redact-secret · Report
Legacy API key (bare UUID)
Pre-2024-04 unprefixed 8-4-4-4-12 hex UUID token, still valid until regenerated; recognized only beside a same-line heroku keyword.
Research record
3 events in the review history: 2 observed, 1 reviewed. Latest: observed on 2026-09-24 by automation, project maintainer. Project-maintained review is not independent validation. The family record at this release.
Format
What it looks like
Shape not recorded.
Format facts
Tool corroborated ·
tool-corroboration· current · observed 2026-09-17Pinned scanner rules are consistent with the contract grammar (2 artifacts: gitleaks 8.30.1; trufflehog 3.97.4).
- gitleaks/gitleaks @ v8.30.1: config/gitleaks.tomlscanner-rule-source · last read 2026-10-04 · latest outcome read · supports gitleaks 8.30.1: gitleaks.toml
- trufflesecurity/trufflehog @ v3.97.4: pkg/detectors/heroku/v1/heroku.goscanner-rule-source · last read 2026-09-17 · latest outcome read · supports trufflehog 3.97.4: heroku/v1
Provider documented ·
field-shape· current · observed 2026-09-24shape: bare 8-4-4-4-12 lowercase-hex UUID (tokens granted before 2024-04-01), valid until regenerated
- devcenter.heroku.com/changelog-items/2842provider-documentation · last read 2026-09-24 · latest outcome read · supports shape: bare 8-4-4-4-12 lowercase-hex UUID (tokens granted before 2024-04-01), valid until regenerated
Tool corroborated ·
field-context-gate· current · observed 2026-09-17context gate: no marker of its own: scored as policy, only beside a same-line heroku keyword
- gitleaks/gitleaks @ v8.30.1: config/gitleaks.tomlscanner-rule-source · last read 2026-10-04 · latest outcome read · supports context gate: no marker of its own: scored as policy, only beside a same-line heroku keyword
- trufflesecurity/trufflehog @ v3.97.4: pkg/detectors/heroku/v1/heroku.goscanner-rule-source · last read 2026-09-17 · latest outcome read · supports context gate: no marker of its own: scored as policy, only beside a same-line heroku keyword
Provider documented ·
field-later-generations· current · observed 2026-09-24later generations: HRKU-<uuid> (41 characters, 2024-04-01 to 2025-04-23) and HRKU-AA + 58 (65 characters) are provider-documented generations of the same credential class; both belong to the current OAuth family (heroku-api-key, #209), not this contract
- devcenter.heroku.com/articles/oauthprovider-documentation · last read 2026-09-24 · latest outcome read · supports later generations: HRKU-<uuid> (41 characters, 2024-04-01 to 2025-04-23) and HRKU-AA + 58 (65 characters) are provider-documented generations of the same credential class; both belong to the current OAuth family (heroku-api-key, #209), not this contract
- devcenter.heroku.com/changelog-items/3175provider-documentation · last read 2026-09-24 · latest outcome read · supports later generations: HRKU-<uuid> (41 characters, 2024-04-01 to 2025-04-23) and HRKU-AA + 58 (65 characters) are provider-documented generations of the same credential class; both belong to the current OAuth family (heroku-api-key, #209), not this contract
Unresolved ·
field-hex-case· current · observed 2026-09-24hex case: provider examples are lowercase; gitleaks and semgrep accept uppercase; whether Heroku ever issued uppercase is unknown, so no fixture asserts either way
- github.com/redact-secret/redact-secret-benchmarks/issues/232other · last read 2026-09-24 · latest outcome read · supports hex case: provider examples are lowercase; gitleaks and semgrep accept uppercase; whether Heroku ever issued uppercase is unknown, so no fixture asserts either way
Unresolved ·
field-40-hex-shape· current · observed 2026-09-2440-hex shape: devcenter.heroku.com/articles/authentication shows a 40-character lowercase-hex token of undated era; no fixture uses or excludes it
- devcenter.heroku.com/articles/authenticationprovider-documentation · last read 2026-09-24 · latest outcome read · supports 40-hex shape: devcenter.heroku.com/articles/authentication shows a 40-character lowercase-hex token of undated era; no fixture uses or excludes it
Unresolved ·
field-uuid-shaped-siblings· current · observed 2026-09-24UUID-shaped siblings: OAuth client secrets and refresh tokens are also bare UUIDs today; they are secrets, so none is used as a benign control
- devcenter.heroku.com/articles/oauthprovider-documentation · last read 2026-09-24 · latest outcome read · supports UUID-shaped siblings: OAuth client secrets and refresh tokens are also bare UUIDs today; they are secrets, so none is used as a benign control
Unresolved ·
dossier-research· current · observed 2026-09-24Legacy dossier research (verdict ready, tier T2) cited 2 sources; the dossier does not attribute sources to individual properties.
- devcenter.heroku.com/changelog-items/2842provider-documentation · last read 2026-09-24 · latest outcome read · supports Cited by the legacy dossier research for this family
- devcenter.heroku.com/changelog-items/3175provider-documentation · last read 2026-09-24 · latest outcome read · supports Cited by the legacy dossier research for this family
Unresolved ·
taxonomy-sources· current · observed 2026-09-24The legacy taxonomy lists 2 sources for this family. The taxonomy records no date; the dossier researchedAt is used as the observed-at date.
- devcenter.heroku.com/changelog-items/2842provider-documentation · last read 2026-09-24 · latest outcome read · supports Listed as a source for this family in the legacy taxonomy
- devcenter.heroku.com/changelog-items/3175provider-documentation · last read 2026-09-24 · latest outcome read · supports Listed as a source for this family in the legacy taxonomy
Open questions
No open question is recorded for this revision.
Benchmark dossier notes
- Shape
- an unprefixed lowercase 8-4-4-4-12 hex UUID (36 characters), granted before 2024-04-01. Heroku states no grammar in prose; the shape is one changelog example.
- Basis
- T2. Provider changelog 2842 (example), gitleaks, trufflehog and Nosey Parker rules, which all gate on a
herokukeyword. Hex case is disputed (gitleaks and Semgrep accept uppercase; Nosey Parker does not). - Issuance
- cannot be reissued; new tokens are prefixed. Not observable.
- Contract in core
- detector-families.md (
heroku_api_key_legacy, confidence-gated).
In this benchmark
- Fixtures
- 63
- Left readable
- 0
- Redacted too much
- 0
- False alarms
- 0
63 fixtures: 42 must stay quiet, 21 record project policy. See every row
| Evidence level | Fixtures | Left readable | Too much | False alarms |
|---|---|---|---|---|
| T2Tool-corroborated | 17 | 0 | 0 | 0 |
| T3Project policy | 45 | 0 | 0 | 0 |
| T0Pending review | 1 | 0 | 0 | 0 |
Every scanner on the same fixtures
In run order. Counts are what each scanner recorded on this family's fixtures, whichever rules it has; a scanner with no rule for the family has nothing to report on it.
| Scanner | Fixtures | Left readable | Too much | False alarms |
|---|---|---|---|---|
| flare-redactRuntime library · 1.6.1 · Published npm package · secrets-only (pii, generic_assignment disabled) · JavaScript engineNo rule maps to it | 63 | 20 | 1 | 0 |
| gitleaksRepository scanner · 8.30.1 · Directory scan · default rules1 rule targets it | 63 | 10 | 0 | 8 |
| redact-secretProduct measured here · 0.1.0-beta.14 · Published npm package · default detectors1 detector mapped | 63 | 0 | 0 | 0 |
| trufflehogRepository scanner · 3.97.4 · Filesystem scan · verification disabled1 rule targets it | 63 | 3 | 1 | 12 |
Benchmark dossier questions
- Open caveat
- Provider shows the bare UUID only as a changelog example; no marker separates it from Heroku ids, so it is claimable only beside a heroku keyword. No legacy token can be newly issued.
Looks like it, but isn't
- Collisions
- structurally identical to Heroku app, release, request and user ids and to current UUID-shaped secrets (client secret, refresh token), so a same-line keyword is the only gate. An app id on a
HEROKU_APP_IDline is the recorded false-positive control.
Scanner rules for this family
| Scanner | Rule | What the rule matches |
|---|---|---|
| gitleaks · rules 8.30.1 | heroku-api-key | heroku keyword + a UUID |
| openredaction · rules 1.1.5 | HEROKU_API_KEY | a bare UUID |
| trufflehog · rules 3.97.4 | heroku/v1 | heroku keyword + a UUID |
No rule maps to this family in flare-redact.
Fixtures in this family
| Fixture | Kind and evidence | redact-secret |
|---|---|---|
heroku-api-key-legacy-app-url-path-public-idheroku · public-identifier | Must not flagT2 · Tool-corroborated | Quiet |
heroku-api-key-legacy-app-uuid-json-public-idheroku · public-identifier | Must not flagT2 · Tool-corroborated | Quiet |
heroku-api-key-legacy-apps-info-json-public-idheroku · public-identifier | Must not flagT2 · Tool-corroborated | Quiet |
heroku-api-key-legacy-auth-token-outputheroku · documented-format-literal | Project policyT3 · Project policy | Redacted |
heroku-api-key-legacy-authorizations-infoheroku · documented-format-literal | Project policyT3 · Project policy | Redacted |
heroku-api-key-legacy-authorizations-list-public-idheroku · public-identifier | Must not flagT2 · Tool-corroborated | Quiet |
heroku-api-key-legacy-ci-debug-echoheroku · documented-format-literal | Project policyT3 · Project policy | Redacted |
heroku-api-key-legacy-compose-envheroku · documented-format-literal | Project policyT3 · Project policy | Redacted |
heroku-api-key-legacy-deploy-actionheroku · documented-format-literal | Project policyT3 · Project policy | Redacted |
heroku-api-key-legacy-deploy-config-jsonheroku · documented-format-literal | Project policyT3 · Project policy | Redacted |
heroku-api-key-legacy-deploy-logheroku · documented-format-literal | Project policyT3 · Project policy | Redacted |
heroku-api-key-legacy-envheroku · documented-format-literal | Project policyT3 · Project policy | Redacted |
heroku-api-key-legacy-exportheroku · documented-format-literal | Project policyT3 · Project policy | Redacted |
heroku-api-key-legacy-git-config-remoteheroku · documented-format-literal | Project policyT3 · Project policy | Redacted |
heroku-api-key-legacy-git-remoteheroku · documented-format-literal | Project policyT3 · Project policy | Redacted |
heroku-api-key-legacy-git-remote-context-twinheroku · missing-context-marker | Must not flagT3 · Project policy · twin | Quiet |
heroku-api-key-legacy-handoff-noteheroku · documented-format-literal | Project policyT3 · Project policy | Redacted |
heroku-api-key-legacy-inline-envheroku · documented-format-literal | Project policyT3 · Project policy | Redacted |
heroku-api-key-legacy-keyword-context-bareheroku · documented-format-literal | Project policyT3 · Project policy | Redacted |
heroku-api-key-legacy-keyword-context-quotedheroku · documented-format-literal | Project policyT3 · Project policy | Redacted |
heroku-api-key-legacy-keyword-context-unicode-crlfheroku · documented-format-literal | Project policyT3 · Project policy | Redacted |
heroku-api-key-legacy-netrc-multi-lineheroku · documented-format-literal | Project policyT3 · Project policy | Redacted |
heroku-api-key-legacy-netrc-single-lineheroku · documented-format-literal | Project policyT3 · Project policy | Redacted |
heroku-api-key-legacy-oauth-client-id-public-idheroku · public-identifier | Must not flagT2 · Tool-corroborated | Quiet |
heroku-api-key-legacy-other-git-host-twinheroku · missing-context-marker | Must not flagT3 · Project policy · twin | Quiet |
heroku-api-key-legacy-platform-apiheroku · documented-format-literal | Project policyT3 · Project policy | Redacted |
heroku-api-key-legacy-platform-api-context-twinheroku · missing-context-marker | Must not flagT3 · Project policy · twin | Quiet |
heroku-api-key-legacy-platform-api-rubyheroku · documented-format-literal | Project policyT3 · Project policy | Redacted |
heroku-api-key-legacy-public-idheroku · benign-lookalike | Must not flagT2 · Tool-corroborated | Quiet |
heroku-api-key-legacy-release-id-public-idheroku · public-identifier | Must not flagT2 · Tool-corroborated | Quiet |
heroku-api-key-legacy-releases-path-near-missheroku · format-near-miss | Must not flagT2 · Tool-corroborated | Quiet |
heroku-api-key-legacy-router-request-id-public-idheroku · public-identifier | Must not flagT2 · Tool-corroborated | Quiet |
heroku-api-key-legacy-router-request-id-public-id-public-identifierheroku · public-identifier | Must not flagT2 · Tool-corroborated | Quiet |
heroku-api-key-legacy-terraform-providerheroku · documented-format-literal | Project policyT3 · Project policy | Redacted |
heroku-api-key-legacy-zero-uuid-placeholderheroku · documentation-placeholder | Must not flagT3 · Project policy | Quiet |
uuid-under-generic-api-key-nameauthored-prefixless-key-shape-discrimination · uuid-under-credential-name-without-provider-context | Pending reviewT0 · Pending | Unscored |
heroku-api-key-legacy-actions-secret-referenceheroku · templated-reference | Must not flagT3 · Project policy | Quiet |
heroku-api-key-legacy-buildpack-digest-encoded-valueheroku · benign-encoded-value | Must not flagT2 · Tool-corroborated | Quiet |
heroku-api-key-legacy-client-id-row-twinheroku · missing-context-marker | Must not flagT3 · Project policy · twin | Quiet |
heroku-api-key-legacy-command-substitution-referenceheroku · templated-reference | Must not flagT3 · Project policy | Quiet |
heroku-api-key-legacy-compose-context-twinheroku · missing-context-marker | Must not flagT3 · Project policy · twin | Quiet |
heroku-api-key-legacy-deploy-action-context-twinheroku · missing-context-marker | Must not flagT3 · Project policy · twin | Quiet |
heroku-api-key-legacy-deploy-log-context-twinheroku · missing-context-marker | Must not flagT3 · Project policy · twin | Quiet |
heroku-api-key-legacy-env-context-twinheroku · missing-context-marker | Must not flagT3 · Project policy · twin | Quiet |
heroku-api-key-legacy-export-context-twinheroku · missing-context-marker | Must not flagT3 · Project policy · twin | Quiet |
heroku-api-key-legacy-handoff-note-context-twinheroku · missing-context-marker | Must not flagT3 · Project policy · twin | Quiet |
heroku-api-key-legacy-hrku-migration-note-proseheroku · prose-mention | Must not flagT3 · Project policy | Quiet |
heroku-api-key-legacy-keyword-context-bare-twinheroku · wrong-length | Must not flagT2 · Tool-corroborated · twin | Quiet |
heroku-api-key-legacy-keyword-context-quoted-twinheroku · wrong-length | Must not flagT2 · Tool-corroborated · twin | Quiet |
heroku-api-key-legacy-keyword-context-unicode-crlf-twinheroku · wrong-length | Must not flagT2 · Tool-corroborated · twin | Quiet |
Sources
Documentation and code
- devcenter.heroku.com/changelog-items/2842
- devcenter.heroku.com/changelog-items/3175
Research log
- redact-secret/redact-secret-benchmarks#232Research issue