Skip to content
Benchmarks

redact-secret · Report

OAuth access token

OAuth access token, prefixed lin_oauth_.

  • Linear
  • Detectors: none mapped
  • Run 2026-10-07
  • Mode published · redact-secret 0.1.0-beta.14
  • Dossier verdictIssuance-gated
  • Dossier evidence levelT1 · Provider-documented
  • Dossier researched2026-09-29
classifyFixture explicitly routes lin_oauth_ values to the "needs a separate format contract; related detector support is not evidence of parity" guard.

Research record

From credential-evidence snapshot-2026.10.06.4 · records at 77ce761 · schema 1.8.0. It describes the research on the format, not what any scanner or the product does, and not a support status.
  • Review stateDraft, not reviewed
  • Format revision1 · proposed, none current
  • ResearchResearched
  • Researched2026-09-29

What blocks the research

  • Issuance-gatedNo source of any class states the body length or alphabet, and Linear's own OAuth examples are unprefixed; needs one OAuth app issuing an access token (structure only).

2 events in the review history: 1 observed, 1 reviewed. Latest: observed on 2026-09-29 by automation, project maintainer. Project-maintained review is not independent validation. The family record at this release.

Format

Provider format research from credential-evidence snapshot-2026.10.06.4 · records at 77ce761 · schema 1.8.0.

What it looks like

Shape not recorded.

Format facts

Open questions

No open question is recorded for this revision.

Benchmark dossier notes

From the provider dossier, as written. The evidence level above says how well the format is backed; a fact the dossier does not record is not shown.
Shape
prefix lin_oauth_; no body grammar is established. Untested hypothesis, not evidence: lin_oauth_ + 64 lowercase hex, since Linear's unprefixed authorization-code example is 64 hex.
Basis
- provider changelog (T1, prefix): 2021-08-19, "OAuth access tokens ... lin_api_ and lin_oauth_". - provider docs placeholder (R4, prefix): the linear-solutions integration guides write lin_oauth_... and say the token "starts with lin_oauth_ (not lin_api_)". - provider docs examples (R5): the OAuth 2.0 page shows three example tokens, all unprefixed and 64 characters (the authorization-code access token is lowercase hex; the refresh and client-credentials tokens are [a-z0-9]). No lin_ string appears on that page or on the actor-authorization, app-manifest, GraphQL and agents pages. The prefixed format and the unprefixed examples are an unresolved contradiction that only a prefixed provider example or issuance settles. - Not evidence: 29 third-party redactor rules disagree on the length ({40}, {40,}, {32,}, {30,} with _-, {20,}, {10,}) and cite no sample; koki-develop/mask-go#147 finds no source and declines to ship a rule. - Searched with nothing further: gitleaks, betterleaks, trufflehog (linearapi only), noseyparker, Kingfisher, CredSweeper, secretlint and osv-scalibr have no lin_oauth_ rule; the linear/linear SDK monorepo has no lin_oauth or lin_api string. GitHub's list names the type without a regex.
Issuance
create an OAuth app in a free workspace; run the authorization-code flow once and the client_credentials (actor=app) flow once. For each access token record whether it starts lin_oauth_, the body length, whether the body is only [0-9a-f], and whether the refresh token carries a prefix; then revoke.
Contract in core
detector-families.md. The #367 contract lists this variant as an interim guard at T0, capped per #551; any rule written before issuance would be a guess.

In this benchmark

Fixture rows on the current run. Counts are for redact-secret in published · redact-secret 0.1.0-beta.14 mode.

No fixtures in this family yet

Nothing in the corpus targets it, so nothing is measured and no coverage is claimed.

Not measured

Benchmark dossier questions

Things the sources do not settle. They are listed so nobody reads them as settled.
Blocked by
No source of any class states the body length or alphabet, and Linear's own OAuth examples are unprefixed; needs one OAuth app issuing an access token (structure only).

Looks like it, but isn't

Values the dossier records as resembling this credential without being one.
Collisions
the provider's OAuth example is a bare 64-character hex string with no prefix, which is not distinguishable from ordinary hex.

Scanner rules for this family

Mapped by hand (reviewed 2026-09-30) from each scanner's pinned rule file, never from what a scanner found on the fixtures.

No peer rule maps to this family

None of the reviewed peer scanners has a rule that can match a credential of this family.

None mapped

0 of 0 rows

No fixtures in this family yet

Nothing in the corpus targets it, so nothing is measured and no coverage is claimed.

Not measured

Sources

Researched 2026-09-29.

Documentation and code

Research log

Other Linear families