redact-secret · Report
License key
40-character hexadecimal license key.
Research record
2 events in the review history: 1 observed, 1 reviewed. Latest: observed on 2026-09-24 by automation, project maintainer. Project-maintained review is not independent validation. The family record at this release.
Format
What it looks like
- Descriptive pattern
^([0-9a-f]{32}|eu01xx[0-9a-f]{26})FFFFNRAL$
Parts are shown as recorded. Evidence classes belong to the facts below; no class is assigned to a part.
Format facts
Provider documented ·
provider-source· current · observed 2026-09-23ingest license key length and NRAL suffix: New Relic's own documentation (docs.newrelic.com, IBM MQ host-integration page) states the ingest license key as 40 characters with the literal suffix NRAL, establishing the suffix and total length; its eBPF install pages show elided examples ending FFFFNRAL. The body alphabet, the FFFF segment and the EU eu01xx prefix are not provider-stated: they rest on New Relic-authored code (newrelic-cli IsValidLicenseKeyFormat, docs-website check-for-keys.sh) and trufflehog 3.97.4
- docs.newrelic.com/docs/opentelemetry/integrations/ibm-mq/host/provider-documentation · last read 2026-09-24 · latest outcome read · supports New Relic's own documentation (docs.newrelic.com, IBM MQ host-integration page) states the ingest license key as 40 characters with the literal suffix NRAL, establishing the suffix and total length; its eBPF install pages show elided examples ending FFFFNRAL. The body alphabet, the FFFF segment and the EU eu01xx prefix are not provider-stated: they rest on New Relic-authored code (newrelic-cli IsValidLicenseKeyFormat, docs-website check-for-keys.sh) and trufflehog 3.97.4
Unresolved ·
tool-corroboration· current · observed 2026-09-23Pinned scanner rules are consistent with the contract grammar (1 artifact: trufflehog 3.97.4).
- trufflesecurity/trufflehog @ v3.97.4: pkg/detectors/newreliclicensekey/newreliclicensekey.goscanner-rule-source · last read 2026-09-23 · latest outcome read · supports trufflehog 3.97.4: newreliclicensekey/newreliclicensekey
Unresolved ·
listed-references· current · observed 2026-09-23The legacy contract lists 3 references without stating which property each supports.
- docs.newrelic.com/docs/apis/intro-apis/new-relic-api-keys/provider-documentation · last read 2026-09-23 · latest outcome read · supports Listed as a reference by the legacy contract
- docs.newrelic.com/docs/ebpf/k8s-installation/provider-documentation · last read 2026-09-24 · latest outcome read · supports Listed as a reference by the legacy contract
- docs.newrelic.com/docs/ebpf/linux-installation/provider-documentation · last read 2026-09-24 · latest outcome read · supports Listed as a reference by the legacy contract
Provider documented ·
dossier-research· current · observed 2026-09-24Legacy dossier research (verdict ready, tier T1) cited 4 sources; the dossier does not attribute sources to individual properties.
- docs.newrelic.com/docs/ebpf/k8s-installation/provider-documentation · last read 2026-09-24 · latest outcome read · supports Cited by the legacy dossier research for this family
- docs.newrelic.com/docs/opentelemetry/integrations/ibm-mq/host/provider-documentation · last read 2026-09-24 · latest outcome read · supports Cited by the legacy dossier research for this family
- docs.newrelic.com/docs/ebpf/linux-installation/provider-documentation · last read 2026-09-24 · latest outcome read · supports Cited by the legacy dossier research for this family
- redact-secret/redact-secret @ 8b6a5fde52ecb4dfce13f09c7a947062d21483c7: docs/audits/evidence/656/README.mdproject-research-note · last read 2026-09-24 · latest outcome read · supports Final research evidence recorded by the legacy dossier
Open questions
No open question is recorded for this revision.
Benchmark dossier notes
- Shape
- current generation: 32 lowercase hex characters then the literal
FFFFNRAL(40 total), or the EU formeu01xx+ 26 hex +FFFFNRAL. The firstNRALgeneration (36 hex +NRAL, labelled_OLDby New Relic's docs scanner) and other region prefixes are not covered. The legacy all-hex 40-character key has no marker and stays keyword-gated. The taxonomy description ("40-character hexadecimal") matches the older canonical page. - Basis
- T1 for the suffix and length: a docs.newrelic.com comment says "New Relic ingest license key (40 chars, suffix NRAL)"; two eBPF pages show elided examples ending
FFFFNRALand the docs style guide uses 32 masked characters thenFFFFNRAL. The canonical API-keys page still says "40-character hexadecimal string", which contradictsNRALunless it describes the legacy key. Body,FFFFandeu01xx: New Relic-authored code (newrelic-cliIsValidLicenseKeyFormat, docs-website key checker) and TruffleHog 3.97.4. - Issuance
- not attempted; an empirical check of one or two fresh
Ingest - Licensekeys is specified in the #656 web-search pass. - Contract in core
- detector-families.md (row
new-relic:license-key); evidence #656 record.
In this benchmark
- Fixtures
- 42
- Left readable
- 0
- Redacted too much
- 0
- False alarms
- 0
42 fixtures: 15 expect a redaction, 24 must stay quiet, 3 record project policy. See every row
| Evidence level | Fixtures | Left readable | Too much | False alarms |
|---|---|---|---|---|
| T1Provider-documented | 15 | 0 | 0 | 0 |
| T2Tool-corroborated | 18 | 0 | 0 | 0 |
| T3Project policy | 9 | 0 | 0 | 0 |
Every scanner on the same fixtures
In run order. Counts are what each scanner recorded on this family's fixtures, whichever rules it has; a scanner with no rule for the family has nothing to report on it.
| Scanner | Fixtures | Left readable | Too much | False alarms |
|---|---|---|---|---|
| flare-redactRuntime library · 1.6.1 · Published npm package · secrets-only (pii, generic_assignment disabled) · JavaScript engineNo rule maps to it | 42 | 18 | 0 | 0 |
| gitleaksRepository scanner · 8.30.1 · Directory scan · default rulesNo rule maps to it | 42 | 6 | 0 | 1 |
| redact-secretProduct measured here · 0.1.0-beta.14 · Published npm package · default detectors1 detector mapped | 42 | 0 | 0 | 0 |
| trufflehogRepository scanner · 3.97.4 · Filesystem scan · verification disabled1 rule targets it | 42 | 3 | 0 | 0 |
Benchmark dossier questions
- Open caveat
- The NRAL suffix and total length 40 are T1; the hex body, the FFFF segment and the eu01xx region prefix are provider-code and tool corroborated, and the canonical API-keys page still says 40-character hexadecimal.
Looks like it, but isn't
- Collisions
- the legacy shape collides with SHA-1 digests and commit ids; suffixed shapes need no same-line keyword after redact-secret#754.
Scanner rules for this family
| Scanner | Rule | What the rule matches |
|---|---|---|
| trufflehog · rules 3.97.4 | newreliclicensekey | 32 hex + FFFFNRAL |
No rule maps to this family in flare-redact, gitleaks, openredaction.
Fixtures in this family
| Fixture | Kind and evidence | redact-secret |
|---|---|---|
new-relic-license-key-actions-step-envnew-relic · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
new-relic-license-key-agent-startup-jsonnew-relic · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
new-relic-license-key-config-checksum-encoded-valuenew-relic · benign-encoded-value | Must not flagT2 · Tool-corroborated | Quiet |
new-relic-license-key-current-format-barenew-relic · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
new-relic-license-key-current-format-quotednew-relic · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
new-relic-license-key-current-format-unicode-crlfnew-relic · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
new-relic-license-key-env-license-keynew-relic · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
new-relic-license-key-helm-bundle-valuesnew-relic · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
new-relic-license-key-k8s-secret-stringdatanew-relic · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
new-relic-license-key-keyword-context-barenew-relic · documented-format-literal | Project policyT3 · Project policy | Redacted |
new-relic-license-key-keyword-context-quotednew-relic · documented-format-literal | Project policyT3 · Project policy | Redacted |
new-relic-license-key-keyword-context-unicode-crlfnew-relic · documented-format-literal | Project policyT3 · Project policy | Redacted |
new-relic-license-key-log-api-license-headernew-relic · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
new-relic-license-key-newrelic-js-confignew-relic · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
new-relic-license-key-newrelic-ymlnew-relic · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
new-relic-license-key-otel-collector-api-keynew-relic · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
new-relic-license-key-python-newrelic-ininew-relic · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
new-relic-license-key-shell-export-licensenew-relic · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
new-relic-license-key-terraform-tfvars-eunew-relic · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
new-relic-license-key-account-and-app-ids-public-idnew-relic · public-identifier | Must not flagT2 · Tool-corroborated | Quiet |
new-relic-license-key-current-format-bare-twinnew-relic · wrong-length | Must not flagT2 · Tool-corroborated · twin | Quiet |
new-relic-license-key-current-format-marker-bare-twinnew-relic · boundary-violation | Must not flagT2 · Tool-corroborated · twin | Quiet |
new-relic-license-key-current-format-marker-quoted-twinnew-relic · boundary-violation | Must not flagT2 · Tool-corroborated · twin | Quiet |
new-relic-license-key-current-format-marker-unicode-crlf-twinnew-relic · boundary-violation | Must not flagT2 · Tool-corroborated · twin | Quiet |
new-relic-license-key-current-format-quoted-twinnew-relic · wrong-length | Must not flagT2 · Tool-corroborated · twin | Quiet |
new-relic-license-key-current-format-unicode-crlf-twinnew-relic · wrong-length | Must not flagT2 · Tool-corroborated · twin | Quiet |
new-relic-license-key-dashboard-permalink-public-idnew-relic · public-identifier | Must not flagT2 · Tool-corroborated | Quiet |
new-relic-license-key-erb-template-placeholdernew-relic · documentation-placeholder | Must not flagT3 · Project policy | Quiet |
new-relic-license-key-helm-values-indirection-referencenew-relic · templated-reference | Must not flagT3 · Project policy | Quiet |
new-relic-license-key-ingest-note-prosenew-relic · prose-mention | Must not flagT3 · Project policy | Quiet |
new-relic-license-key-keyword-context-bare-twinnew-relic · wrong-length | Must not flagT2 · Tool-corroborated · twin | Quiet |
new-relic-license-key-keyword-context-quoted-twinnew-relic · wrong-length | Must not flagT2 · Tool-corroborated · twin | Quiet |
new-relic-license-key-keyword-context-unicode-crlf-twinnew-relic · wrong-length | Must not flagT2 · Tool-corroborated · twin | Quiet |
new-relic-license-key-label-prosenew-relic · benign-lookalike | Must not flagT3 · Project policy | Quiet |
new-relic-license-key-length-39-eu-twinnew-relic · wrong-length | Must not flagT2 · Tool-corroborated · twin | Quiet |
new-relic-license-key-length-41-twinnew-relic · wrong-length | Must not flagT2 · Tool-corroborated · twin | Quiet |
new-relic-license-key-masknew-relic · benign-lookalike | Must not flagT3 · Project policy | Quiet |
new-relic-license-key-missing-keywordnew-relic · benign-lookalike | Must not flagT2 · Tool-corroborated | Quiet |
new-relic-license-key-referencenew-relic · benign-lookalike | Must not flagT3 · Project policy | Quiet |
new-relic-license-key-short-keynew-relic · benign-lookalike | Must not flagT2 · Tool-corroborated | Quiet |
new-relic-license-key-suffix-nrai-twinnew-relic · prefix-near-miss | Must not flagT2 · Tool-corroborated · twin | Quiet |
new-relic-license-key-trailing-identifier-twinnew-relic · boundary-violation | Must not flagT2 · Tool-corroborated · twin | Quiet |
Sources
Documentation and code
- docs.newrelic.com/docs/opentelemetry/integrations/ibm-mq/host/
- docs.newrelic.com/docs/ebpf/k8s-installation/
- docs.newrelic.com/docs/ebpf/linux-installation/
Research log
- redact-secret/redact-secret#656Research issue
- redact-secret/redact-secret#672Research issue
- redact-secret/redact-secret#754Research issue
- redact-secret/redact-secret-benchmarks#160Research issue
- Final evidence, pinned to a commit/redact-secret/redact-secret/blob/8b6a5fde52ecb4dfce13f09c7a947062d21483c7/docs/audits/evidence/656/README.md