redact-secret · Report
Application client secret
Client secret value for an app registration, with a digit+Q~ marker.
Research record
2 events in the review history: 1 observed, 1 reviewed. Latest: observed on 2026-09-24 by automation, project maintainer. Project-maintained review is not independent validation. The family record at this release.
Format
What it looks like
- Descriptive pattern
^[A-Za-z0-9_.~-]{3}\dQ~[A-Za-z0-9_.~-]{31,34}$
Parts are shown as recorded. Evidence classes belong to the facts below; no class is assigned to a part.
Format facts
Provider documented ·
provider-source· current · observed 2026-09-23Graph PowerShell Add-MgApplicationPassword SecretText examples (3 + 8Q~ + 34): Microsoft Graph PowerShell's Add-MgApplicationPassword reference (learn.microsoft.com) prints two example SecretText values, each 3 characters (equal to the printed 3-character Hint), the digit 8, the literal Q~, and 34 characters, 40 in total. The Q~ marker at offset 4 and the 8-variant's 40-character width come from these examples, not from a stated grammar. The 7Q~ 37-character previous format, the digit-to-length coupling and the body alphabet are corroborated only by Microsoft's security-utilities code (SEC101/156) and third-party tools
- learn.microsoft.com/en-us/powershell/module/microsoft.graph.applications/add-mgapplicationpassword?view=graph-powershell-1.0provider-documentation · last read 2026-09-24 · latest outcome read · supports Microsoft Graph PowerShell's Add-MgApplicationPassword reference (learn.microsoft.com) prints two example SecretText values, each 3 characters (equal to the printed 3-character Hint), the digit 8, the literal Q~, and 34 characters, 40 in total. The Q~ marker at offset 4 and the 8-variant's 40-character width come from these examples, not from a stated grammar. The 7Q~ 37-character previous format, the digit-to-length coupling and the body alphabet are corroborated only by Microsoft's security-utilities code (SEC101/156) and third-party tools
Provider documented ·
mutable-property-source· current · observed 2026-09-22Documentation for the one property varied in legacy twin fixtures (Purview Entra client secret definition): learn.microsoft.com states the client secret is "a combination of up to 40 characters" of letters, digits, "-", "_", "." and "~". It backs a length twin (41 characters) only; the digit+Q~ marker is example- and tool-corroborated (redact-secret#655) and the positive tier is unchanged
- learn.microsoft.com/en-us/purview/sit-defn-azure-ad-client-secretprovider-documentation · last read 2026-09-22 · latest outcome read · supports learn.microsoft.com states the client secret is "a combination of up to 40 characters" of letters, digits, "-", "_", "." and "~". It backs a length twin (41 characters) only; the digit+Q~ marker is example- and tool-corroborated (redact-secret#655) and the positive tier is unchanged
Tool corroborated ·
tool-corroboration· current · observed 2026-09-22Pinned scanner rules are consistent with the contract grammar (2 artifacts: gitleaks 8.30.1; trufflehog 3.97.4).
- gitleaks/gitleaks @ v8.30.1: config/gitleaks.tomlscanner-rule-source · last read 2026-10-04 · latest outcome read · supports gitleaks 8.30.1: gitleaks.toml
- trufflesecurity/trufflehog @ v3.97.4: pkg/detectors/azure_entra/serviceprincipal/v2/spv2.goscanner-rule-source · last read 2026-09-22 · latest outcome read · supports trufflehog 3.97.4: Azure Entra Service Principal v2
Provider documented ·
dossier-research· current · observed 2026-09-24Legacy dossier research (verdict ready, tier T1) cited 2 sources; the dossier does not attribute sources to individual properties.
- redact-secret/redact-secret @ 8b6a5fde52ecb4dfce13f09c7a947062d21483c7: docs/audits/evidence/655/README.mdproject-research-note · last read 2026-09-24 · latest outcome read · supports Final research evidence recorded by the legacy dossier
- learn.microsoft.com/en-us/powershell/module/microsoft.graph.applications/add-mgapplicationpassword?view=graph-powershell-1.0provider-documentation · last read 2026-09-24 · latest outcome read · supports Cited by the legacy dossier research for this family
Open questions
No open question is recorded for this revision.
Benchmark dossier notes
- Shape
- 3 leading characters, a digit, the literal
Q~, then 31 to 34 characters; the current generation is8Q~with 34 (40 in total), the previous7Q~with 31 (37 in total). Alphabet[A-Za-z0-9_.~-]; the first three characters are per-secret (the Graphhintequals them). A leading-occurs in issued secrets (four field reports, and Microsoft's own SEC101/156 rule allows it); core accepted it after redact-secret#707. - Basis
- two example secrets in the Graph PowerShell SDK reference show 40 characters with
8Q~at characters 4 to 6 (0-based offsets 3 to 5) (measured on the live page 2026-09-23; values not reproduced). A Graph SDK maintainer calls them "not real secrets"; Microsoft's own push gate flags them as SEC101/156. T1 by example only, accepted by maintainer ruling on the precedent ofterraform-cloud-tokenandsupabase-management-token. Corroboration:microsoft/security-utilitiesSEC101/156 (8Q~+ 34 and7Q~+ 31), GitLab, TruffleHog v2. Other Microsoft pages conflict without contradicting the examples: Graph REST says "16-64 characters", Purview says "up to 40" with noQ~. - Issuance
- not attempted; secrets can be created and deleted per app registration.
- Contract in core
- detector-families.md (row
microsoft-entra:application-client-secret); evidence #655 record.
In this benchmark
- Fixtures
- 45
- Left readable
- 0
- Redacted too much
- 0
- False alarms
- 0
45 fixtures: 20 expect a redaction, 25 must stay quiet. See every row
| Evidence level | Fixtures | Left readable | Too much | False alarms |
|---|---|---|---|---|
| T1Provider-documented | 20 | 0 | 0 | 0 |
| T2Tool-corroborated | 22 | 0 | 0 | 0 |
| T3Project policy | 3 | 0 | 0 | 0 |
Every scanner on the same fixtures
In run order. Counts are what each scanner recorded on this family's fixtures, whichever rules it has; a scanner with no rule for the family has nothing to report on it.
| Scanner | Fixtures | Left readable | Too much | False alarms |
|---|---|---|---|---|
| flare-redactRuntime library · 1.6.1 · Published npm package · secrets-only (pii, generic_assignment disabled) · JavaScript engineNo rule maps to it | 45 | 20 | 0 | 0 |
| gitleaksRepository scanner · 8.30.1 · Directory scan · default rules1 rule targets it | 45 | 3 | 0 | 0 |
| redact-secretProduct measured here · 0.1.0-beta.14 · Published npm package · default detectors1 detector mapped | 45 | 0 | 0 | 0 |
| trufflehogRepository scanner · 3.97.4 · Filesystem scan · verification disabled2 rules target it | 45 | 0 | 0 | 0 |
Benchmark dossier questions
- Open caveat
- T1 is a maintainer ruling on two SDK-example values (3 chars, 8Q~, 34, 40 total); the marker digit to length coupling and the alphabet come from Microsoft security-utilities code and tools.
Looks like it, but isn't
- Collisions
- no provider prefix; the
<digit>Q~marker is the identifying element.
Scanner rules for this family
| Scanner | Rule | What the rule matches |
|---|---|---|
| gitleaks · rules 8.30.1 | azure-ad-client-secret | 3 characters + digit + Q~ + 31-34 characters |
| trufflehog · rules 3.97.4 | azure_entra/serviceprincipal/v1 | secret or password keyword + 31-34 characters |
| trufflehog · rules 3.97.4 | azure_entra/serviceprincipal/v2 | 3 characters + digit + Q~ + 31-34 characters |
No rule maps to this family in flare-redact, openredaction.
Fixtures in this family
| Fixture | Kind and evidence | redact-secret |
|---|---|---|
microsoft-entra-client-secret-appsettings-azureadmicrosoft-entra · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
microsoft-entra-client-secret-az-ad-sp-create-for-rbacmicrosoft-entra · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
microsoft-entra-client-secret-az-login-service-principalmicrosoft-entra · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
microsoft-entra-client-secret-bommicrosoft-entra · multibyte-text-offsets | Must redactT1 · Provider-documented | Redacted |
microsoft-entra-client-secret-client-secret-credential-csharpmicrosoft-entra · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
microsoft-entra-client-secret-compose-environmentmicrosoft-entra · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
microsoft-entra-client-secret-digit-q-tilde-baremicrosoft-entra · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
microsoft-entra-client-secret-digit-q-tilde-quotedmicrosoft-entra · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
microsoft-entra-client-secret-digit-q-tilde-unicode-crlfmicrosoft-entra · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
microsoft-entra-client-secret-env-client-secretmicrosoft-entra · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
microsoft-entra-client-secret-jsonmicrosoft-entra · structured-text-value | Must redactT1 · Provider-documented | Redacted |
microsoft-entra-client-secret-leading-dash-baremicrosoft-entra · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
microsoft-entra-client-secret-leading-dash-quotedmicrosoft-entra · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
microsoft-entra-client-secret-leading-dash-unicode-crlfmicrosoft-entra · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
microsoft-entra-client-secret-markdownmicrosoft-entra · markdown-and-comment-value | Must redactT1 · Provider-documented | Redacted |
microsoft-entra-client-secret-no-final-newlinemicrosoft-entra · value-at-input-edges | Must redactT1 · Provider-documented | Redacted |
microsoft-entra-client-secret-pythonmicrosoft-entra · source-code-string-literal | Must redactT1 · Provider-documented | Redacted |
microsoft-entra-client-secret-single-quotesmicrosoft-entra · quoted-value-extent | Must redactT1 · Provider-documented | Redacted |
microsoft-entra-client-secret-tomlmicrosoft-entra · structured-text-value | Must redactT1 · Provider-documented | Redacted |
microsoft-entra-client-secret-yamlmicrosoft-entra · structured-text-value | Must redactT1 · Provider-documented | Redacted |
microsoft-entra-client-secret-bom-twinmicrosoft-entra · wrong-length | Must not flagT2 · Tool-corroborated · twin | Quiet |
microsoft-entra-client-secret-credential-listing-public-idmicrosoft-entra · public-identifier | Must not flagT2 · Tool-corroborated | Quiet |
microsoft-entra-client-secret-digit-q-tilde-bare-twinmicrosoft-entra · wrong-length | Must not flagT2 · Tool-corroborated · twin | Quiet |
microsoft-entra-client-secret-digit-q-tilde-marker-bare-twinmicrosoft-entra · boundary-violation | Must not flagT2 · Tool-corroborated · twin | Quiet |
microsoft-entra-client-secret-digit-q-tilde-marker-quoted-twinmicrosoft-entra · boundary-violation | Must not flagT2 · Tool-corroborated · twin | Quiet |
microsoft-entra-client-secret-digit-q-tilde-marker-unicode-crlf-twinmicrosoft-entra · boundary-violation | Must not flagT2 · Tool-corroborated · twin | Quiet |
microsoft-entra-client-secret-digit-q-tilde-quoted-twinmicrosoft-entra · wrong-length | Must not flagT2 · Tool-corroborated · twin | Quiet |
microsoft-entra-client-secret-digit-q-tilde-unicode-crlf-twinmicrosoft-entra · wrong-length | Must not flagT2 · Tool-corroborated · twin | Quiet |
microsoft-entra-client-secret-json-twinmicrosoft-entra · wrong-length | Must not flagT2 · Tool-corroborated · twin | Quiet |
microsoft-entra-client-secret-label-prosemicrosoft-entra · benign-lookalike | Must not flagT3 · Project policy | Quiet |
microsoft-entra-client-secret-leading-dash-bare-twinmicrosoft-entra · wrong-length | Must not flagT2 · Tool-corroborated · twin | Quiet |
microsoft-entra-client-secret-leading-dash-missing-markermicrosoft-entra · benign-lookalike | Must not flagT2 · Tool-corroborated | Quiet |
microsoft-entra-client-secret-leading-dash-quoted-twinmicrosoft-entra · wrong-length | Must not flagT2 · Tool-corroborated · twin | Quiet |
microsoft-entra-client-secret-leading-dash-short-suffixmicrosoft-entra · benign-lookalike | Must not flagT2 · Tool-corroborated | Quiet |
microsoft-entra-client-secret-leading-dash-unicode-crlf-twinmicrosoft-entra · wrong-length | Must not flagT2 · Tool-corroborated · twin | Quiet |
microsoft-entra-client-secret-markdown-twinmicrosoft-entra · wrong-length | Must not flagT2 · Tool-corroborated · twin | Quiet |
microsoft-entra-client-secret-maskmicrosoft-entra · benign-lookalike | Must not flagT3 · Project policy | Quiet |
microsoft-entra-client-secret-missing-markermicrosoft-entra · benign-lookalike | Must not flagT2 · Tool-corroborated | Quiet |
microsoft-entra-client-secret-no-final-newline-twinmicrosoft-entra · wrong-length | Must not flagT2 · Tool-corroborated · twin | Quiet |
microsoft-entra-client-secret-python-twinmicrosoft-entra · wrong-length | Must not flagT2 · Tool-corroborated · twin | Quiet |
microsoft-entra-client-secret-referencemicrosoft-entra · benign-lookalike | Must not flagT3 · Project policy | Quiet |
microsoft-entra-client-secret-short-suffixmicrosoft-entra · benign-lookalike | Must not flagT2 · Tool-corroborated | Quiet |
microsoft-entra-client-secret-single-quotes-twinmicrosoft-entra · wrong-length | Must not flagT2 · Tool-corroborated · twin | Quiet |
microsoft-entra-client-secret-toml-twinmicrosoft-entra · wrong-length | Must not flagT2 · Tool-corroborated · twin | Quiet |
microsoft-entra-client-secret-yaml-twinmicrosoft-entra · wrong-length | Must not flagT2 · Tool-corroborated · twin | Quiet |
Sources
Documentation and code
- learn.microsoft.com/en-us/powershell/module/microsoft.graph.applications/add-mgapplicationpassword?view=graph-powershell-1.0
Research log
- redact-secret/redact-secret#655Research issue
- redact-secret/redact-secret#707Research issue
- redact-secret/redact-secret-benchmarks#161Research issue
- Final evidence, pinned to a commit/redact-secret/redact-secret/blob/8b6a5fde52ecb4dfce13f09c7a947062d21483c7/docs/audits/evidence/655/README.md