must not flagT2 · Tool-corroborated · twin | Quiet |
github-fine-grained-pat-bearer-header-plus-alphabet-twingithub · wrong-alphabet | Must not flagT2 · Tool-corroborated · twin | Quiet |
github-fine-grained-pat-command-substitution-referencegithub · templated-reference | Must not flagT3 · Project policy | Quiet |
github-fine-grained-pat-compose-renovategithub · documented-format-literal | Must redactT2 · Tool-corroborated | Redacted |
github-fine-grained-pat-composer-auth-jsongithub · documented-format-literal | Must redactT2 · Tool-corroborated | Redacted |
github-fine-grained-pat-composer-auth-json-separator-twingithub · wrong-alphabet | Must not flagT2 · Tool-corroborated · twin | Quiet |
github-fine-grained-pat-curl-basic-authgithub · documented-format-literal | Must redactT2 · Tool-corroborated | Redacted |
github-fine-grained-pat-docs-sentence-prosegithub · prose-mention | Must not flagT3 · Project policy | Quiet |
github-fine-grained-pat-dotenv-gh-tokengithub · documented-format-literal | Must redactT2 · Tool-corroborated | Redacted |
github-fine-grained-pat-dotenv-gh-token-hyphen-prefix-twingithub · prefix-near-miss | Must not flagT2 · Tool-corroborated · twin | Quiet |
github-fine-grained-pat-dotenv-gh-token-prefix-twingithub · prefix-near-miss | Must not flagT2 · Tool-corroborated · twin | Quiet |
github-fine-grained-pat-expiry-variable-near-missgithub · format-near-miss | Must not flagT2 · Tool-corroborated | Quiet |
github-fine-grained-pat-export-github-patgithub · documented-format-literal | Must redactT2 · Tool-corroborated | Redacted |
github-fine-grained-pat-gh-auth-logingithub · documented-format-literal | Must redactT2 · Tool-corroborated | Redacted |
github-fine-grained-pat-git-credential-fillgithub · documented-format-literal | Must redactT2 · Tool-corroborated | Redacted |
github-fine-grained-pat-git-remote-userinfogithub · documented-format-literal | Must redactT2 · Tool-corroborated | Redacted |
github-fine-grained-pat-gitlab-ci-mirrorgithub · documented-format-literal | Must redactT2 · Tool-corroborated | Redacted |
github-fine-grained-pat-go-oauth2-staticgithub · documented-format-literal | Must redactT2 · Tool-corroborated | Redacted |
github-fine-grained-pat-hub-configgithub · documented-format-literal | Must redactT2 · Tool-corroborated | Redacted |
github-fine-grained-pat-identifier-name-near-missgithub · format-near-miss | Must not flagT2 · Tool-corroborated | Quiet |
github-fine-grained-pat-k8s-secret-stringdatagithub · documented-format-literal | Must redactT2 · Tool-corroborated | Redacted |
github-fine-grained-pat-masked-list-entry-placeholdergithub · documentation-placeholder | Must not flagT3 · Project policy | Quiet |
github-fine-grained-pat-octokit-debug-loggithub · documented-format-literal | Must redactT2 · Tool-corroborated | Redacted |
github-fine-grained-pat-org-token-requests-listing-public-idgithub · public-identifier | Must not flagT2 · Tool-corroborated | Quiet |
github-fine-grained-pat-pygithub-auth-tokengithub · documented-format-literal | Must redactT2 · Tool-corroborated | Redacted |
github-fine-grained-pat-redacted-dotenv-placeholdergithub · documentation-placeholder | Must not flagT3 · Project policy | Quiet |
github-fine-grained-pat-request-id-header-public-idgithub · public-identifier | Must not flagT2 · Tool-corroborated | Quiet |
github-fine-grained-pat-rotation-policy-prosegithub · prose-mention | Must not flagT3 · Project policy | Quiet |
github-fine-grained-pat-terraform-providergithub · documented-format-literal | Must redactT2 · Tool-corroborated | Redacted |
github-fine-grained-pat-terraform-provider-prefix-separator-twingithub · prefix-near-miss | Must not flagT2 · Tool-corroborated · twin | Quiet |
github-fine-grained-pat-vault-kv-lookup-referencegithub · templated-reference | Must not flagT3 · Project policy | Quiet |
Sources
Documentation and code
- docs.github.com/en/authentication/keeping-your-account-and-data-secure/about-authentication-to-github#githubs-token-formats
- github.com/github/docs/blob/e4859a83ac13c5715b723b3d17e273beba5c4572/src/rest/data/fpt-2026-03-10/credentials.json#L29
- github.com/github/CopilotForXcode/blob/258d4577dcf8fba0e9131b514dbe45b5dbb8906c/Tool/Sources/TelemetryService/TelemetryCleaner.swift#L65
- github.com/github/gh-aw-firewall/blob/8f9b21bf756e3a9a46819dc29118b92e96c1b7a8/src/dlp.ts#L64-L65
- github.com/github/gh-aw-mcpg/blob/4576c3e06752aae7d50502883db294b468844dc5/internal/sanitize/sanitize.go#L44
- github.com/community/community/discussions/36441#discussioncomment-3951965
Research log
- redact-secret/redact-secret-benchmarks#223Research issue
- redact-secret/redact-secret-benchmarks#367Research issue
- redact-secret/redact-secret-benchmarks#371Research issue
- redact-secret/redact-secret#517Research issue
- redact-secret/redact-secret#726Research issue
- redact-secret/redact-secret#729Research issue
- redact-secret/redact-secret#1013Research issue
- Final evidence, pinned to a commit/redact-secret/redact-secret/blob/add1188fed9993723c59fbce8c867086b9d2049a/docs/audits/evidence/1013/github-fine-grained-personal-access-token.md