Skip to content
Benchmarks

redact-secret · Report

OAuth2 access and refresh tokens

OAuth2 access token (ya29.) or refresh token (1//); the client secret is google:oauth-client-secret.

  • Google
  • Detectors: none mapped
  • Run 2026-10-07
  • Mode published · redact-secret 0.1.0-beta.14
  • Dossier verdictIssuance-gated
  • Dossier evidence levelT0 · Pending
  • Dossier researched2026-09-29
BLOCKED in the #1012 research record: the ya29. alphabet and floor and the 1// lead byte and length are unsettled, so no contract is authored. The GOCSPX- client secret is split out as google:oauth-client-secret.

Research record

From credential-evidence snapshot-2026.10.06.4 · records at 77ce761 · schema 1.8.0. It describes the research on the format, not what any scanner or the product does, and not a support status.
  • Review stateDraft, not reviewed
  • Format revision1 · proposed, none current
  • ResearchResearched
  • Researched2026-09-29

What blocks the research

  • Issuance-gatedya29. alphabet (Google's own example has an interior .) and floor, and the 1// lead byte and length (Google example 1// + 43 vs peer 1//0 + 80 or more); needs one access token and one refresh token measured.

2 events in the review history: 1 observed, 1 reviewed. Latest: observed on 2026-09-29 by automation, project maintainer. Project-maintained review is not independent validation. The family record at this release.

Format

Provider format research from credential-evidence snapshot-2026.10.06.4 · records at 77ce761 · schema 1.8.0.

What it looks like

Shape not recorded.

Format facts

Open questions

No open question is recorded for this revision.

Benchmark dossier notes

From the provider dossier, as written. The evidence level above says how well the format is backed; a fact the dossier does not record is not shown.
Basis
none reach a grammar. Google's OAuth 2.0 protocol page states only an upper bound of 512 bytes for a refresh token and gives no example. Tools: flare-redact has a single 1// rule with an open 20 to 160 range, trufflehog has an open-ended ya29. rule, and no consulted tool has a GOCSPX- rule. #519 recorded all three as pending, T0.
Issuance
gcloud auth print-access-token and generateAccessToken for access tokens (record total length, whether a . follows ya29., whether _ or - occur); one installed-app flow for the refresh token (total length, whether it starts 1//0, classes); revoke the grant.
Contract in core
detector-families.md.

In this benchmark

Fixture rows on the current run. Counts are for redact-secret in published · redact-secret 0.1.0-beta.14 mode.

No fixtures in this family yet

Nothing in the corpus targets it, so nothing is measured and no coverage is claimed.

Not measured

Benchmark dossier questions

Things the sources do not settle. They are listed so nobody reads them as settled.
Blocked by
ya29. alphabet (Google's own example has an interior .) and floor, and the 1// lead byte and length (Google example 1// + 43 vs peer 1//0 + 80 or more); needs one access token and one refresh token measured.

Looks like it, but isn't

Values the dossier records as resembling this credential without being one.
Collisions
the OAuth client ID is a public application identifier. A client_secret assignment can still be caught by generic contextual rules.

Scanner rules for this family

Mapped by hand (reviewed 2026-09-30) from each scanner's pinned rule file, never from what a scanner found on the fixtures.
Peer scanner rules that target this family
ScannerRuleWhat the rule matches
flare-redact · rules 1.6.1gcp_refresh_token1// + 20-160 characters
trufflehog · rules 3.97.4googleoauth2ya29. + 10 or more characters

No rule maps to this family in gitleaks, openredaction.

0 of 0 rows

No fixtures in this family yet

Nothing in the corpus targets it, so nothing is measured and no coverage is claimed.

Not measured

Sources

Researched 2026-09-29.

Documentation and code

  • developers.google.com/identity/protocols/oauth2
  • github.com/redact-secret/redact-secret/blob/4fb78827f1ddf5b3106f25130ca510a836ada186/docs/audits/evidence/1012/google-oauth2-credential.md
  • developers.google.com/identity/protocols/oauth2/web-server
  • docs.cloud.google.com/iam/docs/create-short-lived-credentials-direct
  • docs.cloud.google.com/docs/authentication/token-types
  • github.com/google/osv-scalibr/blob/5ab8022c6d67ff99d91d9750f2456ed9549fe8cb/veles/secrets/gcpoauth2access/detector.go#L28-L42
  • github.com/trufflesecurity/trufflehog/blob/48b58d3bf3f02ba17bf23b87f095499bc80c6fd7/pkg/detectors/googleoauth2/googleoauth2_access_token.go#L34
  • github.com/Samsung/CredSweeper/blob/f21ab2f2553eea288a72273b9658cd297ab1d11f/credsweeper/rules/config.yaml#L477-L503

Research log

Other Google families