redact-secret · Report
OAuth access token
OAuth access token, prefixed lin_oauth_.
Research record
What blocks the research
- Issuance-gatedNo source of any class states the body length or alphabet, and Linear's own OAuth examples are unprefixed; needs one OAuth app issuing an access token (structure only).
2 events in the review history: 1 observed, 1 reviewed. Latest: observed on 2026-09-29 by automation, project maintainer. Project-maintained review is not independent validation. The family record at this release.
Format
What it looks like
Shape not recorded.
Format facts
Provider documented ·
dossier-research· current · observed 2026-09-29Legacy dossier research (verdict issuance-gated, tier T1) cited 4 sources; the dossier does not attribute sources to individual properties.
- linear/linear-solutions @ 4529f1e807d19e25f3c3889737f5b4bf90c242fe: integration_guides/README.mdother · last read 2026-09-29 · latest outcome read · supports Cited by the legacy dossier research for this family · #L11-L12
- redact-secret/redact-secret @ 378581770a87751d72e27529796c4f790649fd00: docs/audits/evidence/1012/linear-oauth-access-token.mdproject-research-note · last read 2026-09-29 · latest outcome read · supports Final research evidence recorded by the legacy dossier
- linear.app/changelog/2021-08-19-github-secret-scanningprovider-documentation · last read 2026-09-29 · latest outcome read · supports Cited by the legacy dossier research for this family
- linear.app/developers/oauth-2-0-authenticationother · last read 2026-09-29 · latest outcome read · supports Cited by the legacy dossier research for this family
Open questions
No open question is recorded for this revision.
Benchmark dossier notes
- Shape
- prefix
lin_oauth_; no body grammar is established. Untested hypothesis, not evidence:lin_oauth_+ 64 lowercase hex, since Linear's unprefixed authorization-code example is 64 hex. - Basis
- - provider changelog (T1, prefix): 2021-08-19, "OAuth access tokens ... lin_api_ and lin_oauth_". - provider docs placeholder (R4, prefix): the linear-solutions integration guides write
lin_oauth_...and say the token "starts withlin_oauth_(notlin_api_)". - provider docs examples (R5): the OAuth 2.0 page shows three example tokens, all unprefixed and 64 characters (the authorization-code access token is lowercase hex; the refresh and client-credentials tokens are[a-z0-9]). Nolin_string appears on that page or on the actor-authorization, app-manifest, GraphQL and agents pages. The prefixed format and the unprefixed examples are an unresolved contradiction that only a prefixed provider example or issuance settles. - Not evidence: 29 third-party redactor rules disagree on the length ({40},{40,},{32,},{30,}with_-,{20,},{10,}) and cite no sample; koki-develop/mask-go#147 finds no source and declines to ship a rule. - Searched with nothing further: gitleaks, betterleaks, trufflehog (linearapionly), noseyparker, Kingfisher, CredSweeper, secretlint and osv-scalibr have nolin_oauth_rule; thelinear/linearSDK monorepo has nolin_oauthorlin_apistring. GitHub's list names the type without a regex. - Issuance
- create an OAuth app in a free workspace; run the authorization-code flow once and the
client_credentials(actor=app) flow once. For each access token record whether it startslin_oauth_, the body length, whether the body is only[0-9a-f], and whether the refresh token carries a prefix; then revoke. - Contract in core
- detector-families.md. The #367 contract lists this variant as an interim guard at T0, capped per #551; any rule written before issuance would be a guess.
In this benchmark
No fixtures in this family yet
Nothing in the corpus targets it, so nothing is measured and no coverage is claimed.
Not measured
Benchmark dossier questions
- Blocked by
- No source of any class states the body length or alphabet, and Linear's own OAuth examples are unprefixed; needs one OAuth app issuing an access token (structure only).
Looks like it, but isn't
- Collisions
- the provider's OAuth example is a bare 64-character hex string with no prefix, which is not distinguishable from ordinary hex.
Scanner rules for this family
No peer rule maps to this family
None of the reviewed peer scanners has a rule that can match a credential of this family.
None mapped
No fixtures in this family yet
Nothing in the corpus targets it, so nothing is measured and no coverage is claimed.
Not measured
Sources
Documentation and code
- benchmarks/lib/assessment.ts (classifyFixture variant guard: "Variant support must not be inferred from a related family name.")
- linear.app/changelog/2021-08-19-github-secret-scanning
- linear.app/developers/oauth-2-0-authentication
- github.com/linear/linear-solutions/blob/4529f1e807d19e25f3c3889737f5b4bf90c242fe/integration_guides/README.md#L11-L12
Research log
- redact-secret/redact-secret#367Research issue
- redact-secret/redact-secret#642Research issue
- redact-secret/redact-secret#1012Research issue
- Final evidence, pinned to a commit/redact-secret/redact-secret/blob/378581770a87751d72e27529796c4f790649fd00/docs/audits/evidence/1012/linear-oauth-access-token.md