redact-secret · Report
OAuth2 access and refresh tokens
OAuth2 access token (ya29.) or refresh token (1//); the client secret is google:oauth-client-secret.
Research record
What blocks the research
- Issuance-gatedya29. alphabet (Google's own example has an interior .) and floor, and the 1// lead byte and length (Google example 1// + 43 vs peer 1//0 + 80 or more); needs one access token and one refresh token measured.
2 events in the review history: 1 observed, 1 reviewed. Latest: observed on 2026-09-29 by automation, project maintainer. Project-maintained review is not independent validation. The family record at this release.
Format
What it looks like
Shape not recorded.
Format facts
Unresolved ·
dossier-research· current · observed 2026-09-29Legacy dossier research (verdict issuance-gated, tier T0) cited 8 sources; the dossier does not attribute sources to individual properties.
- developers.google.com/identity/protocols/oauth2/web-serverother · last read 2026-09-29 · latest outcome read · supports Cited by the legacy dossier research for this family
- developers.google.com/identity/protocols/oauth2provider-documentation · last read 2026-09-29 · latest outcome read · supports Cited by the legacy dossier research for this family
- docs.cloud.google.com/iam/docs/create-short-lived-credentials-directother · last read 2026-09-29 · latest outcome read · supports Cited by the legacy dossier research for this family
- docs.cloud.google.com/docs/authentication/token-typesother · last read 2026-09-29 · latest outcome read · supports Cited by the legacy dossier research for this family
- google/osv-scalibr @ 5ab8022c6d67ff99d91d9750f2456ed9549fe8cb: veles/secrets/gcpoauth2access/detector.goother · last read 2026-09-29 · latest outcome read · supports Cited by the legacy dossier research for this family · #L28-L42
- redact-secret/redact-secret @ 378581770a87751d72e27529796c4f790649fd00: docs/audits/evidence/1012/google-oauth2-credential.mdproject-research-note · last read 2026-09-29 · latest outcome read · supports Final research evidence recorded by the legacy dossier
- Samsung/CredSweeper @ f21ab2f2553eea288a72273b9658cd297ab1d11f: credsweeper/rules/config.yamlscanner-rule-source · last read 2026-09-29 · latest outcome read · supports Cited by the legacy dossier research for this family · #L477-L503
- trufflesecurity/trufflehog @ 48b58d3bf3f02ba17bf23b87f095499bc80c6fd7: pkg/detectors/googleoauth2/googleoauth2_access_token.goother · last read 2026-09-29 · latest outcome read · supports Cited by the legacy dossier research for this family · #L34
Unresolved ·
taxonomy-sources· current · observed 2026-09-29The legacy taxonomy lists 2 sources for this family. The taxonomy records no date; the dossier researchedAt is used as the observed-at date.
- developers.google.com/identity/protocols/oauth2provider-documentation · last read 2026-09-29 · latest outcome read · supports Listed as a source for this family in the legacy taxonomy
- redact-secret/redact-secret @ 4fb78827f1ddf5b3106f25130ca510a836ada186: docs/audits/evidence/1012/google-oauth2-credential.mdprovider-documentation · last read 2026-09-29 · latest outcome read · supports Listed as a source for this family in the legacy taxonomy
Open questions
No open question is recorded for this revision.
Benchmark dossier notes
- Basis
- none reach a grammar. Google's OAuth 2.0 protocol page states only an upper bound of 512 bytes for a refresh token and gives no example. Tools: flare-redact has a single
1//rule with an open 20 to 160 range, trufflehog has an open-endedya29.rule, and no consulted tool has aGOCSPX-rule. #519 recorded all three as pending, T0. - Issuance
gcloud auth print-access-tokenandgenerateAccessTokenfor access tokens (record total length, whether a.followsya29., whether_or-occur); one installed-app flow for the refresh token (total length, whether it starts1//0, classes); revoke the grant.- Contract in core
- detector-families.md.
In this benchmark
No fixtures in this family yet
Nothing in the corpus targets it, so nothing is measured and no coverage is claimed.
Not measured
Benchmark dossier questions
- Blocked by
- ya29. alphabet (Google's own example has an interior .) and floor, and the 1// lead byte and length (Google example 1// + 43 vs peer 1//0 + 80 or more); needs one access token and one refresh token measured.
Looks like it, but isn't
- Collisions
- the OAuth client ID is a public application identifier. A
client_secretassignment can still be caught by generic contextual rules.
Scanner rules for this family
| Scanner | Rule | What the rule matches |
|---|---|---|
| flare-redact · rules 1.6.1 | gcp_refresh_token | 1// + 20-160 characters |
| trufflehog · rules 3.97.4 | googleoauth2 | ya29. + 10 or more characters |
No rule maps to this family in gitleaks, openredaction.
No fixtures in this family yet
Nothing in the corpus targets it, so nothing is measured and no coverage is claimed.
Not measured
Sources
Documentation and code
- developers.google.com/identity/protocols/oauth2
- github.com/redact-secret/redact-secret/blob/4fb78827f1ddf5b3106f25130ca510a836ada186/docs/audits/evidence/1012/google-oauth2-credential.md
- developers.google.com/identity/protocols/oauth2/web-server
- docs.cloud.google.com/iam/docs/create-short-lived-credentials-direct
- docs.cloud.google.com/docs/authentication/token-types
- github.com/google/osv-scalibr/blob/5ab8022c6d67ff99d91d9750f2456ed9549fe8cb/veles/secrets/gcpoauth2access/detector.go#L28-L42
- github.com/trufflesecurity/trufflehog/blob/48b58d3bf3f02ba17bf23b87f095499bc80c6fd7/pkg/detectors/googleoauth2/googleoauth2_access_token.go#L34
- github.com/Samsung/CredSweeper/blob/f21ab2f2553eea288a72273b9658cd297ab1d11f/credsweeper/rules/config.yaml#L477-L503
Research log
- redact-secret/redact-secret#487Research issue
- redact-secret/redact-secret#519Research issue
- redact-secret/redact-secret#1012Research issue
- Final evidence, pinned to a commit/redact-secret/redact-secret/blob/378581770a87751d72e27529796c4f790649fd00/docs/audits/evidence/1012/google-oauth2-credential.md