redact-secret · Report
Recovery token
Vault recovery operation token, prefixed hvr.
Research record
2 events in the review history: 1 observed, 1 reviewed. Latest: observed on 2026-09-20 by automation, project maintainer. Project-maintained review is not independent validation. The family record at this release.
Format
What it looks like
Shape not recorded.
Format facts
Provider documented ·
provider-source· current · observed 2026-09-17hvs./hvb./hvr. prefixes, 24+ random characters: prefixes and minimum length; the provider states the structure is opaque, so the 90–120-character rule the pinned tools use is corroboration, not contract [Legacy contract 'vault-token' is shared by 3 families; this statement is not specific to one of them.]
- developer.hashicorp.com/vault/docs/concepts/tokensprovider-documentation · last read 2026-09-20 · latest outcome read · supports prefixes and minimum length; the provider states the structure is opaque, so the 90–120-character rule the pinned tools use is corroboration, not contract
Tool corroborated ·
tool-corroboration· current · observed 2026-09-17Pinned scanner rules are consistent with the contract grammar (2 artifacts: gitleaks 8.30.1; trufflehog 3.97.4). [Legacy contract 'vault-token' is shared by 3 families; this statement is not specific to one of them.]
- gitleaks/gitleaks @ v8.30.1: config/gitleaks.tomlscanner-rule-source · last read 2026-10-04 · latest outcome read · supports gitleaks 8.30.1: gitleaks.toml
- trufflesecurity/trufflehog @ v3.97.4: pkg/detectors/hashicorpvault/hashicorpvaulttoken/hashicorpvaulttoken.goscanner-rule-source · last read 2026-09-17 · latest outcome read · supports trufflehog 3.97.4: hashicorpvault/hashicorpvaulttoken/hashicorpvaulttoken
Provider documented ·
dossier-research· current · observed 2026-09-20Legacy dossier research (verdict ready, tier T1) cited 1 source; the dossier does not attribute sources to individual properties.
- developer.hashicorp.com/vault/docs/concepts/tokensprovider-documentation · last read 2026-09-20 · latest outcome read · supports Cited by the legacy dossier research for this family
Open questions
No open question is recorded for this revision.
Benchmark dossier notes
- Shape
- Vault recovery operation token, prefixed hvr.
- Basis
- T1 per the shipped
vault-tokencontract in the benchmarks assessment: the tokens concept page documents exactly thehvs.,hvb.andhvr.prefixes and a minimum of 24 random characters, and states the structure is opaque, so the 90 to 120 character rule the pinned tools use is corroboration, not contract. Re-checked 2026-09-20 in benchmarks#46 (PR #55). - Contract in core
- detector-families.md.
In this benchmark
- Fixtures
- 3
- Left readable
- 0
- Redacted too much
- 0
- False alarms
- 0
3 fixtures: 3 record project policy. All at the T3 level, project policy. See every row
Every scanner on the same fixtures
In run order. Counts are what each scanner recorded on this family's fixtures, whichever rules it has; a scanner with no rule for the family has nothing to report on it.
| Scanner | Fixtures | Left readable | Too much | False alarms |
|---|---|---|---|---|
| flare-redactRuntime library · 1.6.1 · Published npm package · secrets-only (pii, generic_assignment disabled) · JavaScript engine1 rule targets it | 3 | 0 | 0 | 0 |
| gitleaksRepository scanner · 8.30.1 · Directory scan · default rulesNo rule maps to it | 3 | 3 | 0 | 0 |
| redact-secretProduct measured here · 0.1.0-beta.14 · Published npm package · default detectors1 detector mapped | 3 | 0 | 0 | 0 |
| trufflehogRepository scanner · 3.97.4 · Filesystem scan · verification disabledNo rule maps to it | 3 | 3 | 0 | 0 |
Scanner rules for this family
| Scanner | Rule | What the rule matches |
|---|---|---|
| flare-redact · rules 1.6.1 | vault_token | hvs., hvb. or hvr. + 20-200 characters |
No rule maps to this family in gitleaks, openredaction, trufflehog.
Fixtures in this family
| Fixture | Kind and evidence | redact-secret |
|---|---|---|
vault-token-shape-3-barehashicorp-vault · documented-format-literal | Project policyT3 · Project policy | Redacted |
vault-token-shape-3-quotedhashicorp-vault · documented-format-literal | Project policyT3 · Project policy | Redacted |
vault-token-shape-3-unicode-crlfhashicorp-vault · documented-format-literal | Project policyT3 · Project policy | Redacted |
Sources
Documentation and code
- developer.hashicorp.com/vault/docs/concepts/tokens
Research log
- redact-secret/redact-secret-benchmarks#46Research issue