Skip to content
Benchmarks

redact-secret · Report

Integration token

ntn_ prefixed integration token from Notion's 2024-09 rollout.

  • Notion
  • Detectors: none mapped
  • Run 2026-10-07
  • Mode published · redact-secret 0.1.0-beta.14
  • Dossier verdictIssuance-gated
  • Dossier evidence levelT1 · Provider-documented
  • Dossier researched2026-09-29
notion-token's contract review states this current ntn_-prefixed format has no contract here; the pinned gitleaks rule targets it instead of the legacy secret_ shape. Measured as the Beta.8 arrival family notion-integration-token (#211, research #225), separate from notion:legacy-integration-token: the ntn_ prefix is provider-documented, the 11-digit + 35-character body is tool-only and provisional, and PAT/OAuth/org-bot roles that may share the prefix are not merged into it.

Research record

From credential-evidence snapshot-2026.10.06.4 · records at 77ce761 · schema 1.8.0. It describes the research on the format, not what any scanner or the product does, and not a support status.
  • Review stateDraft, not reviewed
  • Format revision1 · proposed, none current
  • ResearchResearched
  • Researched2026-09-29

What blocks the research

  • Issuance-gatedLeading digit run (11 per gitleaks and secretlint, 9 per CredSweeper) and body alphabet rest on peer rules only (one class); needs one integration token and one PAT measured (structure only).

3 events in the review history: 2 observed, 1 reviewed. Latest: observed on 2026-09-29 by automation, project maintainer. Project-maintained review is not independent validation. The family record at this release.

Format

Provider format research from credential-evidence snapshot-2026.10.06.4 · records at 77ce761 · schema 1.8.0.

What it looks like

Descriptive pattern
^ntn_[0-9]{11}[A-Za-z0-9]{35}$

Parts are shown as recorded. Evidence classes belong to the facts below; no class is assigned to a part.

Format facts

Open questions

No open question is recorded for this revision.

Benchmark dossier notes

From the provider dossier, as written. The evidence level above says how well the format is backed; a fact the dossier does not record is not shown.
Shape
prefix ntn_, 11 digits, then 35 letters and digits (50 in total). The prefix is provider-documented. The body comes from one contributor's samples in gitleaks issue 1890, carried into betterleaks, Kingfisher and TruffleHog; secretlint agrees on lengths; flare-redact disagrees (no digit run). Notion's docs show a placeholder with 33 lowercase letters after ntn_, which does not fit.
Basis
- provider changelog (T1, prefix): 2024-09-11 entry, "newly generated Public API tokens will automatically use the ntn_ prefix", plus the warning against regex validation. - provider statement off the docs domain (R3, prefix): @NotionHQ on X, 2025-04-21, "The ntn_ format is our current standard for integration tokens"; no length or alphabet. - provider code (R6, prefix and role only): notion-mcp-server accepts ntn_ and secret_ with a length of 8 to 300 and says it avoids coupling to an exact server-side length; notion-skills-github-sync also accepts development_ntn_ and redacts at a floor of 20; lore classes ntn_ as production personal access or bot token, development_ntn_ as development and secret_ as integration. - peer scanner rules (T2 input, one lineage): gitleaks ntn_ + 11 digits + 35 alphanumerics (betterleaks and Kingfisher carry the same rule); secretlint agrees. - contradicting peer rule: CredSweeper ntn_ + 9 digits + 36 to 255 of [0-9A-Za-z_-]; its 50-character test samples have a 9-digit lead followed by a letter. - Searched with nothing further: the docs llms-full.txt (placeholders), the Notion SDKs (no validation), trufflehog (secret_ only), noseyparker and osv-scalibr (no Notion rule). GitHub's list names the type without a regex.
Issuance
not attempted. Internal connection tokens come from the developer portal Configuration tab; PATs from Settings; checklist in benchmarks#225. The #1012 check: issue one internal-integration token and one personal access token, and for each record the total length (50?), the count of leading digits after ntn_ (11 or 9), whether the rest is only [A-Za-z0-9], and whether the two tokens share the digit run (is it an ID?). Then revoke.
Contract in core
detector-families.md (frozen in the #726 record; already implemented before #729, which left it unchanged): ntn_ + exactly 11 digits + exactly 35 [A-Za-z0-9]. A token with a 9-digit lead, if CredSweeper's samples reflect real issuance, is a false negative; development_ntn_ stays out through the leading boundary.

In this benchmark

Fixture rows on the current run. Counts are for redact-secret in published · redact-secret 0.1.0-beta.14 mode.
Fixtures
24
Left readable
0
Redacted too much
0
False alarms
0

24 fixtures: 10 expect a redaction, 14 must stay quiet. See every row

redact-secret fixture counts by evidence level
Evidence levelFixturesLeft readableToo muchFalse alarms
T2Tool-corroborated19000
T3Project policy5000

Every scanner on the same fixtures

In run order. Counts are what each scanner recorded on this family's fixtures, whichever rules it has; a scanner with no rule for the family has nothing to report on it.

Counts per scanner on this family's fixtures
ScannerFixturesLeft readableToo muchFalse alarms
flare-redactRuntime library · 1.6.1 · Published npm package · secrets-only (pii, generic_assignment disabled) · JavaScript engine1 rule targets it24020
gitleaksRepository scanner · 8.30.1 · Directory scan · default rules1 rule targets it24100
redact-secretProduct measured here · 0.1.0-beta.14 · Published npm package · default detectorsNo detector mapped24000
trufflehogRepository scanner · 3.97.4 · Filesystem scan · verification disabledNo rule maps to it241000

Benchmark dossier questions

Things the sources do not settle. They are listed so nobody reads them as settled.
Blocked by
Leading digit run (11 per gitleaks and secretlint, 9 per CredSweeper) and body alphabet rest on peer rules only (one class); needs one integration token and one PAT measured (structure only).
Open caveat
The prefix is provider-documented but the 11 digit plus 35 alphanumeric body is tool-only, one class, and contradicted by a new peer rule (9 digits); Notion advises against regexes for its tokens (checklist in benchmarks#225).

Looks like it, but isn't

Values the dossier records as resembling this credential without being one.
Collisions
the same ntn_ prefix is documented for PATs, ntn CLI tokens and connection tokens, and possibly OAuth access tokens (Notion's MCP server comment); a shared body grammar is unknown. nrt_ (OAuth refresh, one docs sample of 13 digits plus 32 alphanumerics) and development_ntn_ are siblings. Ids (bot_id, workspace_id, PAT record id) are UUIDs and public.

Scanner rules for this family

Mapped by hand (reviewed 2026-09-30) from each scanner's pinned rule file, never from what a scanner found on the fixtures.
Peer scanner rules that target this family
ScannerRuleWhat the rule matches
flare-redact · rules 1.6.1notion_tokenntn_ + 40-50 or secret_ + 43 characters
gitleaks · rules 8.30.1notion-api-tokenntn_ + 11 digits + 35 characters

No rule maps to this family in openredaction, trufflehog.

24 of 24 rows

Fixtures in this family

24 rows, redact-secret's outcome on each. Rows that need a look come first (0), then the rest in corpus order. Choose "Every scanner" to see each scanner's outcome for the same rows.
Fixtures in Integration token
FixtureKind and evidenceredact-secret
notion-integration-token-actions-envnotion · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
notion-integration-token-agent-session-jsonlnotion · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
notion-integration-token-bearer-headernotion · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
notion-integration-token-compose-mcpnotion · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
notion-integration-token-curl-users-menotion · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
notion-integration-token-dotenv-notion-tokennotion · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
notion-integration-token-escaped-openapi-headersnotion · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
notion-integration-token-export-api-keynotion · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
notion-integration-token-js-clientnotion · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
notion-integration-token-mcp-server-envnotion · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
notion-integration-token-bearer-header-separator-twinnotion · prefix-near-missMust not flagT2 · Tool-corroborated · twinQuiet
notion-integration-token-database-id-public-idnotion · public-identifierMust not flagT2 · Tool-corroboratedQuiet
notion-integration-token-docker-env-passthrough-referencenotion · templated-referenceMust not flagT3 · Project policyQuiet
notion-integration-token-docs-sentence-prosenotion · prose-mentionMust not flagT3 · Project policyQuiet
notion-integration-token-dotenv-notion-token-prefix-twinnotion · prefix-near-missMust not flagT2 · Tool-corroborated · twinQuiet
notion-integration-token-export-api-key-case-twinnotion · prefix-near-missMust not flagT2 · Tool-corroborated · twinQuiet
notion-integration-token-js-client-alphabet-twinnotion · wrong-alphabetMust not flagT2 · Tool-corroborated · twinQuiet
notion-integration-token-masked-env-placeholdernotion · documentation-placeholderMust not flagT3 · Project policyQuiet
notion-integration-token-mcp-server-env-boundary-twinnotion · boundary-violationMust not flagT2 · Tool-corroborated · twinQuiet
notion-integration-token-oauth-ids-public-idnotion · public-identifierMust not flagT2 · Tool-corroboratedQuiet
notion-integration-token-page-url-public-idnotion · public-identifierMust not flagT2 · Tool-corroboratedQuiet
notion-integration-token-prefix-only-near-missnotion · format-near-missMust not flagT2 · Tool-corroboratedQuiet
notion-integration-token-process-env-referencenotion · templated-referenceMust not flagT3 · Project policyQuiet
notion-integration-token-words-placeholder-placeholdernotion · documentation-placeholderMust not flagT3 · Project policyQuiet

Sources

Researched 2026-09-29.

Documentation and code

  • developers.notion.com/page/changelog
  • x.com/NotionHQ/status/1914437336789553311
  • github.com/makenotion/notion-mcp-server/blob/730ae781ba28beeaf0865025a3f2ed4c25ea2387/src/openapi-mcp-server/mcp/token.ts#L21-L32
  • github.com/makenotion/lore/blob/6e741b1bb91a36b47213f4d3af5bbdfaa2f2081d/src/auth/token-prefix.ts#L6-L44
  • github.com/gitleaks/gitleaks/blob/b58d3f102cf3a2c84cb7f923d05c25c9b1aed84b/config/gitleaks.toml#L2652-L2656
  • github.com/secretlint/secretlint/blob/0001184f56165e7db7ab1b3adc1f957911c78f46/packages/%40secretlint/secretlint-rule-notion/src/index.ts#L38-L50
  • github.com/Samsung/CredSweeper/blob/f21ab2f2553eea288a72273b9658cd297ab1d11f/credsweeper/rules/config.yaml#L1630-L1644

Research log

Other Notion families