redact-secret · Report
Generic API key
AIza prefixed general-purpose API key.
Research record
2 events in the review history: 1 observed, 1 reviewed. Latest: observed on 2026-09-23 by automation, project maintainer. Project-maintained review is not independent validation. The family record at this release.
Format
What it looks like
- Descriptive pattern
^AIza[A-Za-z0-9_-]{35}$
Parts are shown as recorded. Evidence classes belong to the facts below; no class is assigned to a part.
Format facts
Provider documented ·
provider-source· current · observed 2026-09-23Google Cloud API key example: the provider page identifies the exposed key_string as an API key and shows an AIza-prefixed example; the 35-character suffix and alphabet remain gitleaks-corroborated
- docs.cloud.google.com/docs/authentication/api-keysprovider-documentation · last read 2026-09-23 · latest outcome read · supports the provider page identifies the exposed key_string as an API key and shows an AIza-prefixed example; the 35-character suffix and alphabet remain gitleaks-corroborated
Unresolved ·
tool-corroboration· current · observed 2026-09-22Pinned scanner rules are consistent with the contract grammar (1 artifact: gitleaks 8.30.1).
- gitleaks/gitleaks @ v8.30.1: config/gitleaks.tomlscanner-rule-source · last read 2026-10-04 · latest outcome read · supports gitleaks 8.30.1: gitleaks.toml
Provider documented ·
field-prefix· current · observed 2026-09-23prefix: AIza (The T1 tier rests on a single provider example (the supabase-management by-example precedent, redact-secret#642), the weakest basis of the seven families.)
- docs.cloud.google.com/docs/authentication/api-keysprovider-documentation · last read 2026-09-23 · latest outcome read · supports one AIza-prefixed example
Provider documented ·
field-total-length· current · observed 2026-09-23total-length: 39 characters
- docs.cloud.google.com/docs/authentication/api-keysprovider-documentation · last read 2026-09-23 · latest outcome read · supports total-length: 39 characters
Unresolved ·
field-body· current · observed 2026-09-23body: 35 characters of [A-Za-z0-9_-]
- gitleaks/gitleaks @ v8.30.1: config/gitleaks.tomlscanner-rule-source · last read 2026-10-04 · latest outcome read · supports body: 35 characters of [A-Za-z0-9_-]
Unresolved ·
field-aq-dot-format· current · observed 2026-09-22aq-dot-format: a newer AQ.-prefixed key format (Not fixtured in either direction.)
- github.com/redact-secret/redact-secret/issues/642scanner-rule-source · last read 2026-09-22 · latest outcome read · supports unconfirmed community reports
Provider documented ·
dossier-research· current · observed 2026-09-23Legacy dossier research (verdict ready, tier T1) cited 2 sources; the dossier does not attribute sources to individual properties.
- docs.cloud.google.com/docs/authentication/api-keysprovider-documentation · last read 2026-09-23 · latest outcome read · supports Cited by the legacy dossier research for this family
- redact-secret/redact-secret @ 8b6a5fde52ecb4dfce13f09c7a947062d21483c7: docs/audits/evidence/642/README.mdproject-research-note · last read 2026-09-23 · latest outcome read · supports Final research evidence recorded by the legacy dossier
Open questions
No open question is recorded for this revision.
Benchmark dossier notes
- Shape
- prefix
AIzafollowed by 35 characters from letters, digits, underscore and hyphen, 39 characters in all. - Basis
- T1 for the prefix and total length, from one example on Google Cloud's API keys page ("The API key string is an encrypted string, for example,
AIza…"). The page states no prefix rule and no grammar. The 35-character body comes from gitleaks 8.30.1 (gcp-api-key) and flare-redact, which agree, and from trufflehog'sgooglegeminirule with the splitAIzaSyplus 33, the same total length. - Contract in core
- detector-families.md.
In this benchmark
- Fixtures
- 32
- Left readable
- 0
- Redacted too much
- 0
- False alarms
- 0
32 fixtures: 12 expect a redaction, 20 must stay quiet. See every row
| Evidence level | Fixtures | Left readable | Too much | False alarms |
|---|---|---|---|---|
| T1Provider-documented | 12 | 0 | 0 | 0 |
| T2Tool-corroborated | 12 | 0 | 0 | 0 |
| T3Project policy | 5 | 0 | 0 | 0 |
| T0Pending review | 3 | 0 | 0 | 0 |
Every scanner on the same fixtures
In run order. Counts are what each scanner recorded on this family's fixtures, whichever rules it has; a scanner with no rule for the family has nothing to report on it.
| Scanner | Fixtures | Left readable | Too much | False alarms |
|---|---|---|---|---|
| flare-redactRuntime library · 1.6.1 · Published npm package · secrets-only (pii, generic_assignment disabled) · JavaScript engine1 rule targets it | 32 | 0 | 0 | 0 |
| gitleaksRepository scanner · 8.30.1 · Directory scan · default rules1 rule targets it | 32 | 0 | 0 | 0 |
| redact-secretProduct measured here · 0.1.0-beta.14 · Published npm package · default detectors1 detector mapped | 32 | 0 | 0 | 0 |
| trufflehogRepository scanner · 3.97.4 · Filesystem scan · verification disabled1 rule targets it | 32 | 12 | 0 | 0 |
Benchmark dossier questions
- Open caveat
- The provider shows the AIza prefix and a 39-character length in one example, not a stated grammar; the 35-character body alphabet is tool-corroborated.
Looks like it, but isn't
- Collisions
- Gemini keys use this same shape; #519 decided they are not a separate family because restriction to an API is not visible in the bytes. The page now describes "authorization keys" that authenticate as a service account and gives no string format for them; the reported
AQ.prefix does not appear on it. A Firebase Web SDKapiKeyhas the same shape and was moved from exempt to redacted by #749. The OAuth client ID (...apps.googleusercontent.com) and a service account email are public identifiers.
Scanner rules for this family
| Scanner | Rule | What the rule matches |
|---|---|---|
| flare-redact · rules 1.6.1 | google_api_key | AIza + 35 characters |
| gitleaks · rules 8.30.1 | gcp-api-key | AIza + 35 characters |
| openredaction · rules 1.1.5 | FIREBASE_API_KEY | AIza + 35 characters |
| openredaction · rules 1.1.5 | GOOGLE_API_KEY | AIza + 35 characters |
| trufflehog · rules 3.97.4 | googlegemini | AIzaSy + 33 characters |
Fixtures in this family
| Fixture | Kind and evidence | redact-secret |
|---|---|---|
google-api-key-curl-generate-contentgoogle · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
google-api-key-env-maps-keygoogle · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
google-api-key-firebase-web-configgoogle · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
google-api-key-geocode-querygoogle · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
google-api-key-github-actions-placesgoogle · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
google-api-key-goog-api-key-headergoogle · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
google-api-key-google-services-jsongoogle · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
google-api-key-k8s-secret-stringdatagoogle · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
google-api-key-shape-1-baregoogle · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
google-api-key-shape-1-quotedgoogle · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
google-api-key-shape-1-unicode-crlfgoogle · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
google-api-key-shell-export-geminigoogle · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
google-key-shape-under-firebase-config-labelauthored-conflicting-field-label-semantics · google-api-key-shape-under-firebase-and-generic-labels | Pending reviewT0 · Pending | Unscored |
google-key-shape-under-generative-api-env-labelauthored-conflicting-field-label-semantics · google-api-key-shape-under-firebase-and-generic-labels | Pending reviewT0 · Pending | Unscored |
google-key-shape-under-json-api-key-fieldauthored-conflicting-field-label-semantics · google-api-key-shape-under-firebase-and-generic-labels | Pending reviewT0 · Pending | Unscored |
google-api-key-geocode-query-length-twingoogle · wrong-length | Must not flagT2 · Tool-corroborated · twin | Quiet |
google-api-key-goog-api-key-header-prefix-case-twingoogle · prefix-near-miss | Must not flagT2 · Tool-corroborated · twin | Quiet |
google-api-key-google-services-json-prefix-twingoogle · prefix-near-miss | Must not flagT2 · Tool-corroborated · twin | Quiet |
google-api-key-label-prosegoogle · benign-lookalike | Must not flagT3 · Project policy | Quiet |
google-api-key-maps-script-template-placeholdergoogle · documentation-placeholder | Must not flagT3 · Project policy | Quiet |
google-api-key-maskgoogle · benign-lookalike | Must not flagT3 · Project policy | Quiet |
google-api-key-oauth-client-id-public-idgoogle · public-identifier | Must not flagT2 · Tool-corroborated | Quiet |
google-api-key-prefix-onlygoogle · benign-lookalike | Must not flagT2 · Tool-corroborated | Quiet |
google-api-key-referencegoogle · benign-lookalike | Must not flagT3 · Project policy | Quiet |
google-api-key-restriction-note-prosegoogle · prose-mention | Must not flagT3 · Project policy | Quiet |
google-api-key-shape-1-bare-twingoogle · wrong-length | Must not flagT2 · Tool-corroborated · twin | Quiet |
google-api-key-shape-1-prefix-bare-twingoogle · prefix-near-miss | Must not flagT2 · Tool-corroborated · twin | Quiet |
google-api-key-shape-1-prefix-quoted-twingoogle · prefix-near-miss | Must not flagT2 · Tool-corroborated · twin | Quiet |
google-api-key-shape-1-prefix-unicode-crlf-twingoogle · prefix-near-miss | Must not flagT2 · Tool-corroborated · twin | Quiet |
google-api-key-shape-1-quoted-twingoogle · wrong-length | Must not flagT2 · Tool-corroborated · twin | Quiet |
google-api-key-shape-1-unicode-crlf-twingoogle · wrong-length | Must not flagT2 · Tool-corroborated · twin | Quiet |
google-api-key-short-bodygoogle · benign-lookalike | Must not flagT2 · Tool-corroborated | Quiet |
Sources
Documentation and code
- docs.cloud.google.com/docs/authentication/api-keys
Research log
- redact-secret/redact-secret#296Research issue
- redact-secret/redact-secret#519Research issue
- redact-secret/redact-secret#642Research issue
- Final evidence, pinned to a commit/redact-secret/redact-secret/blob/8b6a5fde52ecb4dfce13f09c7a947062d21483c7/docs/audits/evidence/642/README.md