redact-secret · Report
Realtime client token (rt_)
Short-lived rt_ token that a server mints with a Studio API key (POST /v1/client/sessions) and a browser sends in the Sec-WebSocket-Protocol header; the prefix and carrier are provider-documented, the body is not.
Research record
What blocks the research
- Issuance-gatedT1 covers the rt_ prefix and carriers only; no source states body length, alphabet or checksum. Needs hands-on minting via POST /v1/client/sessions (checklist in
2 events in the review history: 1 observed, 1 reviewed. Latest: observed on 2026-09-29 by automation, project maintainer. Project-maintained review is not independent validation. The family record at this release.
Format
What it looks like
Shape not recorded.
Format facts
Provider documented ·
dossier-research· current · observed 2026-09-29Legacy dossier research (verdict issuance-gated, tier T1) cited 3 sources; the dossier does not attribute sources to individual properties.
- docs.mistral.ai/studio-api/audio/speech_to_text/realtime_transcription/client_authprovider-documentation · last read 2026-09-29 · latest outcome read · supports Cited by the legacy dossier research for this family
- mistralai/client-python @ 878fdda2ab8ad64439da729a9cfa23eb195dd73f: src/mistralai/client/models/clientsecret.pyprovider-sdk-source · last read 2026-09-29 · latest outcome read · supports Cited by the legacy dossier research for this family
- redact-secret/redact-secret @ add1188fed9993723c59fbce8c867086b9d2049a: docs/audits/evidence/1013/mistral-realtime-client-token.mdproject-research-note · last read 2026-09-29 · latest outcome read · supports Final research evidence recorded by the legacy dossier
Provider documented ·
taxonomy-sources· current · observed 2026-09-29The legacy taxonomy lists 2 sources for this family. The taxonomy records no date; the dossier researchedAt is used as the observed-at date.
- docs.mistral.ai/studio-api/audio/speech_to_text/realtime_transcription/client_authprovider-documentation · last read 2026-09-29 · latest outcome read · supports Listed as a source for this family in the legacy taxonomy
- github.com/redact-secret/redact-secret/issues/780third-party-writeup · last read 2026-09-29 · latest outcome read · supports Listed as a source for this family in the legacy taxonomy
Open questions
No open question is recorded for this revision.
Benchmark dossier notes
- Shape
- prefix
rt_; opaque body. Minted byPOST /v1/client/sessionsand returned asclient_secret.value; the browser sends it in theSec-WebSocket-Protocolheader asrealtime, <token>, which the page calls the only supported transport. Single-model scope and reusable until expiry. Stated lifetime is about 900 seconds, while the page's own example and search snippets suggest 60 seconds; the SDK exposesttl_seconds, so treat lifetime as configurable and unresolved. - Basis
- T1 for the prefix and the two carriers (provider docs). The Python SDK types the value as a plain string. No scanner has an
rt_rule. Body grammar: none. - Issuance
- not attempted. Needs a Studio key with the
create_client_sessionpermission; the #780 checklist records prefix case, lengths across mints, charset and whetherBearer rt_is accepted. - Contract in core
- none recorded; #780 concluded pending, no implementation. Keyed environment and
Bearercontexts fall to generic paths; the JSON and WebSocket carriers were measured as uncovered and framed as a generic-carrier question, not a Mistral family.
In this benchmark
No fixtures in this family yet
Nothing in the corpus targets it, so nothing is measured and no coverage is claimed.
Not measured
Benchmark dossier questions
- Blocked by
- T1 covers the rt_ prefix and carriers only; no source states body length, alphabet or checksum. Needs hands-on minting via POST /v1/client/sessions (checklist in
Looks like it, but isn't
- Collisions
rt_is a common identifier prefix (rt_config,rt_timeout), so a bare-prefix rule would be imprecise. Not the Studio key.
Scanner rules for this family
No peer rule maps to this family
None of the reviewed peer scanners has a rule that can match a credential of this family.
None mapped
No fixtures in this family yet
Nothing in the corpus targets it, so nothing is measured and no coverage is claimed.
Not measured
Sources
Documentation and code
- docs.mistral.ai/studio-api/audio/speech_to_text/realtime_transcription/client_auth
- github.com/redact-secret/redact-secret/issues/780
- github.com/mistralai/client-python/blob/878fdda2ab8ad64439da729a9cfa23eb195dd73f/src/mistralai/client/models/clientsecret.py
Research log
- redact-secret/redact-secret#780Research issue
- redact-secret/redact-secret#774Research issue
- redact-secret/redact-secret-benchmarks#384Research issue
- redact-secret/redact-secret#1013Research issue
- Final evidence, pinned to a commit/redact-secret/redact-secret/blob/add1188fed9993723c59fbce8c867086b9d2049a/docs/audits/evidence/1013/mistral-realtime-client-token.md