Skip to content
Benchmarks

redact-secret · Report

Granular access token

2021-09 format token with a Base62 CRC32 checksum, prefixed npm_.

  • npm
  • Detectors: npm-token
  • Run 2026-10-07
  • Mode published · redact-secret 0.1.0-beta.14
  • Dossier verdictReady
  • Dossier evidence levelT1 · Provider-documented
  • Dossier researched2026-09-20

Research record

From credential-evidence snapshot-2026.10.06.4 · records at 77ce761 · schema 1.8.0. It describes the research on the format, not what any scanner or the product does, and not a support status.
  • Review stateDraft, not reviewed
  • Format revision1 · current
  • ResearchResearched
  • Researched2026-09-20

3 events in the review history: 2 observed, 1 reviewed. Latest: observed on 2026-10-03 by automation, project maintainer. Project-maintained review is not independent validation. The family record at this release.

Format

Provider format research from credential-evidence snapshot-2026.10.06.4 · records at 77ce761 · schema 1.8.0.

What it looks like

Descriptive pattern
^npm_[A-Za-z0-9]{36}$

Parts are shown as recorded. Evidence classes belong to the facts below; no class is assigned to a part.

Format facts

  • Provider documented · provider-source · current · observed 2026-09-17

    2021-09 npm_ prefix scheme: npm_ prefix, underscore delimiter and six-character Base62 CRC32 checksum; 36-character body is tool-corroborated

  • Tool corroborated · tool-corroboration · current · observed 2026-09-17

    Pinned scanner rules are consistent with the contract grammar (2 artifacts: gitleaks 8.30.1; trufflehog 3.97.4).

  • Provider documented · dossier-research · current · observed 2026-09-20

    Legacy dossier research (verdict ready, tier T1) cited 1 source; the dossier does not attribute sources to individual properties.

  • Provider documented · taxonomy-sources · current · observed 2026-09-20

    The legacy taxonomy lists 1 source for this family. The taxonomy records no date; the dossier researchedAt is used as the observed-at date.

Open questions

No open question is recorded for this revision.

Benchmark dossier notes

From the provider dossier, as written. The evidence level above says how well the format is backed; a fact the dossier does not record is not shown.
Shape
2021-09 format token with a Base62 CRC32 checksum, prefixed npm_.
Basis
T1 per the shipped npm-token contract in the benchmarks assessment: the GitHub changelog of 2021-09-23 documents the npm_ prefix, the underscore delimiter and a six-character Base62 CRC32 checksum. The 36-character body is tool-corroborated. The checksum is not part of the lexical pattern. Re-checked 2026-09-20 in benchmarks#46 (PR #55).
Contract in core
detector-families.md.

In this benchmark

Fixture rows on the current run. Counts are for redact-secret in published · redact-secret 0.1.0-beta.14 mode.
Fixtures
54
Left readable
0
Redacted too much
0
False alarms
0

54 fixtures: 10 expect a redaction, 13 must stay quiet, 31 record project policy. See every row

redact-secret fixture counts by evidence level
Evidence levelFixturesLeft readableToo muchFalse alarms
T1Provider-documented10000
T2Tool-corroborated10000
T3Project policy34000

Every scanner on the same fixtures

In run order. Counts are what each scanner recorded on this family's fixtures, whichever rules it has; a scanner with no rule for the family has nothing to report on it.

Counts per scanner on this family's fixtures
ScannerFixturesLeft readableToo muchFalse alarms
flare-redactRuntime library · 1.6.1 · Published npm package · secrets-only (pii, generic_assignment disabled) · JavaScript engine1 rule targets it54010
gitleaksRepository scanner · 8.30.1 · Directory scan · default rules1 rule targets it54100
redact-secretProduct measured here · 0.1.0-beta.14 · Published npm package · default detectors1 detector mapped54000
trufflehogRepository scanner · 3.97.4 · Filesystem scan · verification disabled1 rule targets it543100

Scanner rules for this family

Mapped by hand (reviewed 2026-09-30) from each scanner's pinned rule file, never from what a scanner found on the fixtures.
Peer scanner rules that target this family
ScannerRuleWhat the rule matches
flare-redact · rules 1.6.1npm_tokennpm_ + 36 characters
gitleaks · rules 8.30.1npm-access-tokennpm_ + 36 characters
openredaction · rules 1.1.5NPM_TOKENnpm_ + 36 characters
trufflehog · rules 3.97.4npmtokenv2npm_ + 36 characters
54 of 54 rows

Fixtures in this family

54 rows, redact-secret's outcome on each. Rows that need a look come first (0), then the rest in corpus order. Choose "Every scanner" to see each scanner's outcome for the same rows.
Fixtures in Granular access token
FixtureKind and evidenceredact-secret
npm-granular-token-base-acontext-and-large-input-bases-authored · environment-assignmentProject policyT3 · Project policyRedacted
npm-granular-token-base-bcontext-and-large-input-bases-authored · environment-assignmentProject policyT3 · Project policyRedacted
npm-granular-token-bare-valuecontext-carrier-projections-generated · value-at-input-edgesProject policyT3 · Project policyRedacted
npm-granular-token-bearer-headercontext-carrier-projections-generated · partial-span-leakageProject policyT3 · Project policyRedacted
npm-granular-token-bom-prefixcontext-carrier-projections-generated · multibyte-text-offsetsProject policyT3 · Project policyRedacted
npm-granular-token-crlf-linescontext-carrier-projections-generated · crlf-line-endingsProject policyT3 · Project policyRedacted
npm-granular-token-emoji-prefixcontext-carrier-projections-generated · multibyte-text-offsetsProject policyT3 · Project policyRedacted
npm-granular-token-json-fieldcontext-carrier-projections-generated · structured-text-valueProject policyT3 · Project policyRedacted
npm-granular-token-korean-text-prefixcontext-carrier-projections-generated · multibyte-text-offsetsProject policyT3 · Project policyRedacted
npm-granular-token-log-linecontext-carrier-projections-generated · environment-assignmentProject policyT3 · Project policyRedacted
npm-granular-token-markdown-code-spancontext-carrier-projections-generated · markdown-and-comment-valueProject policyT3 · Project policyRedacted
npm-granular-token-nbsp-before-valuecontext-carrier-projections-generated · multibyte-text-offsetsProject policyT3 · Project policyRedacted
npm-granular-token-shell-export-quotedcontext-carrier-projections-generated · quoted-value-extentProject policyT3 · Project policyRedacted
npm-granular-token-url-querycontext-carrier-projections-generated · partial-span-leakageProject policyT3 · Project policyRedacted
npm-granular-token-xml-elementcontext-carrier-projections-generated · structured-text-valueProject policyT3 · Project policyRedacted
npm-granular-token-yaml-scalarcontext-carrier-projections-generated · structured-text-valueProject policyT3 · Project policyRedacted
npm-granular-token-head-of-1miblarge-and-repeated-input-projections-generated · credential-after-long-inputProject policyT3 · Project policyRedacted
npm-granular-token-head-of-256kiblarge-and-repeated-input-projections-generated · credential-after-long-inputProject policyT3 · Project policyRedacted
npm-granular-token-head-of-64kiblarge-and-repeated-input-projections-generated · credential-after-long-inputProject policyT3 · Project policyRedacted
npm-granular-token-middle-of-1miblarge-and-repeated-input-projections-generated · credential-after-long-inputProject policyT3 · Project policyRedacted
npm-granular-token-middle-of-256kiblarge-and-repeated-input-projections-generated · credential-after-long-inputProject policyT3 · Project policyRedacted
npm-granular-token-middle-of-64kiblarge-and-repeated-input-projections-generated · credential-after-long-inputProject policyT3 · Project policyRedacted
npm-granular-token-tail-of-1miblarge-and-repeated-input-projections-generated · credential-after-long-inputProject policyT3 · Project policyRedacted
npm-granular-token-tail-of-256kiblarge-and-repeated-input-projections-generated · credential-after-long-inputProject policyT3 · Project policyRedacted
npm-granular-token-tail-of-64kiblarge-and-repeated-input-projections-generated · credential-after-long-inputProject policyT3 · Project policyRedacted
npm-granular-token-three-occurrences-in-1miblarge-and-repeated-input-projections-generated · multiple-credentials-per-inputProject policyT3 · Project policyRedacted
npm-granular-token-three-occurrences-in-256kiblarge-and-repeated-input-projections-generated · multiple-credentials-per-inputProject policyT3 · Project policyRedacted
npm-granular-token-three-occurrences-in-64kiblarge-and-repeated-input-projections-generated · multiple-credentials-per-inputProject policyT3 · Project policyRedacted
npm-granular-token-two-distinct-keys-in-1miblarge-and-repeated-input-projections-generated · multiple-credentials-per-inputProject policyT3 · Project policyRedacted
npm-granular-token-two-distinct-keys-in-256kiblarge-and-repeated-input-projections-generated · multiple-credentials-per-inputProject policyT3 · Project policyRedacted
npm-granular-token-two-distinct-keys-in-64kiblarge-and-repeated-input-projections-generated · multiple-credentials-per-inputProject policyT3 · Project policyRedacted
npm-1npm · documented-format-literalMust redactT1 · Provider-documentedRedacted
npm-2npm · documented-format-literalMust redactT1 · Provider-documentedRedacted
npm-3npm · documented-format-literalMust redactT1 · Provider-documentedRedacted
npm-token-access-delimiter-plain-twinnpm · boundary-violationMust not flagT2 · Tool-corroborated · twinQuiet
npm-token-access-delimiter-unicode-crlf-twinnpm · boundary-violationMust not flagT2 · Tool-corroborated · twinQuiet
npm-token-access-plainnpm · documented-format-literalMust redactT1 · Provider-documentedRedacted
npm-token-access-plain-twinnpm · wrong-lengthMust not flagT2 · Tool-corroborated · twinQuiet
npm-token-access-prefix-plain-twinnpm · prefix-near-missMust not flagT2 · Tool-corroborated · twinQuiet
npm-token-access-prefix-unicode-crlf-twinnpm · prefix-near-missMust not flagT2 · Tool-corroborated · twinQuiet
npm-token-access-unicode-crlfnpm · documented-format-literalMust redactT1 · Provider-documentedRedacted
npm-token-access-unicode-crlf-twinnpm · wrong-lengthMust not flagT2 · Tool-corroborated · twinQuiet
npm-token-granular-token-note-prosenpm · prose-mentionMust not flagT3 · Project policyQuiet
npm-token-masknpm · benign-lookalikeMust not flagT3 · Project policyQuiet
npm-token-npmrc-auth-tokennpm · documented-format-literalMust redactT1 · Provider-documentedRedacted
npm-token-prefix-onlynpm · benign-lookalikeMust not flagT2 · Tool-corroboratedQuiet
npm-token-publish-workflow-envnpm · documented-format-literalMust redactT1 · Provider-documentedRedacted
npm-token-referencenpm · benign-lookalikeMust not flagT3 · Project policyQuiet
npm-token-shape-1-barenpm · documented-format-literalMust redactT1 · Provider-documentedRedacted
npm-token-shape-1-quotednpm · documented-format-literalMust redactT1 · Provider-documentedRedacted

Sources

Researched 2026-09-20.

Documentation and code

  • github.blog/changelog/2021-09-23-npm-has-a-new-access-token-format/

Other npm families