redact-secret · Report
Personal access token
nfp_-prefixed personal access token: 36 bytes of [A-Za-z0-9_], 40 characters total.
Research record
3 events in the review history: 2 observed, 1 reviewed. Latest: observed on 2026-09-23 by automation, project maintainer. Project-maintained review is not independent validation. The family record at this release.
Format
What it looks like
- Descriptive pattern
^nfp_[A-Za-z0-9_]{36}$
Parts are shown as recorded. Evidence classes belong to the facts below; no class is assigned to a part.
Format facts
Provider documented ·
provider-source· current · observed 2026-09-232023-11-07 nf-prefixed token format: Netlify's staff-authored announcement states "All Netlify authentication tokens will start with a nf prefix followed by a single identifying character" — nfp for personal access tokens (nfc/nfo/nfu/nfb for CLI, OAuth, app and build tokens) — and that token storage capacity must grow "to 40 characters"; the "_" delimiter and the [A-Za-z0-9_] body alphabet are tool-corroborated, not stated on the page
- answers.netlify.com/t/change-to-the-netlify-authentication-token-format/106146provider-documentation · last read 2026-09-29 · latest outcome read · supports Netlify's staff-authored announcement states "All Netlify authentication tokens will start with a nf prefix followed by a single identifying character" — nfp for personal access tokens (nfc/nfo/nfu/nfb for CLI, OAuth, app and build tokens) — and that token storage capacity must grow "to 40 characters"; the "_" delimiter and the [A-Za-z0-9_] body alphabet are tool-corroborated, not stated on the page
Tool corroborated ·
tool-corroboration· current · observed 2026-09-23Pinned scanner rules are consistent with the contract grammar (2 artifacts: gitleaks 8.30.1; trufflehog 3.97.4).
- gitleaks/gitleaks @ v8.30.1: config/gitleaks.tomlscanner-rule-source · last read 2026-10-04 · latest outcome read · supports gitleaks 8.30.1: gitleaks.toml
- trufflesecurity/trufflehog @ v3.97.4: pkg/detectors/netlify/v2/netlify_v2.goscanner-rule-source · last read 2026-09-23 · latest outcome read · supports trufflehog 3.97.4: netlify/v2
Provider documented ·
dossier-research· current · observed 2026-09-23Legacy dossier research (verdict ready, tier T1) cited 2 sources; the dossier does not attribute sources to individual properties.
- answers.netlify.com/t/change-to-the-netlify-authentication-token-format/106146provider-documentation · last read 2026-09-29 · latest outcome read · supports Cited by the legacy dossier research for this family
- redact-secret/redact-secret @ 8b6a5fde52ecb4dfce13f09c7a947062d21483c7: docs/audits/evidence/582/README.mdproject-research-note · last read 2026-09-25 · latest outcome read · supports Final research evidence recorded by the legacy dossier
Provider documented ·
taxonomy-sources· current · observed 2026-09-23The legacy taxonomy lists 1 source for this family. The taxonomy records no date; the dossier researchedAt is used as the observed-at date.
- answers.netlify.com/t/change-to-the-netlify-authentication-token-format/106146provider-documentation · last read 2026-09-29 · latest outcome read · supports Listed as a source for this family in the legacy taxonomy
Open questions
No open question is recorded for this revision.
Benchmark dossier notes
- Shape
- prefix
nfp_followed by 36 characters from letters, digits and underscore, 40 characters in all. - Basis
- T1 for the prefix and the 40-character size: a Netlify-staff announcement on answers.netlify.com states the
nfscheme,nfpfor personal access tokens, and storage capacity increased "to 40 characters". The delimiter and body alphabet come from gitleaks 8.30.1 and trufflehog 3.97.4 (netlify/v2), which agree onnfp_plus 36 characters of[A-Za-z0-9_]. Netlify's API guide only documents creating a token and sending it as a Bearer header. #582 confirmed Netlify was the only one of the four committed Beta.7 candidates with a T1 provider source. - Issuance
- not attempted.
- Contract in core
- detector-families.md.
In this benchmark
- Fixtures
- 24
- Left readable
- 0
- Redacted too much
- 0
- False alarms
- 0
24 fixtures: 10 expect a redaction, 14 must stay quiet. See every row
| Evidence level | Fixtures | Left readable | Too much | False alarms |
|---|---|---|---|---|
| T1Provider-documented | 10 | 0 | 0 | 0 |
| T2Tool-corroborated | 10 | 0 | 0 | 0 |
| T3Project policy | 4 | 0 | 0 | 0 |
Every scanner on the same fixtures
In run order. Counts are what each scanner recorded on this family's fixtures, whichever rules it has; a scanner with no rule for the family has nothing to report on it.
| Scanner | Fixtures | Left readable | Too much | False alarms |
|---|---|---|---|---|
| flare-redactRuntime library · 1.6.1 · Published npm package · secrets-only (pii, generic_assignment disabled) · JavaScript engine1 rule targets it | 24 | 6 | 0 | 0 |
| gitleaksRepository scanner · 8.30.1 · Directory scan · default rules1 rule targets it | 24 | 6 | 0 | 0 |
| redact-secretProduct measured here · 0.1.0-beta.14 · Published npm package · default detectors1 detector mapped | 24 | 0 | 0 | 0 |
| trufflehogRepository scanner · 3.97.4 · Filesystem scan · verification disabled1 rule targets it | 24 | 4 | 0 | 0 |
Benchmark dossier questions
- Open caveat
- The underscore delimiter and the [A-Za-z0-9_] body alphabet are stated by scanner rules only; the announcement gives the nfp prefix and a 40-character capacity.
Looks like it, but isn't
- Collisions
- the other four
nf*classes share the scheme and length but are different credentials. Pre-2023 tokens share one unprefixed shape across all five classes, so that legacy form cannot be labelled as a personal token. Site, account and deploy IDs and preview URLs are not credentials.
Scanner rules for this family
| Scanner | Rule | What the rule matches |
|---|---|---|
| flare-redact · rules 1.6.1 | netlify_token | nfp_ + 36-60 characters |
| gitleaks · rules 8.30.1 | netlify-access-token | netlify keyword + a 40-46 character body |
| trufflehog · rules 3.97.4 | netlify/v2 | netlify keyword + nfp_ + 36 characters |
No rule maps to this family in openredaction.
Fixtures in this family
| Fixture | Kind and evidence | redact-secret |
|---|---|---|
netlify-token-api-bearer-headernetlify · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
netlify-token-js-api-clientnetlify · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
netlify-token-keyword-context-barenetlify · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
netlify-token-keyword-context-quotednetlify · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
netlify-token-keyword-context-unicode-crlfnetlify · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
netlify-token-netlify-deploy-auth-flagnetlify · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
netlify-token-pat-shape-barenetlify · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
netlify-token-pat-shape-quotednetlify · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
netlify-token-pat-shape-unicode-crlfnetlify · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
netlify-token-deploy-digest-encoded-valuenetlify · benign-encoded-value | Must not flagT2 · Tool-corroborated | Quiet |
netlify-token-github-actions-deploynetlify · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
netlify-token-label-prosenetlify · benign-lookalike | Must not flagT3 · Project policy | Quiet |
netlify-token-masknetlify · benign-lookalike | Must not flagT3 · Project policy | Quiet |
netlify-token-pat-shape-bare-twinnetlify · wrong-length | Must not flagT2 · Tool-corroborated · twin | Quiet |
netlify-token-pat-shape-prefix-bare-twinnetlify · prefix-near-miss | Must not flagT2 · Tool-corroborated · twin | Quiet |
netlify-token-pat-shape-prefix-quoted-twinnetlify · prefix-near-miss | Must not flagT2 · Tool-corroborated · twin | Quiet |
netlify-token-pat-shape-prefix-unicode-crlf-twinnetlify · prefix-near-miss | Must not flagT2 · Tool-corroborated · twin | Quiet |
netlify-token-pat-shape-quoted-twinnetlify · wrong-length | Must not flagT2 · Tool-corroborated · twin | Quiet |
netlify-token-pat-shape-unicode-crlf-twinnetlify · wrong-length | Must not flagT2 · Tool-corroborated · twin | Quiet |
netlify-token-prefix-onlynetlify · benign-lookalike | Must not flagT2 · Tool-corroborated | Quiet |
netlify-token-public-idnetlify · benign-lookalike | Must not flagT2 · Tool-corroborated | Quiet |
netlify-token-referencenetlify · benign-lookalike | Must not flagT3 · Project policy | Quiet |
netlify-token-short-bodynetlify · benign-lookalike | Must not flagT2 · Tool-corroborated | Quiet |
netlify-token-token-format-note-prosenetlify · prose-mention | Must not flagT3 · Project policy | Quiet |
Sources
Documentation and code
- answers.netlify.com/t/change-to-the-netlify-authentication-token-format/106146
Research log
- redact-secret/redact-secret#311Research issue
- redact-secret/redact-secret#582Research issue
- Final evidence, pinned to a commit/redact-secret/redact-secret/blob/8b6a5fde52ecb4dfce13f09c7a947062d21483c7/docs/audits/evidence/582/README.md