Skip to content
Benchmarks

redact-secret · Report

Realtime client token (rt_)

Short-lived rt_ token that a server mints with a Studio API key (POST /v1/client/sessions) and a browser sends in the Sec-WebSocket-Protocol header; the prefix and carrier are provider-documented, the body is not.

  • Mistral AI
  • Detectors: none mapped
  • Run 2026-10-07
  • Mode published · redact-secret 0.1.0-beta.14
  • Dossier verdictIssuance-gated
  • Dossier evidence levelT1 · Provider-documented
  • Dossier researched2026-09-29
Beta.10 research disposition (redact-secret#780, benchmarks #384): pending, no corpus. No source states a body length, alphabet or checksum, so only a carrier-gated shape could be justified and it needs hands-on issuance first; keyed env and Bearer contexts are already redacted by generic paths, and the documented client_secret.value and WebSocket subprotocol carriers are a generic-carrier question, not a Mistral family. Not the Mistral Studio key (mistral:api-key).

Research record

From credential-evidence snapshot-2026.10.06.4 · records at 77ce761 · schema 1.8.0. It describes the research on the format, not what any scanner or the product does, and not a support status.
  • Review stateDraft, not reviewed
  • Format revision1 · proposed, none current
  • ResearchResearched
  • Researched2026-09-29

What blocks the research

  • Issuance-gatedT1 covers the rt_ prefix and carriers only; no source states body length, alphabet or checksum. Needs hands-on minting via POST /v1/client/sessions (checklist in

2 events in the review history: 1 observed, 1 reviewed. Latest: observed on 2026-09-29 by automation, project maintainer. Project-maintained review is not independent validation. The family record at this release.

Format

Provider format research from credential-evidence snapshot-2026.10.06.4 · records at 77ce761 · schema 1.8.0.

What it looks like

Shape not recorded.

Format facts

Open questions

No open question is recorded for this revision.

Benchmark dossier notes

From the provider dossier, as written. The evidence level above says how well the format is backed; a fact the dossier does not record is not shown.
Shape
prefix rt_; opaque body. Minted by POST /v1/client/sessions and returned as client_secret.value; the browser sends it in the Sec-WebSocket-Protocol header as realtime, <token>, which the page calls the only supported transport. Single-model scope and reusable until expiry. Stated lifetime is about 900 seconds, while the page's own example and search snippets suggest 60 seconds; the SDK exposes ttl_seconds, so treat lifetime as configurable and unresolved.
Basis
T1 for the prefix and the two carriers (provider docs). The Python SDK types the value as a plain string. No scanner has an rt_ rule. Body grammar: none.
Issuance
not attempted. Needs a Studio key with the create_client_session permission; the #780 checklist records prefix case, lengths across mints, charset and whether Bearer rt_ is accepted.
Contract in core
none recorded; #780 concluded pending, no implementation. Keyed environment and Bearer contexts fall to generic paths; the JSON and WebSocket carriers were measured as uncovered and framed as a generic-carrier question, not a Mistral family.

In this benchmark

Fixture rows on the current run. Counts are for redact-secret in published · redact-secret 0.1.0-beta.14 mode.

No fixtures in this family yet

Nothing in the corpus targets it, so nothing is measured and no coverage is claimed.

Not measured

Benchmark dossier questions

Things the sources do not settle. They are listed so nobody reads them as settled.
Blocked by
T1 covers the rt_ prefix and carriers only; no source states body length, alphabet or checksum. Needs hands-on minting via POST /v1/client/sessions (checklist in

Looks like it, but isn't

Values the dossier records as resembling this credential without being one.
Collisions
rt_ is a common identifier prefix (rt_config, rt_timeout), so a bare-prefix rule would be imprecise. Not the Studio key.

Scanner rules for this family

Mapped by hand (reviewed 2026-09-30) from each scanner's pinned rule file, never from what a scanner found on the fixtures.

No peer rule maps to this family

None of the reviewed peer scanners has a rule that can match a credential of this family.

None mapped

0 of 0 rows

No fixtures in this family yet

Nothing in the corpus targets it, so nothing is measured and no coverage is claimed.

Not measured

Sources

Researched 2026-09-29.

Documentation and code

  • docs.mistral.ai/studio-api/audio/speech_to_text/realtime_transcription/client_auth
  • github.com/redact-secret/redact-secret/issues/780
  • github.com/mistralai/client-python/blob/878fdda2ab8ad64439da729a9cfa23eb195dd73f/src/mistralai/client/models/clientsecret.py

Research log

Other Mistral AI families