Skip to content
Benchmarks

redact-secret · Report

API key (personal access token or service key)

LangSmith API key in its two documented roles, personal access token (lsv2_pt_) and workspace/org service key (lsv2_sk_); the 32+10 lowercase-hex segment grammar is tool-corroborated.

  • LangSmith (LangChain)
  • Detectors: langsmith-api-key
  • Run 2026-10-07
  • Mode published · redact-secret 0.1.0-beta.14
  • Dossier verdictReady
  • Dossier evidence levelT2 · Tool-corroborated
  • Dossier researched2026-09-24
Registry detector langsmith-api-key since redact-secret#728 (registry pinned at dad7868); graduated from a Beta.8 arrival family (#210, research #219), contract in benchmarks/lib/beta8/210.ts. Legacy ls__ keys, license keys, SCIM tokens, OAuth tokens and deployment keys are separate credentials this family does not claim.

Research record

From credential-evidence snapshot-2026.10.06.4 · records at 77ce761 · schema 1.8.0. It describes the research on the format, not what any scanner or the product does, and not a support status.
  • Review stateDraft, not reviewed
  • Format revision1 · current
  • ResearchResearched
  • Researched2026-09-24

3 events in the review history: 2 observed, 1 reviewed. Latest: observed on 2026-09-24 by automation, project maintainer. Project-maintained review is not independent validation. The family record at this release.

Format

Provider format research from credential-evidence snapshot-2026.10.06.4 · records at 77ce761 · schema 1.8.0.

What it looks like

Descriptive pattern
^lsv2_(?:pt|sk)_[0-9a-f]{32}_[0-9a-f]{10}$

Parts are shown as recorded. Evidence classes belong to the facts below; no class is assigned to a part.

Format facts

  • Tool corroborated · tool-corroboration · current · observed 2026-09-24

    Pinned scanner rules are consistent with the contract grammar (3 artifacts: poltergeist; titus (kingfisher.langchain.1/.2); trufflehog 3.97.4).

  • Provider documented · field-roles · current · observed 2026-09-24

    roles: Two API-key roles: Personal Access Token (inherits the creating user's permissions) and service key (workspace- or org-scoped). Shown once at creation.

    • docs.langchain.com/langsmith/create-account-api-keyprovider-documentation · last read 2026-09-24 · latest outcome read · supports roles: Two API-key roles: Personal Access Token (inherits the creating user's permissions) and service key (workspace- or org-scoped). Shown once at creation.
  • Provider documented · field-contexts · current · observed 2026-09-24

    contexts: LANGSMITH_API_KEY env (legacy LANGCHAIN_API_KEY), X-API-Key header, OTEL_EXPORTER_OTLP_HEADERS x-api-key=<key>; LANGSMITH_WORKSPACE_ID and LANGSMITH_ENDPOINT are non-secret neighbours.

    • docs.langchain.com/langsmith/trace-with-opentelemetryprovider-documentation · last read 2026-09-24 · latest outcome read · supports contexts: LANGSMITH_API_KEY env (legacy LANGCHAIN_API_KEY), X-API-Key header, OTEL_EXPORTER_OTLP_HEADERS x-api-key=<key>; LANGSMITH_WORKSPACE_ID and LANGSMITH_ENDPOINT are non-secret neighbours.
    • docs.langchain.com/langsmith/create-account-api-keyprovider-documentation · last read 2026-09-24 · latest outcome read · supports contexts: LANGSMITH_API_KEY env (legacy LANGCHAIN_API_KEY), X-API-Key header, OTEL_EXPORTER_OTLP_HEADERS x-api-key=<key>; LANGSMITH_WORKSPACE_ID and LANGSMITH_ENDPOINT are non-secret neighbours.
  • Provider documented · field-profile-file · current · observed 2026-09-24

    profile-file: SDK profiles in ~/.langsmith/config.json carry api_key; workspace id goes to X-Tenant-Id and is not itself a credential; the env lookup checks LANGSMITH_ then legacy LANGCHAIN_.

  • Tool corroborated · field-prefix · current · observed 2026-09-24

    prefix: lsv2_ followed by a role code pt (PAT) or sk (service key) and _. (The docs render masked lsv2_pt_/lsv2_sk_ displays (seen only indirectly, in a search snippet), which agrees but is not a grammar statement. The SDK redactor also keys on lsv2_(pt|sk)_ (provider code).)

  • Tool corroborated · field-segment-widths · current · observed 2026-09-24

    segment-widths: Exactly 32 characters, then _, then exactly 10 characters (51 total). (The provider SDK redactor accepts 32+ and any number of tails, and its own test fixture uses a 36-character first segment. Pending the hands-on checklist in #219.)

  • Unresolved · field-alphabet · current · observed 2026-09-24

    alphabet: Lowercase hex in both segments. (trufflehog is lowercase-only; Titus and Poltergeist are case-insensitive; the provider redactor is alphanumeric. Uppercase acceptance is not claimed and no uppercase twin is authored.)

  • Unresolved · field-tail-semantics · current · observed 2026-09-24

    tail-semantics: Whether the 10-character tail is a checksum, key-id fragment or random is not documented.

  • Unresolved · field-legacy-ls · current · observed 2026-09-24

    legacy-ls__: A legacy ls__ key form exists (provider SDK still redacts ls__[A-Za-z0-9]{16,}); its real length and alphabet are not established. Not claimed; only the ls__... placeholder appears, as a placeholder control.

    • langchain-ai/langsmith-sdk @ main: js/src/anonymizer/index.tsprovider-sdk-source · last read 2026-09-24 · latest outcome read · supports legacy-ls__: A legacy ls__ key form exists (provider SDK still redacts ls__[A-Za-z0-9]{16,}); its real length and alphabet are not established. Not claimed; only the ls__... placeholder appears, as a placeholder control.
  • Unresolved · field-sibling-credentials · current · observed 2026-09-24

    sibling-credentials: License key, SCIM bearer token, OAuth access/refresh tokens, internal X-Service-Key JWT and deployment keys are distinct LangSmith credentials outside this family. Their shapes are unknown or uncorroborated; none is fixtured as a control (they are secrets).

  • Unresolved · listed-references · current · observed 2026-09-24

    The legacy contract lists 4 references without stating which property each supports.

  • Tool corroborated · dossier-research · current · observed 2026-09-24

    Legacy dossier research (verdict ready, tier T2) cited 3 sources; the dossier does not attribute sources to individual properties.

  • Unresolved · taxonomy-sources · current · observed 2026-09-24

    The legacy taxonomy lists 1 source for this family. The taxonomy records no date; the dossier researchedAt is used as the observed-at date.

Open questions

No open question is recorded for this revision.

Benchmark dossier notes

From the provider dossier, as written. The evidence level above says how well the format is backed; a fact the dossier does not record is not shown.
Shape
prefix lsv2_pt_ (personal access token) or lsv2_sk_ (service key), then 32 lowercase hex characters, _, and 10 lowercase hex characters (51 in total). Every scanner agrees on the layout; TruffleHog merges the two roles, other rules split them. The docs render only masked forms of both prefixes. LangChain's own SDK redactor accepts a wider first segment ([A-Za-z0-9]{32,} with any number of _ tails). Whether the 10-hex tail is a checksum, a key-id fragment or random is not documented.
Basis
T2: TruffleHog rule (pinned commit above) plus other scanners; the provider page only documents roles, env vars (LANGSMITH_API_KEY, legacy LANGCHAIN_API_KEY) and headers (X-API-Key, OTLP x-api-key).
Issuance
not attempted; the free Developer tier can issue both roles. The checklist is in benchmarks#219.
Contract in core
detector-families.md (frozen in the #726 record, implemented under #728).

In this benchmark

Fixture rows on the current run. Counts are for redact-secret in published · redact-secret 0.1.0-beta.14 mode.
Fixtures
42
Left readable
0
Redacted too much
0
False alarms
0

42 fixtures: 18 expect a redaction, 24 must stay quiet. See every row

redact-secret fixture counts by evidence level
Evidence levelFixturesLeft readableToo muchFalse alarms
T2Tool-corroborated33000
T3Project policy9000

Every scanner on the same fixtures

In run order. Counts are what each scanner recorded on this family's fixtures, whichever rules it has; a scanner with no rule for the family has nothing to report on it.

Counts per scanner on this family's fixtures
ScannerFixturesLeft readableToo muchFalse alarms
flare-redactRuntime library · 1.6.1 · Published npm package · secrets-only (pii, generic_assignment disabled) · JavaScript engineNo rule maps to it421800
gitleaksRepository scanner · 8.30.1 · Directory scan · default rulesNo rule maps to it42701
redact-secretProduct measured here · 0.1.0-beta.14 · Published npm package · default detectors1 detector mapped42000
trufflehogRepository scanner · 3.97.4 · Filesystem scan · verification disabled1 rule targets it42000

Benchmark dossier questions

Things the sources do not settle. They are listed so nobody reads them as settled.
Open caveat
The provider documents roles and contexts but no prefix, length or alphabet; segment widths and lowercase hex are scanner-corroborated only (checklist in benchmarks#219).

Looks like it, but isn't

Values the dossier records as resembling this credential without being one.
Collisions
siblings that are not this family: legacy ls__ keys (provider code still redacts them; real shape unknown), self-hosted license key, SCIM bearer token, OAuth access and refresh tokens, the internal X-Service-Key JWT, and unconfirmed deployment keys. Public ids next to keys: workspace and organization UUIDs, project names, short_key, and ls_-prefixed trace metadata names such as ls_provider.

Scanner rules for this family

Mapped by hand (reviewed 2026-09-30) from each scanner's pinned rule file, never from what a scanner found on the fixtures.
Peer scanner rules that target this family
ScannerRuleWhat the rule matches
trufflehog · rules 3.97.4langsmithlsv2_pt_ or lsv2_sk_ + 32 hex + _ + 10 hex

No rule maps to this family in flare-redact, gitleaks, openredaction.

42 of 42 rows

Fixtures in this family

42 rows, redact-secret's outcome on each. Rows that need a look come first (0), then the rest in corpus order. Choose "Every scanner" to see each scanner's outcome for the same rows.
Fixtures in API key (personal access token or service key)
FixtureKind and evidenceredact-secret
langsmith-api-key-export-patlangsmith · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
langsmith-api-key-langgraph-clilangsmith · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
langsmith-api-key-op-readlangsmith · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
langsmith-api-key-pat-dotenvlangsmith · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
langsmith-api-key-pat-nested-run-metadatalangsmith · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
langsmith-api-key-pat-otlp-header-listlangsmith · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
langsmith-api-key-pat-profile-jsonlangsmith · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
langsmith-api-key-pat-shape-barelangsmith · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
langsmith-api-key-pat-shape-quotedlangsmith · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
langsmith-api-key-pat-shape-unicode-crlflangsmith · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
langsmith-api-key-runbooklangsmith · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
langsmith-api-key-service-key-legacy-exportlangsmith · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
langsmith-api-key-service-key-python-clientlangsmith · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
langsmith-api-key-service-key-workflow-envlangsmith · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
langsmith-api-key-service-key-x-api-keylangsmith · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
langsmith-api-key-short-tail-twinlangsmith · wrong-lengthMust not flagT2 · Tool-corroborated · twinQuiet
langsmith-api-key-twin-base-cilangsmith · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
langsmith-api-key-twin-base-dotenvlangsmith · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
langsmith-api-key-twin-base-jsonlangsmith · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
langsmith-api-key-env-example-placeholderlangsmith · documentation-placeholderMust not flagT3 · Project policyQuiet
langsmith-api-key-key-roles-doc-proselangsmith · prose-mentionMust not flagT3 · Project policyQuiet
langsmith-api-key-label-proselangsmith · benign-lookalikeMust not flagT3 · Project policyQuiet
langsmith-api-key-legacy-readme-placeholderlangsmith · documentation-placeholderMust not flagT3 · Project policyQuiet
langsmith-api-key-long-tail-twinlangsmith · wrong-lengthMust not flagT2 · Tool-corroborated · twinQuiet
langsmith-api-key-masklangsmith · benign-lookalikeMust not flagT3 · Project policyQuiet
langsmith-api-key-masked-short-key-placeholderlangsmith · documentation-placeholderMust not flagT3 · Project policyQuiet
langsmith-api-key-merged-segments-twinlangsmith · boundary-violationMust not flagT2 · Tool-corroborated · twinQuiet
langsmith-api-key-missing-tail-near-misslangsmith · format-near-missMust not flagT2 · Tool-corroboratedQuiet
langsmith-api-key-non-hex-body-twinlangsmith · wrong-alphabetMust not flagT2 · Tool-corroborated · twinQuiet
langsmith-api-key-non-hex-tail-twinlangsmith · wrong-alphabetMust not flagT2 · Tool-corroborated · twinQuiet
langsmith-api-key-prefix-onlylangsmith · benign-lookalikeMust not flagT2 · Tool-corroboratedQuiet
langsmith-api-key-prefix-only-grep-near-misslangsmith · format-near-missMust not flagT2 · Tool-corroboratedQuiet
langsmith-api-key-python-env-lookup-referencelangsmith · templated-referenceMust not flagT3 · Project policyQuiet
langsmith-api-key-referencelangsmith · benign-lookalikeMust not flagT3 · Project policyQuiet
langsmith-api-key-requirements-hash-encoded-valuelangsmith · benign-encoded-valueMust not flagT2 · Tool-corroboratedQuiet
langsmith-api-key-role-code-twinlangsmith · prefix-near-missMust not flagT2 · Tool-corroborated · twinQuiet
langsmith-api-key-short-bodylangsmith · benign-lookalikeMust not flagT2 · Tool-corroboratedQuiet
langsmith-api-key-short-first-segment-twinlangsmith · wrong-lengthMust not flagT2 · Tool-corroborated · twinQuiet
langsmith-api-key-trace-share-link-public-idlangsmith · public-identifierMust not flagT2 · Tool-corroboratedQuiet
langsmith-api-key-unknown-role-code-twinlangsmith · prefix-near-missMust not flagT2 · Tool-corroborated · twinQuiet
langsmith-api-key-workflow-secret-ref-referencelangsmith · templated-referenceMust not flagT3 · Project policyQuiet
langsmith-api-key-workspace-ids-env-public-idlangsmith · public-identifierMust not flagT2 · Tool-corroboratedQuiet

Sources

Researched 2026-09-24.

Documentation and code

  • docs.langchain.com/langsmith/create-account-api-key
  • github.com/trufflesecurity/trufflehog/blob/363923b901c911a9164f50b6c423f47c15372b1c/pkg/detectors/langsmith/langsmith.go

Research log