redact-secret · Report
Secret API key
Langfuse project/organization secret key as the issuer mints it: sk-lf- plus a lowercase UUIDv4 (42 characters). Paired with the public pk-lf- key.
Research record
3 events in the review history: 2 observed, 1 reviewed. Latest: observed on 2026-09-24 by automation, project maintainer. Project-maintained review is not independent validation. The family record at this release.
Format
What it looks like
- Descriptive pattern
^sk-lf-[0-9a-f]{8}-[0-9a-f]{4}-4[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$
Parts are shown as recorded. Evidence classes belong to the facts below; no class is assigned to a part.
Format facts
Tool corroborated ·
tool-corroboration· current · observed 2026-09-24Pinned scanner rules are consistent with the contract grammar (2 artifacts: betterleaks; trufflehog 3.97.4).
- betterleaks/betterleaks @ main: config/betterleaks.tomlscanner-rule-source · last read 2026-09-24 · latest outcome read · supports betterleaks: langfuse-secret-key.1
- trufflesecurity/trufflehog @ v3.97.4: pkg/detectors/langfuse/langfuse.goscanner-rule-source · last read 2026-09-24 · latest outcome read · supports trufflehog 3.97.4: langfuse/langfuse
Provider documented ·
field-prefix· current · observed 2026-09-24prefix: Secret keys start sk-lf-; the public sibling starts pk-lf-.
- langfuse.com/docs/administration/rbacprovider-documentation · last read 2026-09-24 · latest outcome read · supports prefix: Secret keys start sk-lf-; the public sibling starts pk-lf-.
- langfuse.com/docs/observability/sdk/overviewprovider-documentation · last read 2026-09-24 · latest outcome read · supports prefix: Secret keys start sk-lf-; the public sibling starts pk-lf-.
- langfuse.com/docs/api-and-data-platform/features/public-apiprovider-documentation · last read 2026-09-24 · latest outcome read · supports prefix: Secret keys start sk-lf-; the public sibling starts pk-lf-.
Provider documented ·
field-public-sibling· current · observed 2026-09-24public-sibling: pk-lf- is the public key; browser SDKs need only it, and Langfuse says never to expose the secret key in frontend code.
- langfuse.com/docs/observability/sdk/typescript/guide-webprovider-documentation · last read 2026-09-24 · latest outcome read · supports public-sibling: pk-lf- is the public key; browser SDKs need only it, and Langfuse says never to expose the secret key in frontend code.
Provider documented ·
field-contexts· current · observed 2026-09-24contexts: LANGFUSE_SECRET_KEY / LANGFUSE_PUBLIC_KEY / LANGFUSE_BASE_URL env; secret_key / secretKey SDK args; Basic auth public-key:secret-key (curl -u); OTLP Authorization=Basic <base64 pk:sk>.
- langfuse.com/integrations/native/opentelemetryprovider-documentation · last read 2026-09-24 · latest outcome read · supports contexts: LANGFUSE_SECRET_KEY / LANGFUSE_PUBLIC_KEY / LANGFUSE_BASE_URL env; secret_key / secretKey SDK args; Basic auth public-key:secret-key (curl -u); OTLP Authorization=Basic <base64 pk:sk>.
- langfuse.com/docs/observability/sdk/overviewprovider-documentation · last read 2026-09-24 · latest outcome read · supports contexts: LANGFUSE_SECRET_KEY / LANGFUSE_PUBLIC_KEY / LANGFUSE_BASE_URL env; secret_key / secretKey SDK args; Basic auth public-key:secret-key (curl -u); OTLP Authorization=Basic <base64 pk:sk>.
- langfuse.com/docs/api-and-data-platform/features/public-apiprovider-documentation · last read 2026-09-24 · latest outcome read · supports contexts: LANGFUSE_SECRET_KEY / LANGFUSE_PUBLIC_KEY / LANGFUSE_BASE_URL env; secret_key / secretKey SDK args; Basic auth public-key:secret-key (curl -u); OTLP Authorization=Basic <base64 pk:sk>.
Provider documented ·
field-body· current · observed 2026-09-24body: Lowercase RFC 4122 UUIDv4 (8-4-4-4-12 hex with hyphens; version nibble 4; variant nibble 8/9/a/b), minted by crypto.randomUUID(); 42 characters total.
- langfuse/langfuse @ dbf5107df264bfcb0613a29237143e78ce16ca8a: packages/shared/src/server/auth/apiKeys.tsprovider-sdk-source · last read 2026-09-24 · latest outcome read · supports body: Lowercase RFC 4122 UUIDv4 (8-4-4-4-12 hex with hyphens; version nibble 4; variant nibble 8/9/a/b), minted by crypto.randomUUID(); 42 characters total.
- langfuse/langfuse @ 763147beed6e: src/features/publicApi/lib/apiKeys.tsprovider-sdk-source · last read 2026-09-24 · latest outcome read · supports earliest generator, same shape
- langfuse/langfuse @ dbf5107df264bfcb0613a29237143e78ce16ca8a: web/src/__tests__/server/api-auth.servertest.tsprovider-sdk-source · last read 2026-09-24 · latest outcome read · supports test comment: UUIDs only use hex digits and hyphens
Tool corroborated ·
field-body-corroboration· current · observed 2026-09-24body-corroboration: Peers match sk-lf- + 8-4-4-4-12 lowercase hex without checking the v4 nibbles; trufflehog also requires a langfuse keyword within 40 characters before and a pk-lf- key.
- betterleaks/betterleaks @ main: config/betterleaks.tomlscanner-rule-source · last read 2026-09-24 · latest outcome read · supports body-corroboration: Peers match sk-lf- + 8-4-4-4-12 lowercase hex without checking the v4 nibbles; trufflehog also requires a langfuse keyword within 40 characters before and a pk-lf- key.
- github.com/koki-develop/mask-go/pull/179scanner-rule-source · last read 2026-09-24 · latest outcome read · supports community; treats uppercase as equivalent
- trufflesecurity/trufflehog @ main: pkg/detectors/langfuse/langfuse.goscanner-rule-source · last read 2026-09-24 · latest outcome read · supports body-corroboration: Peers match sk-lf- + 8-4-4-4-12 lowercase hex without checking the v4 nibbles; trufflehog also requires a langfuse keyword within 40 characters before and a pk-lf- key.
Provider documented ·
field-masked-display· current · observed 2026-09-24masked-display: Display form is the first 6 characters + "..." + the last 4 (sk-lf-...<4 hex>).
- langfuse/langfuse @ dbf5107df264bfcb0613a29237143e78ce16ca8a: packages/shared/src/server/auth/apiKeys.tsprovider-sdk-source · last read 2026-09-24 · latest outcome read · supports masked-display: Display form is the first 6 characters + "..." + the last 4 (sk-lf-...<4 hex>).
Provider documented ·
field-gateway-bearer· current · observed 2026-09-24gateway-bearer: The AI gateway accepts the secret alone as Authorization: Bearer or x-api-key, with no pk-lf- beside it.
- langfuse/langfuse @ dbf5107df264bfcb0613a29237143e78ce16ca8a: ai-gateway/src/http.rsprovider-sdk-source · last read 2026-09-24 · latest outcome read · supports gateway-bearer: The AI gateway accepts the secret alone as Authorization: Bearer or x-api-key, with no pk-lf- beside it.
- langfuse/langfuse @ dbf5107df264bfcb0613a29237143e78ce16ca8a: web/src/features/ai-gateway/server/apiKey/gatewayApiKeyService.tsprovider-sdk-source · last read 2026-09-24 · latest outcome read · supports gateway-bearer: The AI gateway accepts the secret alone as Authorization: Bearer or x-api-key, with no pk-lf- beside it.
Unresolved ·
field-self-hosted-values· current · observed 2026-09-24self-hosted-values: Self-hosted operator-defined keys can be any string (headless init) or any sk-lf- string (admin API). Outside the minted-shape claim; not fixtured and not asserted silent.
- langfuse/langfuse @ dbf5107df264bfcb0613a29237143e78ce16ca8a: web/src/ee/features/admin-api/server/projects/projectById/apiKeys/index.tsprovider-sdk-source · last read 2026-09-24 · latest outcome read · supports self-hosted-values: Self-hosted operator-defined keys can be any string (headless init) or any sk-lf- string (admin API). Outside the minted-shape claim; not fixtured and not asserted silent.
- langfuse/langfuse @ dbf5107df264bfcb0613a29237143e78ce16ca8a: web/src/initialize.tsprovider-sdk-source · last read 2026-09-24 · latest outcome read · supports self-hosted-values: Self-hosted operator-defined keys can be any string (headless init) or any sk-lf- string (admin API). Outside the minted-shape claim; not fixtured and not asserted silent.
- langfuse.com/self-hosting/administration/headless-initializationprovider-sdk-source · last read 2026-09-24 · latest outcome read · supports self-hosted-values: Self-hosted operator-defined keys can be any string (headless init) or any sk-lf- string (admin API). Outside the minted-shape claim; not fixtured and not asserted silent.
Unresolved ·
field-sk-lf-gw· current · observed 2026-09-24sk-lf-gw-: A possible sk-lf-gw- gateway-key shape is mentioned in a PR description and UI stories only; gateway keys on main use the same sk-lf-<uuid> generator. Recorded, not claimed, not asserted silent.
- github.com/langfuse/langfuse/pull/17478provider-sdk-source · last read 2026-09-24 · latest outcome read · supports sk-lf-gw-: A possible sk-lf-gw- gateway-key shape is mentioned in a PR description and UI stories only; gateway keys on main use the same sk-lf-<uuid> generator. Recorded, not claimed, not asserted silent.
- langfuse/langfuse @ dbf5107df264bfcb0613a29237143e78ce16ca8a: web/src/features/ai-gateway/server/apiKey/gatewayApiKeyService.tsprovider-sdk-source · last read 2026-09-24 · latest outcome read · supports sk-lf-gw-: A possible sk-lf-gw- gateway-key shape is mentioned in a PR description and UI stories only; gateway keys on main use the same sk-lf-<uuid> generator. Recorded, not claimed, not asserted silent.
Unresolved ·
field-basic-auth-base64· current · observed 2026-09-24basic-auth-base64: In an Authorization: Basic header the secret appears only base64-encoded with its pk. No bare-value claim is made on the encoded form; product handling is reported separately if unsupported.
- langfuse.com/integrations/native/opentelemetryprovider-documentation · last read 2026-09-24 · latest outcome read · supports basic-auth-base64: In an Authorization: Basic header the secret appears only base64-encoded with its pk. No bare-value claim is made on the encoded form; product handling is reported separately if unsupported.
- langfuse.com/docs/api-and-data-platform/features/public-apiprovider-documentation · last read 2026-09-24 · latest outcome read · supports basic-auth-base64: In an Authorization: Basic header the secret appears only base64-encoded with its pk. No bare-value claim is made on the encoded form; product handling is reported separately if unsupported.
Unresolved ·
listed-references· current · observed 2026-09-24The legacy contract lists 4 references without stating which property each supports.
- langfuse/langfuse @ dbf5107df264bfcb0613a29237143e78ce16ca8a: packages/shared/src/server/auth/apiKeys.tsprovider-sdk-source · last read 2026-09-24 · latest outcome read · supports Listed as a reference by the legacy contract
- github.com/redact-secret/redact-secret-benchmarks/issues/221issue-or-discussion · last read 2026-09-24 · latest outcome read · supports Listed as a reference by the legacy contract
- langfuse.com/docs/observability/sdk/overviewprovider-documentation · last read 2026-09-24 · latest outcome read · supports Listed as a reference by the legacy contract
- langfuse.com/docs/api-and-data-platform/features/public-apiprovider-documentation · last read 2026-09-24 · latest outcome read · supports Listed as a reference by the legacy contract
Tool corroborated ·
dossier-research· current · observed 2026-09-24Legacy dossier research (verdict ready, tier T2) cited 3 sources; the dossier does not attribute sources to individual properties.
- langfuse/langfuse @ dbf5107df264bfcb0613a29237143e78ce16ca8a: packages/shared/src/server/auth/apiKeys.tsprovider-sdk-source · last read 2026-09-24 · latest outcome read · supports Cited by the legacy dossier research for this family
- redact-secret/redact-secret @ 8b6a5fde52ecb4dfce13f09c7a947062d21483c7: docs/audits/evidence/726/README.mdproject-research-note · last read 2026-09-27 · latest outcome read · supports Final research evidence recorded by the legacy dossier
- langfuse.com/docs/observability/sdk/overviewprovider-documentation · last read 2026-09-24 · latest outcome read · supports Cited by the legacy dossier research for this family
Tool corroborated ·
taxonomy-sources· current · observed 2026-09-24The legacy taxonomy lists 2 sources for this family. The taxonomy records no date; the dossier researchedAt is used as the observed-at date.
- langfuse/langfuse @ dbf5107df264bfcb0613a29237143e78ce16ca8a: packages/shared/src/server/auth/apiKeys.tsprovider-sdk-source · last read 2026-09-24 · latest outcome read · supports Listed as a source for this family in the legacy taxonomy
- langfuse.com/docs/observability/sdk/overviewprovider-documentation · last read 2026-09-24 · latest outcome read · supports Listed as a source for this family in the legacy taxonomy
Open questions
No open question is recorded for this revision.
Benchmark dossier notes
- Shape
- prefix
sk-lf-followed by a lowercase UUIDv4 in8-4-4-4-12form (42 characters in total), version nibble4and variant nibble in8 9 a b. This is what the provider's key generator builds, unchanged from the earliest code seen (2023-06) to 2026-09. Organization keys and the AI-gateway feature use the same generator. - Basis
- T2. Provider code (permalink above and the earliest generator file) gives the shape; provider docs give prefixes, roles, env vars (
LANGFUSE_SECRET_KEY) and Basic-auth use. TruffleHog's rule (pinned commit363923b, keyword- and public-key-gated) agrees. - Issuance
- not attempted; a free Hobby cloud account can create keys. The checklist is in benchmarks#221.
- Contract in core
- detector-families.md (frozen in the #726 record: issuer-minted keys only).
In this benchmark
- Fixtures
- 42
- Left readable
- 0
- Redacted too much
- 0
- False alarms
- 0
42 fixtures: 18 expect a redaction, 24 must stay quiet. See every row
| Evidence level | Fixtures | Left readable | Too much | False alarms |
|---|---|---|---|---|
| T2Tool-corroborated | 35 | 0 | 0 | 0 |
| T3Project policy | 7 | 0 | 0 | 0 |
Every scanner on the same fixtures
In run order. Counts are what each scanner recorded on this family's fixtures, whichever rules it has; a scanner with no rule for the family has nothing to report on it.
| Scanner | Fixtures | Left readable | Too much | False alarms |
|---|---|---|---|---|
| flare-redactRuntime library · 1.6.1 · Published npm package · secrets-only (pii, generic_assignment disabled) · JavaScript engineNo rule maps to it | 42 | 0 | 1 | 0 |
| gitleaksRepository scanner · 8.30.1 · Directory scan · default rulesNo rule maps to it | 42 | 6 | 2 | 1 |
| redact-secretProduct measured here · 0.1.0-beta.14 · Published npm package · default detectors1 detector mapped | 42 | 0 | 0 | 0 |
| trufflehogRepository scanner · 3.97.4 · Filesystem scan · verification disabled1 rule targets it | 42 | 13 | 0 | 1 |
Benchmark dossier questions
- Open caveat
- The provider documents prefixes and roles but no body grammar; the UUIDv4 body is provider code (the key generator), and self-hosted operators can set arbitrary values.
Looks like it, but isn't
- Collisions
pk-lf-public key has the same length and charset and differs by one letter; it is the main sibling control. Display form issk-lf-...plus four hex characters. Self-hosted headless init and the admin API accept operator chosen secrets (the docs' own example issk-lf-1234567890), and Langfuse's own log redactor is wider than UUID-only (sk-lf-[A-Za-z0-9_-]+). A possiblesk-lf-gw-gateway shape appears only in UI stories, a test fixture and a PR description; no code mints it.
Scanner rules for this family
| Scanner | Rule | What the rule matches |
|---|---|---|
| trufflehog · rules 3.97.4 | langfuse | langfuse keyword + sk-lf- + UUID |
No rule maps to this family in flare-redact, gitleaks, openredaction.
Fixtures in this family
| Fixture | Kind and evidence | redact-secret |
|---|---|---|
langfuse-secret-key-curl-basiclangfuse · documented-format-literal | Must redactT2 · Tool-corroborated | Redacted |
langfuse-secret-key-curl-basic-authlangfuse · documented-format-literal | Must redactT2 · Tool-corroborated | Redacted |
langfuse-secret-key-exportlangfuse · documented-format-literal | Must redactT2 · Tool-corroborated | Redacted |
langfuse-secret-key-gateway-bearerlangfuse · documented-format-literal | Must redactT2 · Tool-corroborated | Redacted |
langfuse-secret-key-handover-notelangfuse · documented-format-literal | Must redactT2 · Tool-corroborated | Redacted |
langfuse-secret-key-key-shape-barelangfuse · documented-format-literal | Must redactT2 · Tool-corroborated | Redacted |
langfuse-secret-key-key-shape-quotedlangfuse · documented-format-literal | Must redactT2 · Tool-corroborated | Redacted |
langfuse-secret-key-key-shape-unicode-crlflangfuse · documented-format-literal | Must redactT2 · Tool-corroborated | Redacted |
langfuse-secret-key-python-clientlangfuse · documented-format-literal | Must redactT2 · Tool-corroborated | Redacted |
langfuse-secret-key-secret-getlangfuse · documented-format-literal | Must redactT2 · Tool-corroborated | Redacted |
langfuse-secret-key-twin-base-cilangfuse · documented-format-literal | Must redactT2 · Tool-corroborated | Redacted |
langfuse-secret-key-twin-base-pythonlangfuse · documented-format-literal | Must redactT2 · Tool-corroborated | Redacted |
langfuse-secret-key-typescript-clientlangfuse · documented-format-literal | Must redactT2 · Tool-corroborated | Redacted |
langfuse-secret-key-variant-nibble-twinlangfuse · wrong-alphabet | Must not flagT2 · Tool-corroborated · twin | Quiet |
langfuse-secret-key-version-nibble-twin-wrong-alphabetlangfuse · wrong-alphabet | Must not flagT2 · Tool-corroborated · twin | Quiet |
langfuse-secret-key-browser-public-key-public-idlangfuse · public-identifier | Must not flagT2 · Tool-corroborated | Quiet |
langfuse-secret-key-compose-initlangfuse · documented-format-literal | Must redactT2 · Tool-corroborated | Redacted |
langfuse-secret-key-dotenvlangfuse · documented-format-literal | Must redactT2 · Tool-corroborated | Redacted |
langfuse-secret-key-env-example-placeholderlangfuse · documentation-placeholder | Must not flagT3 · Project policy | Quiet |
langfuse-secret-key-error-log-team-settingslangfuse · documented-format-literal | Must redactT2 · Tool-corroborated | Redacted |
langfuse-secret-key-hashed-key-row-encoded-valuelangfuse · benign-encoded-value | Must not flagT2 · Tool-corroborated | Quiet |
langfuse-secret-key-k8s-secret-ref-referencelangfuse · templated-reference | Must not flagT3 · Project policy | Quiet |
langfuse-secret-key-key-pair-doc-proselangfuse · prose-mention | Must not flagT3 · Project policy | Quiet |
langfuse-secret-key-litellm-configlangfuse · documented-format-literal | Must redactT2 · Tool-corroborated | Redacted |
langfuse-secret-key-long-last-group-twinlangfuse · wrong-length | Must not flagT2 · Tool-corroborated · twin | Quiet |
langfuse-secret-key-masklangfuse · benign-lookalike | Must not flagT3 · Project policy | Quiet |
langfuse-secret-key-masked-display-placeholderlangfuse · documentation-placeholder | Must not flagT3 · Project policy | Quiet |
langfuse-secret-key-no-hyphens-twinlangfuse · boundary-violation | Must not flagT2 · Tool-corroborated · twin | Quiet |
langfuse-secret-key-prefix-onlylangfuse · benign-lookalike | Must not flagT2 · Tool-corroborated | Quiet |
langfuse-secret-key-prefix-only-grep-near-misslangfuse · format-near-miss | Must not flagT2 · Tool-corroborated | Quiet |
langfuse-secret-key-public-idlangfuse · benign-lookalike | Must not flagT2 · Tool-corroborated | Quiet |
langfuse-secret-key-public-key-twinlangfuse · public-sibling-prefix | Must not flagT2 · Tool-corroborated · twin | Quiet |
langfuse-secret-key-python-env-lookup-referencelangfuse · templated-reference | Must not flagT3 · Project policy | Quiet |
langfuse-secret-key-referencelangfuse · benign-lookalike | Must not flagT3 · Project policy | Quiet |
langfuse-secret-key-region-hosts-env-public-idlangfuse · public-identifier | Must not flagT2 · Tool-corroborated | Quiet |
langfuse-secret-key-short-bodylangfuse · benign-lookalike | Must not flagT2 · Tool-corroborated | Quiet |
langfuse-secret-key-short-last-group-twinlangfuse · wrong-length | Must not flagT2 · Tool-corroborated · twin | Quiet |
langfuse-secret-key-trace-url-ids-public-idlangfuse · public-identifier | Must not flagT2 · Tool-corroborated | Quiet |
langfuse-secret-key-truncated-uuid-near-misslangfuse · format-near-miss | Must not flagT2 · Tool-corroborated | Quiet |
langfuse-secret-key-twin-base-dotenvlangfuse · documented-format-literal | Must redactT2 · Tool-corroborated | Redacted |
langfuse-secret-key-variant-nibble-twin-wrong-alphabetlangfuse · wrong-alphabet | Must not flagT2 · Tool-corroborated · twin | Quiet |
langfuse-secret-key-version-nibble-twinlangfuse · wrong-alphabet | Must not flagT2 · Tool-corroborated · twin | Quiet |
Sources
Documentation and code
- langfuse.com/docs/observability/sdk/overview
- github.com/langfuse/langfuse/blob/dbf5107df264bfcb0613a29237143e78ce16ca8a/packages/shared/src/server/auth/apiKeys.ts
Research log
- redact-secret/redact-secret-benchmarks#221Research issue
- redact-secret/redact-secret#726Research issue
- redact-secret/redact-secret#728Research issue
- Final evidence, pinned to a commit/redact-secret/redact-secret/blob/8b6a5fde52ecb4dfce13f09c7a947062d21483c7/docs/audits/evidence/726/README.md