redact-secret · Report
CLI, OAuth, app and build tokens (nfc_/nfo_/nfu_/nfb_)
The announcement's four other nf-prefixed token classes, sharing the personal access token's scheme but issued for the CLI, OAuth flows, app.netlify.com and builds.
Research record
What blocks the research
- Issuance-gatedSeparator, body width and alphabet per prefix are not provider-stated and peer rules disagree; nfc_ needs one netlify login measured, nfo_, nfu_ and nfb_ need an OAuth app, browser storage and a build step.
2 events in the review history: 1 observed, 1 reviewed. Latest: observed on 2026-09-29 by automation, project maintainer. Project-maintained review is not independent validation. The family record at this release.
Format
What it looks like
Shape not recorded.
Format facts
Provider documented ·
dossier-research· current · observed 2026-09-29Legacy dossier research (verdict issuance-gated, tier T1) cited 10 sources; the dossier does not attribute sources to individual properties.
- answers.netlify.com/t/change-to-the-netlify-authentication-token-format/106146provider-documentation · last read 2026-09-29 · latest outcome read · supports Cited by the legacy dossier research for this family
- bzzimmy/kestrel @ 6d5ff28089d0b775e2a2c3f63366907d45ddb6fd: src/rules/cloud.rsother · last read 2026-09-29 · latest outcome read · supports Cited by the legacy dossier research for this family
- gitleaks/gitleaks @ b58d3f102cf3a2c84cb7f923d05c25c9b1aed84b: cmd/generate/config/rules/netlify.goother · last read 2026-09-29 · latest outcome read · supports Cited by the legacy dossier research for this family · #L9-L25
- koki-develop/mask-go @ 1b861d7ac421b392a5bb962207fd1886b28e013e: builtin_netlify_auth_token.goother · last read 2026-09-29 · latest outcome read · supports Cited by the legacy dossier research for this family
- netlify/netlify-mcp @ 57e547a1b23ace88227b6fc0ce014ec390e4c4f7: src/tools/deploy-tools/deploy-site.test.tsprovider-sdk-source · last read 2026-09-29 · latest outcome read · supports Cited by the legacy dossier research for this family
- puck-security/geiger @ be0bc39ca4862f8d6552b6be90538095ee2a794b: internal/modules/netlify.goother · last read 2026-09-29 · latest outcome read · supports Cited by the legacy dossier research for this family
- redact-secret/redact-secret @ 378581770a87751d72e27529796c4f790649fd00: docs/audits/evidence/1012/netlify-other-prefixed-tokens.mdproject-research-note · last read 2026-09-29 · latest outcome read · supports Final research evidence recorded by the legacy dossier
- testpatterndev/patterns @ 64580c807ea3a3c2896ca4e0f7044da56333fff6: data/patterns/global-netlify-token.yamlother · last read 2026-09-29 · latest outcome read · supports Cited by the legacy dossier research for this family
- trufflesecurity/trufflehog @ 48b58d3bf3f02ba17bf23b87f095499bc80c6fd7: pkg/detectors/netlify/v2/netlify_v2.goother · last read 2026-09-29 · latest outcome read · supports Cited by the legacy dossier research for this family
- Vulnetix/cli @ c6e24fc9b0148dc0a227da70774300fba7f339ee: internal/sast/rules/vnx-sec-092.regoother · last read 2026-09-29 · latest outcome read · supports Cited by the legacy dossier research for this family · #L25-L26
Provider documented ·
taxonomy-sources· current · observed 2026-09-29The legacy taxonomy lists 1 source for this family. The taxonomy records no date; the dossier researchedAt is used as the observed-at date.
- answers.netlify.com/t/change-to-the-netlify-authentication-token-format/106146provider-documentation · last read 2026-09-29 · latest outcome read · supports Listed as a source for this family in the legacy taxonomy
Open questions
No open question is recorded for this revision.
Benchmark dossier notes
- Shape
- prefix
nf+ one class letter +_:nfc_(Netlify CLI),nfo_(OAuth access token),nfu_(app.netlify.com),nfb_(build), then 36 characters, 40 in all. The observed body alphabet is[A-Za-z0-9]; the personal-token rules allow_too. - Issuance
- not attempted. A CLI login token (
nfc_) and an OAuth token (nfo_) are cheap to mint and revoke;nfu_andnfb_are minted by the platform (session and build) and are not. The #1012 checks:nfc_runnetlify loginonce and record total length (40?), whether byte 4 is_and the body classes;nfo_authorize a test OAuth app once, same record;nfu_read only the shape (length,_position, classes) of the app session token in browser storage without copying it;nfb_a build step that prints only the length and classes of the build token variable. Revoke afterwards. - Contract in core
- none for these four classes; #311 listed them as unsupported variants. The shipped
netlify-tokenclaimsnfp_+ exactly 36[A-Za-z0-9_]and tests the four other prefixes as non-matches; its module doc says gitleaks converges onnfp_+ 36, but at gitleaks HEAD the rule has no prefix (a keyword-gated run of 40 to 46), so that sentence overstates it. A bounded interim contract (nf[coub]_+[A-Za-z0-9], total at most 40) is defensible but its floor would be policy. Named contexts (NETLIFY_AUTH_TOKEN=) are already redacted.
In this benchmark
No fixtures in this family yet
Nothing in the corpus targets it, so nothing is measured and no coverage is claimed.
Not measured
Benchmark dossier questions
- Blocked by
- Separator, body width and alphabet per prefix are not provider-stated and peer rules disagree; nfc_ needs one netlify login measured, nfo_, nfu_ and nfb_ need an OAuth app, browser storage and a build step.
- Open caveat
- for
nfo_,nfu_andnfb_the underscore and 36-character alphanumeric body rest on analogy withnfp_andnfc_plus the announcement's 40-character size; no real value of those three was observed. One issued token each would settle it. Whether a former-staff forum announcement counts as provider documentation is the same ruling as fornfp_.
Looks like it, but isn't
- Collisions
- each is a distinct credential, so none is a control or positive for the personal access token family.
nfc_also opens ordinary snake_case names (Unicode normalization code), which the 36-character body, not the prefix, separates. Pre-2023 unprefixed tokens are a separate variant. Site, account and deploy IDs are not credentials.
Scanner rules for this family
| Scanner | Rule | What the rule matches |
|---|---|---|
| gitleaks · rules 8.30.1 | netlify-access-token | netlify keyword + a 40-46 character body |
No rule maps to this family in flare-redact, openredaction, trufflehog.
No fixtures in this family yet
Nothing in the corpus targets it, so nothing is measured and no coverage is claimed.
Not measured
Sources
Documentation and code
- answers.netlify.com/t/change-to-the-netlify-authentication-token-format/106146
- github.com/trufflesecurity/trufflehog/blob/48b58d3bf3f02ba17bf23b87f095499bc80c6fd7/pkg/detectors/netlify/v2/netlify_v2.go
- github.com/netlify/netlify-mcp/blob/57e547a1b23ace88227b6fc0ce014ec390e4c4f7/src/tools/deploy-tools/deploy-site.test.ts
- github.com/puck-security/geiger/blob/be0bc39ca4862f8d6552b6be90538095ee2a794b/internal/modules/netlify.go
- github.com/koki-develop/mask-go/blob/1b861d7ac421b392a5bb962207fd1886b28e013e/builtin_netlify_auth_token.go
- github.com/bzzimmy/kestrel/blob/6d5ff28089d0b775e2a2c3f63366907d45ddb6fd/src/rules/cloud.rs
- github.com/testpatterndev/patterns/blob/64580c807ea3a3c2896ca4e0f7044da56333fff6/data/patterns/global-netlify-token.yaml
- github.com/Vulnetix/cli/blob/c6e24fc9b0148dc0a227da70774300fba7f339ee/internal/sast/rules/vnx-sec-092.rego#L25-L26
- github.com/gitleaks/gitleaks/blob/b58d3f102cf3a2c84cb7f923d05c25c9b1aed84b/cmd/generate/config/rules/netlify.go#L9-L25
Research log
- redact-secret/redact-secret#311Research issue
- redact-secret/redact-secret#582Research issue
- redact-secret/redact-secret-benchmarks#473Research issue
- redact-secret/redact-secret#1012Research issue
- Final evidence, pinned to a commit/redact-secret/redact-secret/blob/378581770a87751d72e27529796c4f790649fd00/docs/audits/evidence/1012/netlify-other-prefixed-tokens.md