Skip to content
Benchmarks

redact-secret · Report

Studio API key (unprefixed)

32 alphanumeric characters recognised only beside a same-line Mistral name, host or SDK constructor; no prefix is documented.

  • Mistral AI
  • Detectors: mistral-api-key
  • Run 2026-10-07
  • Mode published · redact-secret 0.1.0-beta.14
  • Dossier verdictReady
  • Dossier evidence levelT2 · Tool-corroborated
  • Dossier researched2026-09-29
Registry detector mistral-api-key since redact-secret#868 (registry pinned at cfe2aec); graduated from a Beta.10 arrival family (#384, research #781), contract in benchmarks/lib/beta8/384e.ts. T2, context-gated, no bare-value claim; generic coverage already redacts labelled forms, so the family adds the SDK-call-argument forms.

Research record

From credential-evidence snapshot-2026.10.06.4 · records at 77ce761 · schema 1.8.0. It describes the research on the format, not what any scanner or the product does, and not a support status.
  • Review stateDraft, not reviewed
  • Format revision1 · current
  • ResearchResearched
  • Researched2026-09-29

3 events in the review history: 2 observed, 1 reviewed. Latest: observed on 2026-09-29 by automation, project maintainer. Project-maintained review is not independent validation. The family record at this release.

Format

Provider format research from credential-evidence snapshot-2026.10.06.4 · records at 77ce761 · schema 1.8.0.

What it looks like

Descriptive pattern
^[A-Za-z0-9]{32}$

Parts are shown as recorded. Evidence classes belong to the facts below; no class is assigned to a part.

Format facts

Open questions

No open question is recorded for this revision.

Benchmark dossier notes

From the provider dossier, as written. The evidence level above says how well the format is backed; a fact the dossier does not record is not shown.
Shape
no prefix; 32 alphanumeric characters [A-Za-z0-9], recognised only beside Mistral context on the same line (a mistral key name, the api.mistral.ai host, a Mistral(...) call argument). Not stated in provider prose, and the SDK model is a plain optional string with no validation, but Mistral's own Admin API OpenAPI schema (APIKeyExtendedOUT, 2026-07-24) shows one full-length example key of exactly that shape.
Basis
T2 at best, and #868 says no provider has T1 here. Three tool rules (osv-scalibr, betterleaks, pleno-dlp) agree on 32 alphanumeric with a mandatory keyword gate, but read as one repeated assertion, not three measurements. The redact-secret#1013 pass added the missing second class twice: the provider example above, and three independent client validators (GitLens since 2025-05-27, GPTPortal, NeuroLink) that accept exactly ^[A-Za-z0-9]{32}$. That is 7 references, 7 owners and 3 non-summary classes, recorded in empirical-observations.json. GitGuardian states "Prefixed: No" for this detector but lists a second, prefixed "Mistral AI API Key v2" with an undisclosed prefix; no Mistral source mentions one, and the contract bounds it out. No pinned scanner (trufflehog 3.97.4, gitleaks 8.30.1) has a Mistral rule.
Issuance
not attempted. Console "Create new key" with name and expiry; "may take a few minutes to be usable" per the console message; connector scope option. Codestral keys use a separate console tab; their shape is undocumented.
Contract in core
detector-families.md, section Keyword-gated provider keys (#868).

In this benchmark

Fixture rows on the current run. Counts are for redact-secret in published · redact-secret 0.1.0-beta.14 mode.
Fixtures
68
Left readable
0
Redacted too much
0
False alarms
0

68 fixtures: 43 must stay quiet, 25 record project policy. See every row

redact-secret fixture counts by evidence level
Evidence levelFixturesLeft readableToo muchFalse alarms
T2Tool-corroborated18000
T3Project policy50000

Every scanner on the same fixtures

In run order. Counts are what each scanner recorded on this family's fixtures, whichever rules it has; a scanner with no rule for the family has nothing to report on it.

Counts per scanner on this family's fixtures
ScannerFixturesLeft readableToo muchFalse alarms
flare-redactRuntime library · 1.6.1 · Published npm package · secrets-only (pii, generic_assignment disabled) · JavaScript engineNo rule maps to it682320
gitleaksRepository scanner · 8.30.1 · Directory scan · default rulesNo rule maps to it68301
redact-secretProduct measured here · 0.1.0-beta.14 · Published npm package · default detectors1 detector mapped68000
trufflehogRepository scanner · 3.97.4 · Filesystem scan · verification disabledNo rule maps to it682500

Benchmark dossier questions

Things the sources do not settle. They are listed so nobody reads them as settled.
Open caveat
No provider prose states a shape; 32 alphanumeric rests on one provider API example, independent validators and scanner rules, so T2, never T1. Contextual only, never bare. The remaining gates are two product false negatives, not evidence: the Kubernetes name:/value: pair (redact-secret#1016) and the Python subscript assignment os.environ["MISTRAL_API_KEY"] = "…" (redact-secret#1038). One issued Studio key would still settle whether a prefixed "v2" key exists.

Looks like it, but isn't

Values the dossier records as resembling this credential without being one.
Collisions
any 32-hex hash, request id or other vendor's 32-byte key near the word "mistral". The realtime token below is minted by this key and is a different shape. Model ids such as mistral-large-latest are benign.

Scanner rules for this family

Mapped by hand (reviewed 2026-09-30) from each scanner's pinned rule file, never from what a scanner found on the fixtures.

No peer rule maps to this family

None of the reviewed peer scanners has a rule that can match a credential of this family.

None mapped

68 of 68 rows

Fixtures in this family

68 rows, redact-secret's outcome on each. Rows that need a look come first (0), then the rest in corpus order. Choose "Every scanner" to see each scanner's outcome for the same rows.
Fixtures in Studio API key (unprefixed)
FixtureKind and evidenceredact-secret
mistral-api-key-actions-env-literalmistral · documented-format-literalProject policyT3 · Project policyRedacted
mistral-api-key-auth-failure-logmistral · documented-format-literalProject policyT3 · Project policyRedacted
mistral-api-key-camel-constmistral · documented-format-literalProject policyT3 · Project policyRedacted
mistral-api-key-compose-envmistral · documented-format-literalProject policyT3 · Project policyRedacted
mistral-api-key-curl-headermistral · documented-format-literalProject policyT3 · Project policyRedacted
mistral-api-key-docker-run-envmistral · documented-format-literalProject policyT3 · Project policyRedacted
mistral-api-key-dotenvmistral · documented-format-literalProject policyT3 · Project policyRedacted
mistral-api-key-dotenv-altmistral · documented-format-literalProject policyT3 · Project policyRedacted
mistral-api-key-exportmistral · documented-format-literalProject policyT3 · Project policyRedacted
mistral-api-key-http-request-headermistral · documented-format-literalProject policyT3 · Project policyRedacted
mistral-api-key-inline-env-commandmistral · documented-format-literalProject policyT3 · Project policyRedacted
mistral-api-key-json-configmistral · documented-format-literalProject policyT3 · Project policyRedacted
mistral-api-key-k8s-env-valuemistral · documented-format-literalProject policyT3 · Project policyRedacted
mistral-api-key-key-shape-baremistral · documented-format-literalProject policyT3 · Project policyRedacted
mistral-api-key-key-shape-quotedmistral · documented-format-literalProject policyT3 · Project policyRedacted
mistral-api-key-key-shape-unicode-crlfmistral · documented-format-literalProject policyT3 · Project policyRedacted
mistral-api-key-langchain-kwargmistral · documented-format-literalProject policyT3 · Project policyRedacted
mistral-api-key-litellm-yamlmistral · documented-format-literalProject policyT3 · Project policyRedacted
mistral-api-key-other-host-curl-twinmistral · missing-context-markerMust not flagT3 · Project policy · twinQuiet
mistral-api-key-printenv-outputmistral · documented-format-literalProject policyT3 · Project policyRedacted
mistral-api-key-proxy-logmistral · documented-format-literalProject policyT3 · Project policyRedacted
mistral-api-key-python-ctormistral · documented-format-literalProject policyT3 · Project policyRedacted
mistral-api-key-python-environ-assignmistral · documented-format-literalProject policyT3 · Project policyRedacted
mistral-api-key-toml-config-keymistral · documented-format-literalProject policyT3 · Project policyRedacted
mistral-api-key-tool-callmistral · documented-format-literalProject policyT3 · Project policyRedacted
mistral-api-key-ts-ctormistral · documented-format-literalProject policyT3 · Project policyRedacted
mistral-api-key-actions-secret-referencemistral · templated-referenceMust not flagT3 · Project policyQuiet
mistral-api-key-angle-key-placeholdermistral · documentation-placeholderMust not flagT3 · Project policyQuiet
mistral-api-key-bare-in-prose-near-missmistral · format-near-missMust not flagT2 · Tool-corroboratedQuiet
mistral-api-key-bare-line-near-missmistral · format-near-missMust not flagT2 · Tool-corroboratedQuiet
mistral-api-key-base64-text-encoded-valuemistral · benign-encoded-valueMust not flagT2 · Tool-corroboratedQuiet
mistral-api-key-data-uri-encoded-valuemistral · benign-encoded-valueMust not flagT2 · Tool-corroboratedQuiet
mistral-api-key-docs-ctor-placeholdermistral · documentation-placeholderMust not flagT3 · Project policyQuiet
mistral-api-key-embedded-run-near-missmistral · format-near-missMust not flagT2 · Tool-corroboratedQuiet
mistral-api-key-env-reference-referencemistral · templated-referenceMust not flagT3 · Project policyQuiet
mistral-api-key-id-named-compose-twinmistral · missing-context-markerMust not flagT3 · Project policy · twinQuiet
mistral-api-key-id-named-env-alt-twinmistral · missing-context-markerMust not flagT3 · Project policy · twinQuiet
mistral-api-key-id-named-env-twinmistral · missing-context-markerMust not flagT3 · Project policy · twinQuiet
mistral-api-key-id-named-export-twinmistral · missing-context-markerMust not flagT3 · Project policy · twinQuiet
mistral-api-key-id-named-json-twinmistral · missing-context-markerMust not flagT3 · Project policy · twinQuiet
mistral-api-key-id-named-kwarg-twinmistral · missing-context-markerMust not flagT3 · Project policy · twinQuiet
mistral-api-key-id-named-tool-call-twinmistral · missing-context-markerMust not flagT3 · Project policy · twinQuiet
mistral-api-key-key-guidance-prosemistral · prose-mentionMust not flagT3 · Project policyQuiet
mistral-api-key-key-shape-bare-twinmistral · wrong-lengthMust not flagT2 · Tool-corroborated · twinQuiet
mistral-api-key-key-shape-quoted-twinmistral · wrong-lengthMust not flagT2 · Tool-corroborated · twinQuiet
mistral-api-key-key-shape-unicode-crlf-twinmistral · wrong-lengthMust not flagT2 · Tool-corroborated · twinQuiet
mistral-api-key-label-prosemistral · benign-lookalikeMust not flagT3 · Project policyQuiet
mistral-api-key-long-value-twinmistral · wrong-lengthMust not flagT2 · Tool-corroborated · twinQuiet
mistral-api-key-maskmistral · benign-lookalikeMust not flagT3 · Project policyQuiet
mistral-api-key-missing-keywordmistral · benign-lookalikeMust not flagT2 · Tool-corroboratedQuiet

Sources

Researched 2026-09-29.

Documentation and code

  • docs.mistral.ai/getting-started/quickstarts/studio/activate-and-generate-api-key
  • github.com/google/osv-scalibr/blob/main/veles/secrets/mistralapikey/detector.go
  • github.com/google/osv-scalibr/blob/110859bf0788ec406a93c1320f8d95c99ab60eea/veles/secrets/mistralapikey/detector.go
  • github.com/betterleaks/betterleaks/blob/2a387a5bad4290a84b9a1eb679bffe70611218cc/cmd/generate/config/rules/mistral.go
  • github.com/mistralai/platform-docs-public/blob/ecac75b617af32e87a6d59c5d9e39e7029fc35db/openapi-public-doc.yaml#L33436-L33455
  • github.com/gitkraken/vscode-gitlens/blob/6492b560fd704d62fc6e0bd4f86c4daa06a4d8e1/packages/plus/ai/src/providers/mistralProvider.ts#L156-L159

Research log

Other Mistral AI families