redact-secret · Report
Signing key (signkey-)
signkey-prod-, signkey-test- or signkey-branch- + exactly 64 lowercase hex; the raw key, the rotation fallback and the hashed wire form share the shape.
Research record
3 events in the review history: 2 observed, 1 reviewed. Latest: observed on 2026-09-28 by automation, project maintainer. Project-maintained review is not independent validation. The family record at this release.
Format
What it looks like
- Descriptive pattern
^signkey-(?:prod|test|branch)-[0-9a-f]{64}$
Parts are shown as recorded. Evidence classes belong to the facts below; no class is assigned to a part.
Format facts
Provider documented ·
provider-source· current · observed 2026-09-28inngest/inngest dabb03f: SigningKeyPrefixTest/Branch/Prod constants; self-hosting docs "a valid hexadecimal string with an even number of characters", openssl rand -hex 32 (re-checked 2026-09-28): signkey-prod-, signkey-test- or signkey-branch- + exactly 64 lowercase hex (77 or 79 in all); no checksum
- inngest/inngest @ dabb03f9e093672aaef2ee77eb7accdf0cd00ca3: pkg/authn/signing_key_strategy.goprovider-documentation · last read 2026-09-28 · latest outcome read · supports signkey-prod-, signkey-test- or signkey-branch- + exactly 64 lowercase hex (77 or 79 in all); no checksum · #L15-L25
Provider documented ·
field-prefix· current · observed 2026-09-28prefix: signkey-prod-, signkey-test- or signkey-branch-
- inngest/inngest @ dabb03f9e093672aaef2ee77eb7accdf0cd00ca3: pkg/authn/signing_key_strategy.goprovider-documentation · last read 2026-09-28 · latest outcome read · supports SigningKeyPrefixTest/Branch/Prod · #L15-L25
- github.com/redact-secret/redact-secret/issues/860issue-or-discussion · last read 2026-09-29 · latest outcome read · supports R1 · #issuecomment-5852413851
Provider documented ·
field-body-alphabet· current · observed 2026-09-28body-alphabet: lowercase hex [0-9a-f]; an even number of characters
- www.inngest.com/docs/self-hostingprovider-documentation · last read 2026-09-28 · latest outcome read · supports "a valid hexadecimal string with an even number of characters"; openssl rand -hex 32
Provider documented ·
field-body-length· current · observed 2026-09-28body-length: exactly 64 (77 in all for prod/test, 79 for branch)
- inngest/inngest-js @ 197812b: packages/inngest/src/test/helpers.tsprovider-documentation · last read 2026-09-28 · latest outcome read · supports three signkey-test- fixtures of 64 lowercase hex
- github.com/redact-secret/redact-secret/issues/860issue-or-discussion · last read 2026-09-29 · latest outcome read · supports R5 · #issuecomment-5871306275
- www.inngest.com/docs/self-hostingprovider-documentation · last read 2026-09-28 · latest outcome read · supports openssl rand -hex 32
Provider documented ·
field-wire-form· current · observed 2026-09-28wire-form: the SDK sends signkey-<env>- + SHA-256 hex of the key bytes as Bearer; it is accepted as the API credential and has the same shape
- redact-secret/redact-secret @ 54fe385f718c884d7e3dde6b9756e2d70999ca91: docs/audits/evidence/860/inngest.mdprovider-documentation · last read 2026-09-28 · latest outcome read · supports role and blast radius
Provider documented ·
field-other-labels· current · observed 2026-09-28other-labels: a signkey-<label>- other than prod, test and branch (The twin on signkey-preview- records that exclusion.)
- inngest/inngest @ dabb03f9e093672aaef2ee77eb7accdf0cd00ca3: pkg/authn/signing_key_strategy.goprovider-documentation · last read 2026-09-28 · latest outcome read · supports only three constants · #L15-L25
- redact-secret/redact-secret @ 54fe385f718c884d7e3dde6b9756e2d70999ca91: docs/audits/evidence/860/inngest.mdprovider-documentation · last read 2026-09-28 · latest outcome read · supports a future label is an accepted false negative
Provider documented ·
field-uppercase-hex· current · observed 2026-09-28uppercase-hex: the decoder accepts an uppercase-hex body the generator and fixtures never produce (The contract follows the issued grammar; the uppercase twin records the accepted false negative.)
- redact-secret/redact-secret @ 54fe385f718c884d7e3dde6b9756e2d70999ca91: docs/audits/evidence/860/inngest.mdprovider-documentation · last read 2026-09-28 · latest outcome read · supports excluded shapes
Provider documented ·
field-transport· current · observed 2026-09-28transport: INNGEST_SIGNING_KEY and INNGEST_SIGNING_KEY_FALLBACK environment variables, the signingKey client option and Authorization: Bearer
- www.inngest.com/docs/self-hostingprovider-documentation · last read 2026-09-28 · latest outcome read · supports transport: INNGEST_SIGNING_KEY and INNGEST_SIGNING_KEY_FALLBACK environment variables, the signingKey client option and Authorization: Bearer
Unresolved ·
field-event-key· current · observed 2026-09-28event-key: INNGEST_EVENT_KEY has no documented shape; self-hosted event keys are arbitrary strings (Not this family; only a literal non-key sentinel appears as a control.)
- redact-secret/redact-secret @ 54fe385f718c884d7e3dde6b9756e2d70999ca91: docs/audits/evidence/860/inngest.mdprovider-documentation · last read 2026-09-28 · latest outcome read · supports excluded shapes
Tool corroborated ·
field-peer-lag· current · observed 2026-09-28peer-lag: no rule in trufflehog 3.97.4 or gitleaks 8.30.1
- gitleaks/gitleaks @ v8.30.1: config/gitleaks.tomlscanner-rule-source · last read 2026-10-04 · latest outcome read · supports no inngest rule
- trufflesecurity/trufflehog @ v3.97.4: pkg/detectorsscanner-rule-source · last read 2026-09-29 · latest outcome read · supports no inngest detector directory
Unresolved ·
listed-references· current · observed 2026-09-28The legacy contract lists 10 references without stating which property each supports.
- inngest/inngest @ dabb03f9e093672aaef2ee77eb7accdf0cd00ca3: pkg/authn/signing_key_strategy.goprovider-documentation · last read 2026-09-28 · latest outcome read · supports Listed as a reference by the legacy contract · #L15-L25
- inngest/inngest-js @ 197812b: packages/inngest/src/test/helpers.tsprovider-documentation · last read 2026-09-28 · latest outcome read · supports Listed as a reference by the legacy contract
- github.com/redact-secret/redact-secret/issues/914issue-or-discussion · last read 2026-09-28 · latest outcome read · supports Listed as a reference by the legacy contract
- redact-secret/redact-secret @ 54fe385f718c884d7e3dde6b9756e2d70999ca91: docs/audits/evidence/860/tier-b-rerank.mdproject-research-note · last read 2026-09-28 · latest outcome read · supports Listed as a reference by the legacy contract
- redact-secret/redact-secret @ 54fe385f718c884d7e3dde6b9756e2d70999ca91: docs/audits/evidence/860/inngest.mdprovider-documentation · last read 2026-09-28 · latest outcome read · supports Listed as a reference by the legacy contract
- github.com/redact-secret/redact-secret/issues/860issue-or-discussion · last read 2026-09-29 · latest outcome read · supports Listed as a reference by the legacy contract · #issuecomment-5852413851
- github.com/redact-secret/redact-secret/issues/860issue-or-discussion · last read 2026-09-29 · latest outcome read · supports Listed as a reference by the legacy contract · #issuecomment-5871306275
- github.com/redact-secret/redact-secret/issues/860issue-or-discussion · last read 2026-09-29 · latest outcome read · supports Listed as a reference by the legacy contract
- github.com/redact-secret/redact-secret-benchmarks/issues/436issue-or-discussion · last read 2026-09-28 · latest outcome read · supports Listed as a reference by the legacy contract
- www.inngest.com/docs/self-hostingprovider-documentation · last read 2026-09-28 · latest outcome read · supports Listed as a reference by the legacy contract
Provider documented ·
dossier-research· current · observed 2026-09-28Legacy dossier research (verdict ready, tier T1) cited 3 sources; the dossier does not attribute sources to individual properties.
- inngest/inngest @ dabb03f9e093672aaef2ee77eb7accdf0cd00ca3: pkg/authn/signing_key_strategy.goprovider-documentation · last read 2026-09-28 · latest outcome read · supports Cited by the legacy dossier research for this family · #L15-L25
- redact-secret/redact-secret @ 8b6a5fde52ecb4dfce13f09c7a947062d21483c7: docs/audits/evidence/860/inngest.mdproject-research-note · last read 2026-09-28 · latest outcome read · supports Final research evidence recorded by the legacy dossier
- www.inngest.com/docs/self-hostingprovider-documentation · last read 2026-09-28 · latest outcome read · supports Cited by the legacy dossier research for this family
Provider documented ·
taxonomy-sources· current · observed 2026-09-28The legacy taxonomy lists 2 sources for this family. The taxonomy records no date; the dossier researchedAt is used as the observed-at date.
- inngest/inngest @ dabb03f9e093672aaef2ee77eb7accdf0cd00ca3: pkg/authn/signing_key_strategy.goprovider-documentation · last read 2026-09-28 · latest outcome read · supports Listed as a source for this family in the legacy taxonomy · #L15-L25
- www.inngest.com/docs/self-hostingprovider-documentation · last read 2026-09-28 · latest outcome read · supports Listed as a source for this family in the legacy taxonomy
Open questions
No open question is recorded for this revision.
Benchmark dossier notes
- Shape
- prefix
signkey-prod-,signkey-test-orsignkey-branch-, then exactly 64 lowercase hex characters (77 or 79 in total). - Basis
- prefix T1 from provider code constants (
signkey-prod-is also in a docs curl example). Hex alphabet T1 from provider code (hex decode, "must be hex string") and the self-hosting docs. The 64-character length is T1 by example under R5: the docs generation command produces 64 lowercase hex, and SDK test fixtures all use it. Re-checked 2026-09-28. - Issuance
- not attempted.
- Contract in core
- detector-families.md.
In this benchmark
- Fixtures
- 40
- Left readable
- 0
- Redacted too much
- 0
- False alarms
- 0
40 fixtures: 16 expect a redaction, 24 must stay quiet. See every row
| Evidence level | Fixtures | Left readable | Too much | False alarms |
|---|---|---|---|---|
| T1Provider-documented | 16 | 0 | 0 | 0 |
| T2Tool-corroborated | 15 | 0 | 0 | 0 |
| T3Project policy | 9 | 0 | 0 | 0 |
Every scanner on the same fixtures
In run order. Counts are what each scanner recorded on this family's fixtures, whichever rules it has; a scanner with no rule for the family has nothing to report on it.
| Scanner | Fixtures | Left readable | Too much | False alarms |
|---|---|---|---|---|
| flare-redactRuntime library · 1.6.1 · Published npm package · secrets-only (pii, generic_assignment disabled) · JavaScript engineNo rule maps to it | 40 | 14 | 2 | 1 |
| gitleaksRepository scanner · 8.30.1 · Directory scan · default rulesNo rule maps to it | 40 | 8 | 0 | 1 |
| redact-secretProduct measured here · 0.1.0-beta.14 · Published npm package · default detectors1 detector mapped | 40 | 0 | 0 | 0 |
| trufflehogRepository scanner · 3.97.4 · Filesystem scan · verification disabledNo rule maps to it | 40 | 16 | 0 | 0 |
Looks like it, but isn't
- Collisions
- the self-hosted bare hex key without a prefix is a digest shape and not attributable. Other labels the SDK regex would admit are not provider constants.
Scanner rules for this family
No peer rule maps to this family
None of the reviewed peer scanners has a rule that can match a credential of this family.
None mapped
Fixtures in this family
| Fixture | Kind and evidence | redact-secret |
|---|---|---|
inngest-signing-key-bare-proseinngest · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
inngest-signing-key-bearer-headerinngest · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
inngest-signing-key-chat-pasteinngest · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
inngest-signing-key-curl-hashed-bearerinngest · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
inngest-signing-key-docs-angle-placeholderinngest · documentation-placeholder | Must not flagT3 · Project policy | Quiet |
inngest-signing-key-dotenvinngest · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
inngest-signing-key-exportinngest · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
inngest-signing-key-fallback-dotenvinngest · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
inngest-signing-key-json-api-keyinngest · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
inngest-signing-key-json-tokeninngest · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
inngest-signing-key-key-shape-bareinngest · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
inngest-signing-key-key-shape-quotedinngest · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
inngest-signing-key-key-shape-unicode-crlfinngest · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
inngest-signing-key-sdk-kwarginngest · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
inngest-signing-key-sdk-short-placeholderinngest · documentation-placeholder | Must not flagT3 · Project policy | Quiet |
inngest-signing-key-ts-clientinngest · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
inngest-signing-key-vercel-envinngest · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
inngest-signing-key-x-api-key-headerinngest · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
inngest-signing-key-actions-secret-referenceinngest · templated-reference | Must not flagT3 · Project policy | Quiet |
inngest-signing-key-body-63-twininngest · wrong-length | Must not flagT2 · Tool-corroborated · twin | Quiet |
inngest-signing-key-body-65-twininngest · wrong-length | Must not flagT2 · Tool-corroborated · twin | Quiet |
inngest-signing-key-env-reference-referenceinngest · templated-reference | Must not flagT3 · Project policy | Quiet |
inngest-signing-key-event-key-local-public-idinngest · public-identifier | Must not flagT2 · Tool-corroborated | Quiet |
inngest-signing-key-g-in-body-twininngest · wrong-alphabet | Must not flagT2 · Tool-corroborated · twin | Quiet |
inngest-signing-key-key-guidance-proseinngest · prose-mention | Must not flagT3 · Project policy | Quiet |
inngest-signing-key-label-proseinngest · benign-lookalike | Must not flagT3 · Project policy | Quiet |
inngest-signing-key-leading-glue-twininngest · boundary-violation | Must not flagT2 · Tool-corroborated · twin | Quiet |
inngest-signing-key-maskinngest · benign-lookalike | Must not flagT3 · Project policy | Quiet |
inngest-signing-key-no-event-key-sentinel-public-idinngest · public-identifier | Must not flagT2 · Tool-corroborated | Quiet |
inngest-signing-key-prefix-onlyinngest · benign-lookalike | Must not flagT2 · Tool-corroborated | Quiet |
inngest-signing-key-referenceinngest · benign-lookalike | Must not flagT3 · Project policy | Quiet |
inngest-signing-key-sha256-digest-encoded-valueinngest · benign-encoded-value | Must not flagT2 · Tool-corroborated | Quiet |
inngest-signing-key-short-bodyinngest · benign-lookalike | Must not flagT2 · Tool-corroborated | Quiet |
inngest-signing-key-trailing-glue-twininngest · boundary-violation | Must not flagT2 · Tool-corroborated · twin | Quiet |
inngest-signing-key-truncated-near-missinngest · format-near-miss | Must not flagT2 · Tool-corroborated | Quiet |
inngest-signing-key-underscore-delimiters-twininngest · boundary-violation | Must not flagT2 · Tool-corroborated · twin | Quiet |
inngest-signing-key-unknown-label-twininngest · prefix-near-miss | Must not flagT2 · Tool-corroborated · twin | Quiet |
inngest-signing-key-uppercase-hex-byte-twininngest · wrong-alphabet | Must not flagT2 · Tool-corroborated · twin | Quiet |
inngest-signing-key-uppercase-prefix-twininngest · prefix-near-miss | Must not flagT2 · Tool-corroborated · twin | Quiet |
inngest-signing-key-zeros-placeholderinngest · documentation-placeholder | Must not flagT3 · Project policy | Quiet |
Sources
Documentation and code
- www.inngest.com/docs/self-hosting
- github.com/inngest/inngest/blob/dabb03f9e093672aaef2ee77eb7accdf0cd00ca3/pkg/authn/signing_key_strategy.go#L15-L25
Research log
- redact-secret/redact-secret#860Research issue
- redact-secret/redact-secret#914Research issue
- redact-secret/redact-secret-benchmarks#436Research issue
- Final evidence, pinned to a commit/redact-secret/redact-secret/blob/8b6a5fde52ecb4dfce13f09c7a947062d21483c7/docs/audits/evidence/860/inngest.md