redact-secret · Report
Secret access token (sk.)
sk. + a base64url JSON payload (eyJ lead) + . + a 22-character base64url signature.
Registered in the product at the 3b1a5aa re-pin (redact-secret PR #1227, unreleased), with a benchmark contract and a seeded corpus (#583, `beta8-583g`); the claim stays provisional until the conformance and arrival gates and the open ruling questions settle. Not a support claim. Handoff mapbox.md (READY, conditional on Q7); must not double-report with jwt.
Research record
From credential-evidence snapshot-2026.10.06.4 · records at 77ce761 · schema 1.8.0. It describes the research on the format, not what any scanner or the product does, and not a support status.
No research record for this family
snapshot-2026.10.06.4 has no family record for mapbox:secret-access-token, so its review state, format revision and format facts are not recorded here.
Not recorded
Format
Provider format research from credential-evidence snapshot-2026.10.06.4 · records at 77ce761 · schema 1.8.0.
Format not recorded
No format contract is recorded for this family in the pinned release.
Not recordedBenchmark dossier notes
From the provider dossier, as written. The evidence level above says how well the format is backed; a fact the dossier does not record is not shown.
- Shape
sk.+ a base64url JSON payload (eyJlead) +.+ a 22-character base64url signature.- Basis
- T1 for the prefix, three-part structure and alphabet (Mapbox "Tokens" docs and the provider parser
parse-mapbox-token, R1) and the 22-character signature (R5: one docs example plus provider fixtures). The payload has no stated floor or bound; theeyJ+ 20 floor is derived from provider code, so it is policy under ruling Q7 (open), never T1. Scanner rules (trufflehogmapbox, noseyparker) disagree and are T2; gitleaks 8.30.1 has no Mapbox rule. - Issuance
- not attempted; the handoff records no issuance gate.
- Contract in core
- detector-families.md (the detector is registered on
main, redact-secret#1108, unreleased). The benchmark contract and corpus arebenchmarks/lib/beta8/583g.tsandfixtures/generated/beta8/583g.mjs; a payload ofeyJ+ 19 and thetk.token are authored as unclaimed (T0) shapes.
In this benchmark
Fixture rows on the current run. Counts are for redact-secret in published · redact-secret 0.1.0-beta.14 mode.
No fixtures in this family yet
Nothing in the corpus targets it, so nothing is measured and no coverage is claimed.
Not measured
Looks like it, but isn't
Values the dossier records as resembling this credential without being one.
- Collisions
- public
pk.tokens (public by design, Q5);tk.temporary tokens (unclaimed, Q9); a three-part JWT with aneyJheader belongs tojwt(R7), and a Mapboxsk.token has a non-JWT header, sojwtdoes not claim it. The corpus holds a JWT with Mapbox-shaped claims as the no-double-report control.
Scanner rules for this family
Mapped by hand (reviewed 2026-09-30) from each scanner's pinned rule file, never from what a scanner found on the fixtures.
| Scanner | Rule | What the rule matches |
|---|---|---|
| trufflehog · rules 3.97.4 | mapbox | sk. + 80-240 [a-zA-Z0-9.-] |
No rule maps to this family in flare-redact, gitleaks, openredaction.
No fixtures in this family yet
Nothing in the corpus targets it, so nothing is measured and no coverage is claimed.
Not measured
Sources
Researched 2026-09-30.
Documentation and code
- github.com/redact-secret/redact-secret/blob/3b1a5aa9935c57416a026a44f45501fd41ffeac8/docs/audits/evidence/1014/mapbox.md
- github.com/mapbox/parse-mapbox-token/blob/015a6b470fdb489a2635a4889c9f5b1d545a512c/index.js
Research log
- redact-secret/redact-secret#1014Research issue
- redact-secret/redact-secret#1108Research issue
- redact-secret/redact-secret-benchmarks#583Research issue
- Final evidence, pinned to a commit/redact-secret/redact-secret/blob/3b1a5aa9935c57416a026a44f45501fd41ffeac8/docs/audits/evidence/1014/mapbox.md