redact-secret · Report
Studio API key (unprefixed)
32 alphanumeric characters recognised only beside a same-line Mistral name, host or SDK constructor; no prefix is documented.
Research record
3 events in the review history: 2 observed, 1 reviewed. Latest: observed on 2026-09-29 by automation, project maintainer. Project-maintained review is not independent validation. The family record at this release.
Format
What it looks like
- Descriptive pattern
^[A-Za-z0-9]{32}$
Parts are shown as recorded. Evidence classes belong to the facts below; no class is assigned to a part.
Format facts
Tool corroborated ·
tool-corroboration· current · observed 2026-09-26Pinned scanner rules are consistent with the contract grammar (3 artifacts: betterleaks; osv-scalibr; pleno-dlp).
- betterleaks/betterleaks @ main: cmd/generate/config/rules/mistral.goscanner-rule-source · last read 2026-09-26 · latest outcome read · supports betterleaks: mistral-api-key: mistral keyword + [A-Z0-9]{32}, case-insensitive (Kingfisher aliases it)
- google/osv-scalibr @ main: veles/secrets/mistralapikey/detector.goscanner-rule-source · last read 2026-09-29 · latest outcome read · supports osv-scalibr: mistralapikey: \b[A-Za-z0-9]{32}\b beside a mistral context within 200 characters
- pkg.go.dev/github.com/plenoai/pleno-dlp/pkg/detectors/mistralscanner-rule-source · last read 2026-09-26 · latest outcome read · supports pleno-dlp: mistral detector: 32-character base62, keyword gate mandatory
Tool corroborated ·
field-shape· current · observed 2026-09-26shape: 32 alphanumeric characters, no prefix (Three rules from one assertion; nothing is a measurement of a real key.)
- betterleaks/betterleaks @ main: cmd/generate/config/rules/mistral.goscanner-rule-source · last read 2026-09-26 · latest outcome read · supports shape: 32 alphanumeric characters, no prefix
- google/osv-scalibr @ main: veles/secrets/mistralapikey/detector.goscanner-rule-source · last read 2026-09-29 · latest outcome read · supports shape: 32 alphanumeric characters, no prefix
- pkg.go.dev/github.com/plenoai/pleno-dlp/pkg/detectors/mistralscanner-rule-source · last read 2026-09-26 · latest outcome read · supports shape: 32 alphanumeric characters, no prefix
Tool corroborated ·
field-context· current · observed 2026-09-26context: a same-line mistral/codestral name, api.mistral.ai host or Mistral constructor
- betterleaks/betterleaks @ main: cmd/generate/config/rules/mistral.goscanner-rule-source · last read 2026-09-26 · latest outcome read · supports mistral keyword
- google/osv-scalibr @ main: veles/secrets/mistralapikey/detector.goscanner-rule-source · last read 2026-09-29 · latest outcome read · supports context regex within 200 characters
Tool corroborated ·
field-body-case· current · observed 2026-09-26body-case: upper- and lower-case letters both occur (The rules agree once case is folded; positives are mixed case.)
- betterleaks/betterleaks @ main: cmd/generate/config/rules/mistral.goscanner-rule-source · last read 2026-09-26 · latest outcome read · supports [A-Z0-9], case-insensitive
- google/osv-scalibr @ main: veles/secrets/mistralapikey/detector.goscanner-rule-source · last read 2026-09-29 · latest outcome read · supports [A-Za-z0-9]
Provider documented ·
field-transport· current · observed 2026-09-26transport: MISTRAL_API_KEY, the api_key constructor argument, Authorization: Bearer
- docs.mistral.ai/getting-started/quickstarts/studio/activate-and-generate-api-keyprovider-sdk-source · last read 2026-09-29 · latest outcome read · supports transport: MISTRAL_API_KEY, the api_key constructor argument, Authorization: Bearer
- github.com/mistralai/client-pythonprovider-sdk-source · last read 2026-09-26 · latest outcome read · supports api_key=os.getenv("MISTRAL_API_KEY", "")
Unresolved ·
field-sibling-shapes· current · observed 2026-09-26sibling-shapes: the Codestral key and the realtime rt_ token (research #780) are separate credentials whose shape is undecided (Not claimed; never a control.)
- github.com/redact-secret/redact-secret/issues/781third-party-writeup · last read 2026-09-26 · latest outcome read · supports Codestral: separate console tab, undocumented shape
- github.com/redact-secret/redact-secret/issues/780third-party-writeup · last read 2026-09-29 · latest outcome read · supports sibling-shapes: the Codestral key and the realtime rt_ token (research #780) are separate credentials whose shape is undecided
Unresolved ·
listed-references· current · observed 2026-09-26The legacy contract lists 6 references without stating which property each supports.
- docs.github.com/en/code-security/secret-scanning/introduction/supported-secret-scanning-patternsprovider-documentation · last read 2026-10-05 · latest outcome read · supports Listed as a reference by the legacy contract
- docs.mistral.ai/getting-started/quickstarts/studio/activate-and-generate-api-keyprovider-sdk-source · last read 2026-09-29 · latest outcome read · supports Listed as a reference by the legacy contract
- docs.mistral.ai/admin/identity-access/api-keysprovider-documentation · last read 2026-09-26 · latest outcome read · supports Listed as a reference by the legacy contract
- github.com/mistralai/client-pythonprovider-sdk-source · last read 2026-09-26 · latest outcome read · supports Listed as a reference by the legacy contract
- github.com/redact-secret/redact-secret/issues/868issue-or-discussion · last read 2026-09-26 · latest outcome read · supports Listed as a reference by the legacy contract
- github.com/redact-secret/redact-secret/issues/781third-party-writeup · last read 2026-09-26 · latest outcome read · supports Listed as a reference by the legacy contract
Tool corroborated ·
dossier-research· current · observed 2026-09-29Legacy dossier research (verdict ready, tier T2) cited 6 sources; the dossier does not attribute sources to individual properties.
- docs.mistral.ai/getting-started/quickstarts/studio/activate-and-generate-api-keyprovider-sdk-source · last read 2026-09-29 · latest outcome read · supports Cited by the legacy dossier research for this family
- betterleaks/betterleaks @ 2a387a5bad4290a84b9a1eb679bffe70611218cc: cmd/generate/config/rules/mistral.goother · last read 2026-09-29 · latest outcome read · supports Cited by the legacy dossier research for this family
- gitkraken/vscode-gitlens @ 6492b560fd704d62fc6e0bd4f86c4daa06a4d8e1: packages/plus/ai/src/providers/mistralProvider.tsother · last read 2026-09-29 · latest outcome read · supports Cited by the legacy dossier research for this family · #L156-L159
- google/osv-scalibr @ 110859bf0788ec406a93c1320f8d95c99ab60eea: veles/secrets/mistralapikey/detector.goother · last read 2026-09-29 · latest outcome read · supports Cited by the legacy dossier research for this family
- mistralai/platform-docs-public @ ecac75b617af32e87a6d59c5d9e39e7029fc35db: openapi-public-doc.yamlprovider-documentation · last read 2026-09-29 · latest outcome read · supports Cited by the legacy dossier research for this family · #L33436-L33455
- redact-secret/redact-secret @ add1188fed9993723c59fbce8c867086b9d2049a: docs/audits/evidence/1013/mistral-api-key.mdproject-research-note · last read 2026-09-29 · latest outcome read · supports Final research evidence recorded by the legacy dossier
Tool corroborated ·
taxonomy-sources· current · observed 2026-09-29The legacy taxonomy lists 2 sources for this family. The taxonomy records no date; the dossier researchedAt is used as the observed-at date.
- docs.mistral.ai/getting-started/quickstarts/studio/activate-and-generate-api-keyprovider-sdk-source · last read 2026-09-29 · latest outcome read · supports Listed as a source for this family in the legacy taxonomy
- google/osv-scalibr @ main: veles/secrets/mistralapikey/detector.goscanner-rule-source · last read 2026-09-29 · latest outcome read · supports Listed as a source for this family in the legacy taxonomy
Open questions
No open question is recorded for this revision.
Benchmark dossier notes
- Shape
- no prefix; 32 alphanumeric characters
[A-Za-z0-9], recognised only beside Mistral context on the same line (amistralkey name, theapi.mistral.aihost, aMistral(...)call argument). Not stated in provider prose, and the SDK model is a plain optional string with no validation, but Mistral's own Admin API OpenAPI schema (APIKeyExtendedOUT, 2026-07-24) shows one full-length example key of exactly that shape. - Basis
- T2 at best, and #868 says no provider has T1 here. Three tool rules (osv-scalibr, betterleaks, pleno-dlp) agree on 32 alphanumeric with a mandatory keyword gate, but read as one repeated assertion, not three measurements. The redact-secret#1013 pass added the missing second class twice: the provider example above, and three independent client validators (GitLens since 2025-05-27, GPTPortal, NeuroLink) that accept exactly
^[A-Za-z0-9]{32}$. That is 7 references, 7 owners and 3 non-summary classes, recorded inempirical-observations.json. GitGuardian states "Prefixed: No" for this detector but lists a second, prefixed "Mistral AI API Key v2" with an undisclosed prefix; no Mistral source mentions one, and the contract bounds it out. No pinned scanner (trufflehog 3.97.4, gitleaks 8.30.1) has a Mistral rule. - Issuance
- not attempted. Console "Create new key" with name and expiry; "may take a few minutes to be usable" per the console message; connector scope option. Codestral keys use a separate console tab; their shape is undocumented.
- Contract in core
- detector-families.md, section Keyword-gated provider keys (#868).
In this benchmark
- Fixtures
- 68
- Left readable
- 0
- Redacted too much
- 0
- False alarms
- 0
68 fixtures: 43 must stay quiet, 25 record project policy. See every row
| Evidence level | Fixtures | Left readable | Too much | False alarms |
|---|---|---|---|---|
| T2Tool-corroborated | 18 | 0 | 0 | 0 |
| T3Project policy | 50 | 0 | 0 | 0 |
Every scanner on the same fixtures
In run order. Counts are what each scanner recorded on this family's fixtures, whichever rules it has; a scanner with no rule for the family has nothing to report on it.
| Scanner | Fixtures | Left readable | Too much | False alarms |
|---|---|---|---|---|
| flare-redactRuntime library · 1.6.1 · Published npm package · secrets-only (pii, generic_assignment disabled) · JavaScript engineNo rule maps to it | 68 | 23 | 2 | 0 |
| gitleaksRepository scanner · 8.30.1 · Directory scan · default rulesNo rule maps to it | 68 | 3 | 0 | 1 |
| redact-secretProduct measured here · 0.1.0-beta.14 · Published npm package · default detectors1 detector mapped | 68 | 0 | 0 | 0 |
| trufflehogRepository scanner · 3.97.4 · Filesystem scan · verification disabledNo rule maps to it | 68 | 25 | 0 | 0 |
Benchmark dossier questions
- Open caveat
- No provider prose states a shape; 32 alphanumeric rests on one provider API example, independent validators and scanner rules, so T2, never T1. Contextual only, never bare. The remaining gates are two product false negatives, not evidence: the Kubernetes
name:/value:pair (redact-secret#1016) and the Python subscript assignmentos.environ["MISTRAL_API_KEY"] = "…"(redact-secret#1038). One issued Studio key would still settle whether a prefixed "v2" key exists.
Looks like it, but isn't
- Collisions
- any 32-hex hash, request id or other vendor's 32-byte key near the word "mistral". The realtime token below is minted by this key and is a different shape. Model ids such as
mistral-large-latestare benign.
Scanner rules for this family
No peer rule maps to this family
None of the reviewed peer scanners has a rule that can match a credential of this family.
None mapped
Fixtures in this family
| Fixture | Kind and evidence | redact-secret |
|---|---|---|
mistral-api-key-actions-env-literalmistral · documented-format-literal | Project policyT3 · Project policy | Redacted |
mistral-api-key-auth-failure-logmistral · documented-format-literal | Project policyT3 · Project policy | Redacted |
mistral-api-key-camel-constmistral · documented-format-literal | Project policyT3 · Project policy | Redacted |
mistral-api-key-compose-envmistral · documented-format-literal | Project policyT3 · Project policy | Redacted |
mistral-api-key-curl-headermistral · documented-format-literal | Project policyT3 · Project policy | Redacted |
mistral-api-key-docker-run-envmistral · documented-format-literal | Project policyT3 · Project policy | Redacted |
mistral-api-key-dotenvmistral · documented-format-literal | Project policyT3 · Project policy | Redacted |
mistral-api-key-dotenv-altmistral · documented-format-literal | Project policyT3 · Project policy | Redacted |
mistral-api-key-exportmistral · documented-format-literal | Project policyT3 · Project policy | Redacted |
mistral-api-key-http-request-headermistral · documented-format-literal | Project policyT3 · Project policy | Redacted |
mistral-api-key-inline-env-commandmistral · documented-format-literal | Project policyT3 · Project policy | Redacted |
mistral-api-key-json-configmistral · documented-format-literal | Project policyT3 · Project policy | Redacted |
mistral-api-key-k8s-env-valuemistral · documented-format-literal | Project policyT3 · Project policy | Redacted |
mistral-api-key-key-shape-baremistral · documented-format-literal | Project policyT3 · Project policy | Redacted |
mistral-api-key-key-shape-quotedmistral · documented-format-literal | Project policyT3 · Project policy | Redacted |
mistral-api-key-key-shape-unicode-crlfmistral · documented-format-literal | Project policyT3 · Project policy | Redacted |
mistral-api-key-langchain-kwargmistral · documented-format-literal | Project policyT3 · Project policy | Redacted |
mistral-api-key-litellm-yamlmistral · documented-format-literal | Project policyT3 · Project policy | Redacted |
mistral-api-key-other-host-curl-twinmistral · missing-context-marker | Must not flagT3 · Project policy · twin | Quiet |
mistral-api-key-printenv-outputmistral · documented-format-literal | Project policyT3 · Project policy | Redacted |
mistral-api-key-proxy-logmistral · documented-format-literal | Project policyT3 · Project policy | Redacted |
mistral-api-key-python-ctormistral · documented-format-literal | Project policyT3 · Project policy | Redacted |
mistral-api-key-python-environ-assignmistral · documented-format-literal | Project policyT3 · Project policy | Redacted |
mistral-api-key-toml-config-keymistral · documented-format-literal | Project policyT3 · Project policy | Redacted |
mistral-api-key-tool-callmistral · documented-format-literal | Project policyT3 · Project policy | Redacted |
mistral-api-key-ts-ctormistral · documented-format-literal | Project policyT3 · Project policy | Redacted |
mistral-api-key-actions-secret-referencemistral · templated-reference | Must not flagT3 · Project policy | Quiet |
mistral-api-key-angle-key-placeholdermistral · documentation-placeholder | Must not flagT3 · Project policy | Quiet |
mistral-api-key-bare-in-prose-near-missmistral · format-near-miss | Must not flagT2 · Tool-corroborated | Quiet |
mistral-api-key-bare-line-near-missmistral · format-near-miss | Must not flagT2 · Tool-corroborated | Quiet |
mistral-api-key-base64-text-encoded-valuemistral · benign-encoded-value | Must not flagT2 · Tool-corroborated | Quiet |
mistral-api-key-data-uri-encoded-valuemistral · benign-encoded-value | Must not flagT2 · Tool-corroborated | Quiet |
mistral-api-key-docs-ctor-placeholdermistral · documentation-placeholder | Must not flagT3 · Project policy | Quiet |
mistral-api-key-embedded-run-near-missmistral · format-near-miss | Must not flagT2 · Tool-corroborated | Quiet |
mistral-api-key-env-reference-referencemistral · templated-reference | Must not flagT3 · Project policy | Quiet |
mistral-api-key-id-named-compose-twinmistral · missing-context-marker | Must not flagT3 · Project policy · twin | Quiet |
mistral-api-key-id-named-env-alt-twinmistral · missing-context-marker | Must not flagT3 · Project policy · twin | Quiet |
mistral-api-key-id-named-env-twinmistral · missing-context-marker | Must not flagT3 · Project policy · twin | Quiet |
mistral-api-key-id-named-export-twinmistral · missing-context-marker | Must not flagT3 · Project policy · twin | Quiet |
mistral-api-key-id-named-json-twinmistral · missing-context-marker | Must not flagT3 · Project policy · twin | Quiet |
mistral-api-key-id-named-kwarg-twinmistral · missing-context-marker | Must not flagT3 · Project policy · twin | Quiet |
mistral-api-key-id-named-tool-call-twinmistral · missing-context-marker | Must not flagT3 · Project policy · twin | Quiet |
mistral-api-key-key-guidance-prosemistral · prose-mention | Must not flagT3 · Project policy | Quiet |
mistral-api-key-key-shape-bare-twinmistral · wrong-length | Must not flagT2 · Tool-corroborated · twin | Quiet |
mistral-api-key-key-shape-quoted-twinmistral · wrong-length | Must not flagT2 · Tool-corroborated · twin | Quiet |
mistral-api-key-key-shape-unicode-crlf-twinmistral · wrong-length | Must not flagT2 · Tool-corroborated · twin | Quiet |
mistral-api-key-label-prosemistral · benign-lookalike | Must not flagT3 · Project policy | Quiet |
mistral-api-key-long-value-twinmistral · wrong-length | Must not flagT2 · Tool-corroborated · twin | Quiet |
mistral-api-key-maskmistral · benign-lookalike | Must not flagT3 · Project policy | Quiet |
mistral-api-key-missing-keywordmistral · benign-lookalike | Must not flagT2 · Tool-corroborated | Quiet |
Sources
Documentation and code
- docs.mistral.ai/getting-started/quickstarts/studio/activate-and-generate-api-key
- github.com/google/osv-scalibr/blob/main/veles/secrets/mistralapikey/detector.go
- github.com/google/osv-scalibr/blob/110859bf0788ec406a93c1320f8d95c99ab60eea/veles/secrets/mistralapikey/detector.go
- github.com/betterleaks/betterleaks/blob/2a387a5bad4290a84b9a1eb679bffe70611218cc/cmd/generate/config/rules/mistral.go
- github.com/mistralai/platform-docs-public/blob/ecac75b617af32e87a6d59c5d9e39e7029fc35db/openapi-public-doc.yaml#L33436-L33455
- github.com/gitkraken/vscode-gitlens/blob/6492b560fd704d62fc6e0bd4f86c4daa06a4d8e1/packages/plus/ai/src/providers/mistralProvider.ts#L156-L159
Research log
- redact-secret/redact-secret#781Research issue
- redact-secret/redact-secret#774Research issue
- redact-secret/redact-secret#868Research issue
- redact-secret/redact-secret#866Research issue
- redact-secret/redact-secret#1013Research issue
- redact-secret/redact-secret-benchmarks#384Research issue
- Final evidence, pinned to a commit/redact-secret/redact-secret/blob/add1188fed9993723c59fbce8c867086b9d2049a/docs/audits/evidence/1013/mistral-api-key.md