redact-secret · Report
API key
napi_-prefixed API key (personal, organization or project-scoped); the 64-character alphanumeric body floor is tool-corroborated.
Research record
3 events in the review history: 2 observed, 1 reviewed. Latest: observed on 2026-09-25 by automation, project maintainer. Project-maintained review is not independent validation. The family record at this release.
Format
What it looks like
- Descriptive pattern
^napi_[A-Za-z0-9]{64,}$
Parts are shown as recorded. Evidence classes belong to the facts below; no class is assigned to a part.
Format facts
Provider documented ·
mutable-property-source· current · observed 2026-09-24Documentation for the one property varied in legacy twin fixtures (napi_ prefix (2025-01-31 changelog)): Neon states that newly created API keys are prefixed with napi_ so that secret scanning can rely on an identifiable marker, and that existing unprefixed keys stay valid. It states no body length or alphabet. Twins mutate the prefix, its delimiter, the body length floor or the body alphabet
- neon.com/docs/changelog/2025-01-31provider-documentation · last read 2026-09-25 · latest outcome read · supports Neon states that newly created API keys are prefixed with napi_ so that secret scanning can rely on an identifiable marker, and that existing unprefixed keys stay valid. It states no body length or alphabet. Twins mutate the prefix, its delimiter, the body length floor or the body alphabet
Tool corroborated ·
tool-corroboration· current · observed 2026-09-24Pinned scanner rules are consistent with the contract grammar (2 artifacts: betterleaks; mask-go).
- betterleaks/betterleaks @ 6cf4f1a29160b68be7c6390599b9b773234e5a43: cmd/generate/config/rules/neon.goscanner-rule-source · last read 2026-09-25 · latest outcome read · supports betterleaks: neon-api-key
- koki-develop/mask-go @ 3ff232051d4d224314b400d9e973c5a8c7d405d5: builtin_neon_api_key.goscanner-rule-source · last read 2026-09-25 · latest outcome read · supports mask-go: neon-api-key
Provider documented ·
field-prefix· current · observed 2026-09-24prefix: napi_
- neondatabase/website @ main: content/changelog/2025-01-31.mdprovider-documentation · last read 2026-09-24 · latest outcome read · supports prefix: napi_
- neon.com/docs/changelog/2025-01-31provider-documentation · last read 2026-09-25 · latest outcome read · supports prefix: napi_
Tool corroborated ·
field-body-length· current · observed 2026-09-24body length: at least 64 characters (Neon says "64-bit token", which fits no string length; not used.)
- betterleaks/betterleaks @ 6cf4f1a29160b68be7c6390599b9b773234e5a43: cmd/generate/config/rules/neon.goscanner-rule-source · last read 2026-09-25 · latest outcome read · supports exactly 64
- koki-develop/mask-go @ 3ff232051d4d224314b400d9e973c5a8c7d405d5: builtin_neon_api_key.goscanner-rule-source · last read 2026-09-25 · latest outcome read · supports 64 as a floor
Tool corroborated ·
field-body-alphabet· current · observed 2026-09-24body alphabet: [A-Za-z0-9]
- betterleaks/betterleaks @ 6cf4f1a29160b68be7c6390599b9b773234e5a43: cmd/generate/config/rules/neon.goscanner-rule-source · last read 2026-09-25 · latest outcome read · supports body alphabet: [A-Za-z0-9]
- koki-develop/mask-go @ 3ff232051d4d224314b400d9e973c5a8c7d405d5: builtin_neon_api_key.goscanner-rule-source · last read 2026-09-25 · latest outcome read · supports body alphabet: [A-Za-z0-9]
Unresolved ·
field-legacy-keys· current · observed 2026-09-24legacy keys: keys issued before the prefix stay valid and carry no marker (Not claimed; never a control.)
- neon.com/docs/changelog/2025-01-31provider-documentation · last read 2026-09-25 · latest outcome read · supports legacy keys: keys issued before the prefix stay valid and carry no marker
Unresolved ·
listed-references· current · observed 2026-09-24The legacy contract lists 3 references without stating which property each supports.
- docs.github.com/en/code-security/secret-scanning/introduction/supported-secret-scanning-patternsprovider-documentation · last read 2026-10-05 · latest outcome read · supports Listed as a reference by the legacy contract
- neondatabase/website @ main: content/changelog/2025-01-31.mdprovider-documentation · last read 2026-09-24 · latest outcome read · supports Listed as a reference by the legacy contract
- neon.com/docs/manage/api-keysprovider-documentation · last read 2026-09-24 · latest outcome read · supports Listed as a reference by the legacy contract
Tool corroborated ·
dossier-research· current · observed 2026-09-25Legacy dossier research (verdict ready, tier T2) cited 4 sources; the dossier does not attribute sources to individual properties.
- betterleaks/betterleaks @ 6cf4f1a29160b68be7c6390599b9b773234e5a43: cmd/generate/config/rules/neon.goscanner-rule-source · last read 2026-09-25 · latest outcome read · supports Cited by the legacy dossier research for this family
- koki-develop/mask-go @ 3ff232051d4d224314b400d9e973c5a8c7d405d5: builtin_neon_api_key.goscanner-rule-source · last read 2026-09-25 · latest outcome read · supports Cited by the legacy dossier research for this family
- redact-secret/redact-secret @ 8b6a5fde52ecb4dfce13f09c7a947062d21483c7: docs/audits/evidence/524/README.mdproject-research-note · last read 2026-09-25 · latest outcome read · supports Final research evidence recorded by the legacy dossier
- neon.com/docs/changelog/2025-01-31provider-documentation · last read 2026-09-25 · latest outcome read · supports Cited by the legacy dossier research for this family
Unresolved ·
taxonomy-sources· current · observed 2026-09-25The legacy taxonomy lists 1 source for this family. The taxonomy records no date; the dossier researchedAt is used as the observed-at date.
- neon.com/docs/changelog/2025-01-31provider-documentation · last read 2026-09-25 · latest outcome read · supports Listed as a source for this family in the legacy taxonomy
Open questions
No open question is recorded for this revision.
Benchmark dossier notes
- Shape
napi_followed by at least 64 alphanumeric characters ([A-Za-z0-9]), read to the end of the run. Neon's API-keys page calls a key "a randomly-generated 64-bit token", which fits no string length, and its only written example is not a shape.- Basis
- the family tier is T2, following the assessment contract (#259: a T1 prefix with a tool-corroborated body stays at the weakest frozen field). T1 for the prefix (Neon changelog, quoted in the #524 record). The body floor is T2: betterleaks
neon-api-key(napi_+ exactly 64) and the mask-go library (64 as a floor). The pinned gitleaks 8.30.1 and trufflehog 3.97.4 have no Neon rule. GitHub secret scanning listsneon_api_key(expression unpublished), which corroborates the prefix only. - Issuance
- Neon Console or API. Not attempted.
- Contract in core
- detector-families.md (
neon_api_key, always redacted); frozen in the #524 evidence.
In this benchmark
- Fixtures
- 42
- Left readable
- 0
- Redacted too much
- 0
- False alarms
- 0
42 fixtures: 18 expect a redaction, 24 must stay quiet. See every row
| Evidence level | Fixtures | Left readable | Too much | False alarms |
|---|---|---|---|---|
| T2Tool-corroborated | 34 | 0 | 0 | 0 |
| T3Project policy | 8 | 0 | 0 | 0 |
Every scanner on the same fixtures
In run order. Counts are what each scanner recorded on this family's fixtures, whichever rules it has; a scanner with no rule for the family has nothing to report on it.
| Scanner | Fixtures | Left readable | Too much | False alarms |
|---|---|---|---|---|
| flare-redactRuntime library · 1.6.1 · Published npm package · secrets-only (pii, generic_assignment disabled) · JavaScript engineNo rule maps to it | 42 | 16 | 2 | 0 |
| gitleaksRepository scanner · 8.30.1 · Directory scan · default rulesNo rule maps to it | 42 | 8 | 0 | 0 |
| redact-secretProduct measured here · 0.1.0-beta.14 · Published npm package · default detectors1 detector mapped | 42 | 0 | 0 | 0 |
| trufflehogRepository scanner · 3.97.4 · Filesystem scan · verification disabledNo rule maps to it | 42 | 18 | 0 | 0 |
Benchmark dossier questions
- Open caveat
- Prefix is T1; the 64-character body floor is T2 (betterleaks exactly 64, mask-go at least 64) and Neon calls a key a "64-bit token". Legacy unprefixed keys are outside the claim. No issued key observed.
Looks like it, but isn't
- Collisions
- project, branch and endpoint ids, pooled hostnames with a database name, and placeholders are the benign controls in the #524 record. A Neon connection URI password is a different credential (
connection-string) and never carries thenapi_key.
Scanner rules for this family
No peer rule maps to this family
None of the reviewed peer scanners has a rule that can match a credential of this family.
None mapped
Fixtures in this family
| Fixture | Kind and evidence | redact-secret |
|---|---|---|
neon-api-key-api-key-createneon · documented-format-literal | Must redactT2 · Tool-corroborated | Redacted |
neon-api-key-bearer-curlneon · documented-format-literal | Must redactT2 · Tool-corroborated | Redacted |
neon-api-key-compose-envneon · documented-format-literal | Must redactT2 · Tool-corroborated | Redacted |
neon-api-key-create-branch-actionneon · documented-format-literal | Must redactT2 · Tool-corroborated | Redacted |
neon-api-key-dotenvneon · documented-format-literal | Must redactT2 · Tool-corroborated | Redacted |
neon-api-key-exportneon · documented-format-literal | Must redactT2 · Tool-corroborated | Redacted |
neon-api-key-incident-noteneon · documented-format-literal | Must redactT2 · Tool-corroborated | Redacted |
neon-api-key-key-shape-bareneon · documented-format-literal | Must redactT2 · Tool-corroborated | Redacted |
neon-api-key-key-shape-quotedneon · documented-format-literal | Must redactT2 · Tool-corroborated | Redacted |
neon-api-key-key-shape-unicode-crlfneon · documented-format-literal | Must redactT2 · Tool-corroborated | Redacted |
neon-api-key-mcp-configneon · documented-format-literal | Must redactT2 · Tool-corroborated | Redacted |
neon-api-key-neonctl-flagneon · documented-format-literal | Must redactT2 · Tool-corroborated | Redacted |
neon-api-key-secret-printneon · documented-format-literal | Must redactT2 · Tool-corroborated | Redacted |
neon-api-key-terraform-varsneon · documented-format-literal | Must redactT2 · Tool-corroborated | Redacted |
neon-api-key-ts-api-clientneon · documented-format-literal | Must redactT2 · Tool-corroborated | Redacted |
neon-api-key-twin-base-dotenvneon · documented-format-literal | Must redactT2 · Tool-corroborated | Redacted |
neon-api-key-twin-base-headerneon · documented-format-literal | Must redactT2 · Tool-corroborated | Redacted |
neon-api-key-twin-base-tsneon · documented-format-literal | Must redactT2 · Tool-corroborated | Redacted |
neon-api-key-actions-secret-referenceneon · templated-reference | Must not flagT3 · Project policy | Quiet |
neon-api-key-api-key-list-public-idneon · public-identifier | Must not flagT2 · Tool-corroborated | Quiet |
neon-api-key-dash-in-body-twinneon · wrong-alphabet | Must not flagT2 · Tool-corroborated · twin | Quiet |
neon-api-key-docs-placeholder-placeholderneon · documentation-placeholder | Must not flagT3 · Project policy | Quiet |
neon-api-key-env-reference-referenceneon · templated-reference | Must not flagT3 · Project policy | Quiet |
neon-api-key-hyphen-delimiter-twinneon · boundary-violation | Must not flagT2 · Tool-corroborated · twin | Quiet |
neon-api-key-inner-dash-twinneon · wrong-alphabet | Must not flagT2 · Tool-corroborated · twin | Quiet |
neon-api-key-key-guidance-proseneon · prose-mention | Must not flagT3 · Project policy | Quiet |
neon-api-key-label-proseneon · benign-lookalike | Must not flagT3 · Project policy | Quiet |
neon-api-key-maskneon · benign-lookalike | Must not flagT3 · Project policy | Quiet |
neon-api-key-masked-display-placeholderneon · documentation-placeholder | Must not flagT3 · Project policy | Quiet |
neon-api-key-node-api-call-near-missneon · format-near-miss | Must not flagT2 · Tool-corroborated | Quiet |
neon-api-key-pooled-host-public-idneon · public-identifier | Must not flagT2 · Tool-corroborated | Quiet |
neon-api-key-prefix-letter-twinneon · prefix-near-miss | Must not flagT2 · Tool-corroborated · twin | Quiet |
neon-api-key-prefix-letter-twin-prefix-near-missneon · prefix-near-miss | Must not flagT2 · Tool-corroborated · twin | Quiet |
neon-api-key-prefix-onlyneon · benign-lookalike | Must not flagT2 · Tool-corroborated | Quiet |
neon-api-key-prefix-only-near-missneon · format-near-miss | Must not flagT2 · Tool-corroborated | Quiet |
neon-api-key-project-and-branch-public-idneon · public-identifier | Must not flagT2 · Tool-corroborated | Quiet |
neon-api-key-project-digest-encoded-valueneon · benign-encoded-value | Must not flagT2 · Tool-corroborated | Quiet |
neon-api-key-referenceneon · benign-lookalike | Must not flagT3 · Project policy | Quiet |
neon-api-key-short-bodyneon · benign-lookalike | Must not flagT2 · Tool-corroborated | Quiet |
neon-api-key-short-body-twinneon · wrong-length | Must not flagT2 · Tool-corroborated · twin | Quiet |
neon-api-key-short-body-twin-wrong-lengthneon · wrong-length | Must not flagT2 · Tool-corroborated · twin | Quiet |
neon-api-key-uppercase-prefix-twinneon · prefix-near-miss | Must not flagT2 · Tool-corroborated · twin | Quiet |
Sources
Documentation and code
- neon.com/docs/changelog/2025-01-31
- github.com/betterleaks/betterleaks/blob/6cf4f1a29160b68be7c6390599b9b773234e5a43/cmd/generate/config/rules/neon.go
- github.com/koki-develop/mask-go/blob/3ff232051d4d224314b400d9e973c5a8c7d405d5/builtin_neon_api_key.go
Research log
- redact-secret/redact-secret#524Research issue
- redact-secret/redact-secret-benchmarks#259Research issue
- Final evidence, pinned to a commit/redact-secret/redact-secret/blob/8b6a5fde52ecb4dfce13f09c7a947062d21483c7/docs/audits/evidence/524/README.md