Skip to content
Benchmarks

redact-secret · Report

Marketing API key

32-hex API key followed by a literal -us and a one- or two-digit data-center number; recognized only beside a same-line mailchimp keyword.

  • Mailchimp
  • Detectors: mailchimp-api-key
  • Run 2026-10-07
  • Mode published · redact-secret 0.1.0-beta.14
  • Dossier verdictReady
  • Dossier evidence levelT2 · Tool-corroborated
  • Dossier researched2026-09-25
redact-secret#313 (product PR #678) landed on the product main after 0.1.0-beta.6; the pinned published package predates it. Mandrill (transactional) keys are a separate product and not this family.

Research record

From credential-evidence snapshot-2026.10.06.4 · records at 77ce761 · schema 1.8.0. It describes the research on the format, not what any scanner or the product does, and not a support status.
  • Review stateDraft, not reviewed
  • Format revision1 · current
  • ResearchResearched
  • Researched2026-09-25

3 events in the review history: 2 observed, 1 reviewed. Latest: observed on 2026-09-25 by automation, project maintainer. Project-maintained review is not independent validation. The family record at this release.

Format

Provider format research from credential-evidence snapshot-2026.10.06.4 · records at 77ce761 · schema 1.8.0.

What it looks like

Descriptive pattern
^[0-9a-f]{32}-us[0-9]{1,2}$

Parts are shown as recorded. Evidence classes belong to the facts below; no class is assigned to a part.

Format facts

  • Provider documented · mutable-property-source · current · observed 2026-09-23

    Documentation for the one property varied in legacy twin fixtures (data-center suffix by example): the page states "if your API key is 0123456789abcdef0123456789abcde-us6, then the data center subdomain is us6" and that the <dc> URL prefix "corresponds to the data center for your account" — establishing a literal us<N> data-center suffix after the dash. It backs a marker twin only; the 32-byte hex body stays tool-corroborated and the positive tier is unchanged

    • mailchimp.com/developer/marketing/docs/fundamentals/provider-documentation · last read 2026-09-25 · latest outcome read · supports the page states "if your API key is 0123456789abcdef0123456789abcde-us6, then the data center subdomain is us6" and that the <dc> URL prefix "corresponds to the data center for your account" — establishing a literal us<N> data-center suffix after the dash. It backs a marker twin only; the 32-byte hex body stays tool-corroborated and the positive tier is unchanged
  • Tool corroborated · tool-corroboration · current · observed 2026-09-23

    Pinned scanner rules are consistent with the contract grammar (2 artifacts: gitleaks 8.30.1; trufflehog 3.97.4).

  • Unresolved · dossier-research · current · observed 2026-09-25

    Legacy dossier research (verdict ready, tier T2) cited 2 sources; the dossier does not attribute sources to individual properties.

  • Unresolved · taxonomy-sources · current · observed 2026-09-25

    The legacy taxonomy lists 1 source for this family. The taxonomy records no date; the dossier researchedAt is used as the observed-at date.

Open questions

No open question is recorded for this revision.

Benchmark dossier notes

From the provider dossier, as written. The evidence level above says how well the format is backed; a fact the dossier does not record is not shown.
Shape
32 hex characters, a literal -us, and a one- or two-digit data center number. Provider text gives the shape only through examples: the fundamentals page shows a 31-hex-character body with -us6, while Mailchimp's own WordPress plugin shows 32 hex with -us19. Non-us data-center literals and body letters g-z are outside the benchmark claim since 2026-09-24.
Basis
T2. Every scanner rule, a 2009 staff post and 111 of 115 public code candidates use 32. Tools split on suffix digits (trufflehog 1 to 2, gitleaks exactly 2, Nosey Parker 1 to 3), on uppercase hex (gitleaks and Nosey Parker accept it, trufflehog does not; 2 of 115 candidates had A-F) and on keyword gating. The 2009 staff post advises against regex validation because keys may change.
Issuance
Mailchimp account API key page. Not attempted. The UI shows only the first four characters of a key afterwards.
Contract in core
detector-families.md (mailchimp_api_key, confidence-gated on a mailchimp keyword; the complete shape can also be read without the keyword).

In this benchmark

Fixture rows on the current run. Counts are for redact-secret in published · redact-secret 0.1.0-beta.14 mode.
Fixtures
54
Left readable
0
Redacted too much
0
False alarms
0

54 fixtures: 24 expect a redaction, 30 must stay quiet. See every row

redact-secret fixture counts by evidence level
Evidence levelFixturesLeft readableToo muchFalse alarms
T2Tool-corroborated41000
T3Project policy9000
T0Pending review4000

Every scanner on the same fixtures

In run order. Counts are what each scanner recorded on this family's fixtures, whichever rules it has; a scanner with no rule for the family has nothing to report on it.

Counts per scanner on this family's fixtures
ScannerFixturesLeft readableToo muchFalse alarms
flare-redactRuntime library · 1.6.1 · Published npm package · secrets-only (pii, generic_assignment disabled) · JavaScript engineNo rule maps to it542210
gitleaksRepository scanner · 8.30.1 · Directory scan · default rules1 rule targets it54610
redact-secretProduct measured here · 0.1.0-beta.14 · Published npm package · default detectors1 detector mapped54000
trufflehogRepository scanner · 3.97.4 · Filesystem scan · verification disabled1 rule targets it54002

Benchmark dossier questions

Things the sources do not settle. They are listed so nobody reads them as settled.
Open caveat
The provider states the shape only by examples, one with a 31-character body; length 32 follows scanners and a 2009 staff regex. Hex case and data-center literals are undecided. Needs one issued key.

Looks like it, but isn't

Values the dossier records as resembling this credential without being one.
Collisions
the usNN label and the four-character key preview are public; a 32-hex body alone matches any MD5-style digest, which is why the detector is keyword-gated.

Scanner rules for this family

Mapped by hand (reviewed 2026-09-30) from each scanner's pinned rule file, never from what a scanner found on the fixtures.
Peer scanner rules that target this family
ScannerRuleWhat the rule matches
gitleaks · rules 8.30.1mailchimp-api-keymailchimp keyword + 32 hex + -us + digits
trufflehog · rules 3.97.4mailchimp32 hex + -us + 1-2 digits

No rule maps to this family in flare-redact, openredaction.

54 of 54 rows

Fixtures in this family

54 rows, redact-secret's outcome on each. Rows that need a look come first (0), then the rest in corpus order. Choose "Every scanner" to see each scanner's outcome for the same rows.
Fixtures in Marketing API key
FixtureKind and evidenceredact-secret
mailchimp-api-key-actions-envmailchimp · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
mailchimp-api-key-client-logmailchimp · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
mailchimp-api-key-compose-envmailchimp · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
mailchimp-api-key-curl-bearermailchimp · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
mailchimp-api-key-curl-usermailchimp · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
mailchimp-api-key-debug-request-headersmailchimp · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
mailchimp-api-key-envmailchimp · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
mailchimp-api-key-handoff-notemailchimp · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
mailchimp-api-key-heroku-configmailchimp · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
mailchimp-api-key-long-twinmailchimp · wrong-lengthMust not flagT2 · Tool-corroborated · twinQuiet
mailchimp-api-key-marketing-clientmailchimp · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
mailchimp-api-key-node-setconfigmailchimp · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
mailchimp-api-key-python-requests-authmailchimp · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
mailchimp-api-key-settings-jsonmailchimp · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
mailchimp-api-key-sha1-width-twinmailchimp · wrong-lengthMust not flagT2 · Tool-corroborated · twinQuiet
mailchimp-api-key-shell-exportmailchimp · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
mailchimp-api-key-single-digit-datacenter-baremailchimp · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
mailchimp-api-key-single-digit-datacenter-quotedmailchimp · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
mailchimp-api-key-single-digit-datacenter-unicode-crlfmailchimp · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
mailchimp-api-key-tfvarsmailchimp · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
mailchimp-api-key-ticket-paragraphmailchimp · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
mailchimp-api-key-two-digit-datacenter-baremailchimp · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
mailchimp-api-key-two-digit-datacenter-quotedmailchimp · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
mailchimp-api-key-two-digit-datacenter-unicode-crlfmailchimp · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
mailchimp-api-key-userinfo-urlmailchimp · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
mailchimp-api-key-v1-apikey-querymailchimp · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
mailchimp-api-key-alphabet-twinmailchimp · unsettled-evidence-inputPending reviewT0 · Pending · twinUnscored
mailchimp-api-key-audience-and-campaign-public-idmailchimp · public-identifierMust not flagT2 · Tool-corroboratedQuiet
mailchimp-api-key-datacenter-move-prosemailchimp · prose-mentionMust not flagT3 · Project policyQuiet
mailchimp-api-key-datacenter-note-prosemailchimp · prose-mentionMust not flagT3 · Project policyQuiet
mailchimp-api-key-docs-template-placeholdermailchimp · documentation-placeholderMust not flagT3 · Project policyQuiet
mailchimp-api-key-label-prosemailchimp · benign-lookalikeMust not flagT3 · Project policyQuiet
mailchimp-api-key-list-and-web-id-public-idmailchimp · public-identifierMust not flagT2 · Tool-corroboratedQuiet
mailchimp-api-key-list-webhook-url-public-idmailchimp · public-identifierMust not flagT2 · Tool-corroboratedQuiet
mailchimp-api-key-maskmailchimp · benign-lookalikeMust not flagT3 · Project policyQuiet
mailchimp-api-key-no-separator-twinmailchimp · boundary-violationMust not flagT2 · Tool-corroborated · twinQuiet
mailchimp-api-key-process-env-referencemailchimp · templated-referenceMust not flagT3 · Project policyQuiet
mailchimp-api-key-public-idmailchimp · benign-lookalikeMust not flagT2 · Tool-corroboratedQuiet
mailchimp-api-key-referencemailchimp · benign-lookalikeMust not flagT3 · Project policyQuiet
mailchimp-api-key-s3-region-key-near-missmailchimp · format-near-missMust not flagT2 · Tool-corroboratedQuiet
mailchimp-api-key-separator-twinmailchimp · boundary-violationMust not flagT2 · Tool-corroborated · twinQuiet
mailchimp-api-key-short-twinmailchimp · wrong-lengthMust not flagT2 · Tool-corroborated · twinQuiet
mailchimp-api-key-single-digit-datacenter-bare-twinmailchimp · unsettled-evidence-inputPending reviewT0 · Pending · twinUnscored
mailchimp-api-key-single-digit-datacenter-quoted-twinmailchimp · unsettled-evidence-inputPending reviewT0 · Pending · twinUnscored
mailchimp-api-key-single-digit-datacenter-unicode-crlf-twinmailchimp · unsettled-evidence-inputPending reviewT0 · Pending · twinUnscored
mailchimp-api-key-subscriber-hash-encoded-valuemailchimp · benign-encoded-valueMust not flagT2 · Tool-corroboratedQuiet
mailchimp-api-key-subscriber-hash-path-encoded-valuemailchimp · benign-encoded-valueMust not flagT2 · Tool-corroboratedQuiet
mailchimp-api-key-suffix-removed-twinmailchimp · prefix-near-missMust not flagT2 · Tool-corroborated · twinQuiet
mailchimp-api-key-two-digit-datacenter-bare-twinmailchimp · wrong-lengthMust not flagT2 · Tool-corroborated · twinQuiet
mailchimp-api-key-two-digit-datacenter-quoted-twinmailchimp · wrong-lengthMust not flagT2 · Tool-corroborated · twinQuiet

Sources

Researched 2026-09-25.

Documentation and code

Research log