Skip to content
Benchmarks

redact-secret · Report

CLI, OAuth, app and build tokens (nfc_/nfo_/nfu_/nfb_)

The announcement's four other nf-prefixed token classes, sharing the personal access token's scheme but issued for the CLI, OAuth flows, app.netlify.com and builds.

  • Netlify
  • Detectors: none mapped
  • Run 2026-10-07
  • Mode published · redact-secret 0.1.0-beta.14
  • Dossier verdictIssuance-gated
  • Dossier evidence levelT1 · Provider-documented
  • Dossier researched2026-09-29
Out of redact-secret#311's explicit scope; each is a distinct credential, so none is a control or positive for netlify:personal-access-token.

Research record

From credential-evidence snapshot-2026.10.06.4 · records at 77ce761 · schema 1.8.0. It describes the research on the format, not what any scanner or the product does, and not a support status.
  • Review stateDraft, not reviewed
  • Format revision1 · proposed, none current
  • ResearchResearched
  • Researched2026-09-29

What blocks the research

  • Issuance-gatedSeparator, body width and alphabet per prefix are not provider-stated and peer rules disagree; nfc_ needs one netlify login measured, nfo_, nfu_ and nfb_ need an OAuth app, browser storage and a build step.

2 events in the review history: 1 observed, 1 reviewed. Latest: observed on 2026-09-29 by automation, project maintainer. Project-maintained review is not independent validation. The family record at this release.

Format

Provider format research from credential-evidence snapshot-2026.10.06.4 · records at 77ce761 · schema 1.8.0.

What it looks like

Shape not recorded.

Format facts

Open questions

No open question is recorded for this revision.

Benchmark dossier notes

From the provider dossier, as written. The evidence level above says how well the format is backed; a fact the dossier does not record is not shown.
Shape
prefix nf + one class letter + _: nfc_ (Netlify CLI), nfo_ (OAuth access token), nfu_ (app.netlify.com), nfb_ (build), then 36 characters, 40 in all. The observed body alphabet is [A-Za-z0-9]; the personal-token rules allow _ too.
Issuance
not attempted. A CLI login token (nfc_) and an OAuth token (nfo_) are cheap to mint and revoke; nfu_ and nfb_ are minted by the platform (session and build) and are not. The #1012 checks: nfc_ run netlify login once and record total length (40?), whether byte 4 is _ and the body classes; nfo_ authorize a test OAuth app once, same record; nfu_ read only the shape (length, _ position, classes) of the app session token in browser storage without copying it; nfb_ a build step that prints only the length and classes of the build token variable. Revoke afterwards.
Contract in core
none for these four classes; #311 listed them as unsupported variants. The shipped netlify-token claims nfp_ + exactly 36 [A-Za-z0-9_] and tests the four other prefixes as non-matches; its module doc says gitleaks converges on nfp_ + 36, but at gitleaks HEAD the rule has no prefix (a keyword-gated run of 40 to 46), so that sentence overstates it. A bounded interim contract (nf[coub]_ + [A-Za-z0-9], total at most 40) is defensible but its floor would be policy. Named contexts (NETLIFY_AUTH_TOKEN=) are already redacted.

In this benchmark

Fixture rows on the current run. Counts are for redact-secret in published · redact-secret 0.1.0-beta.14 mode.

No fixtures in this family yet

Nothing in the corpus targets it, so nothing is measured and no coverage is claimed.

Not measured

Benchmark dossier questions

Things the sources do not settle. They are listed so nobody reads them as settled.
Blocked by
Separator, body width and alphabet per prefix are not provider-stated and peer rules disagree; nfc_ needs one netlify login measured, nfo_, nfu_ and nfb_ need an OAuth app, browser storage and a build step.
Open caveat
for nfo_, nfu_ and nfb_ the underscore and 36-character alphanumeric body rest on analogy with nfp_ and nfc_ plus the announcement's 40-character size; no real value of those three was observed. One issued token each would settle it. Whether a former-staff forum announcement counts as provider documentation is the same ruling as for nfp_.

Looks like it, but isn't

Values the dossier records as resembling this credential without being one.
Collisions
each is a distinct credential, so none is a control or positive for the personal access token family. nfc_ also opens ordinary snake_case names (Unicode normalization code), which the 36-character body, not the prefix, separates. Pre-2023 unprefixed tokens are a separate variant. Site, account and deploy IDs are not credentials.

Scanner rules for this family

Mapped by hand (reviewed 2026-09-30) from each scanner's pinned rule file, never from what a scanner found on the fixtures.
Peer scanner rules that target this family
ScannerRuleWhat the rule matches
gitleaks · rules 8.30.1netlify-access-tokennetlify keyword + a 40-46 character body

No rule maps to this family in flare-redact, openredaction, trufflehog.

0 of 0 rows

No fixtures in this family yet

Nothing in the corpus targets it, so nothing is measured and no coverage is claimed.

Not measured

Sources

Researched 2026-09-29.

Documentation and code

  • answers.netlify.com/t/change-to-the-netlify-authentication-token-format/106146
  • github.com/trufflesecurity/trufflehog/blob/48b58d3bf3f02ba17bf23b87f095499bc80c6fd7/pkg/detectors/netlify/v2/netlify_v2.go
  • github.com/netlify/netlify-mcp/blob/57e547a1b23ace88227b6fc0ce014ec390e4c4f7/src/tools/deploy-tools/deploy-site.test.ts
  • github.com/puck-security/geiger/blob/be0bc39ca4862f8d6552b6be90538095ee2a794b/internal/modules/netlify.go
  • github.com/koki-develop/mask-go/blob/1b861d7ac421b392a5bb962207fd1886b28e013e/builtin_netlify_auth_token.go
  • github.com/bzzimmy/kestrel/blob/6d5ff28089d0b775e2a2c3f63366907d45ddb6fd/src/rules/cloud.rs
  • github.com/testpatterndev/patterns/blob/64580c807ea3a3c2896ca4e0f7044da56333fff6/data/patterns/global-netlify-token.yaml
  • github.com/Vulnetix/cli/blob/c6e24fc9b0148dc0a227da70774300fba7f339ee/internal/sast/rules/vnx-sec-092.rego#L25-L26
  • github.com/gitleaks/gitleaks/blob/b58d3f102cf3a2c84cb7f923d05c25c9b1aed84b/cmd/generate/config/rules/netlify.go#L9-L25

Research log

Other Netlify families