Skip to content
Benchmarks

redact-secret · Report

Legacy token

Pre-2021 unprefixed UUID-format token.

  • npm
  • Detectors: none mapped
  • Run 2026-10-07
  • Mode published · redact-secret 0.1.0-beta.14
  • Dossier verdictRejected
  • Dossier evidence levelNot recorded
  • Dossier researched2026-09-29
npm-token's own provider source is the changelog announcing the npm_ prefix scheme as a replacement, implying the prior UUID-format token predates it; that legacy shape is not matched by the npm_-prefixed pattern.

Research record

From credential-evidence snapshot-2026.10.06.4 · records at 77ce761 · schema 1.8.0. It describes the research on the format, not what any scanner or the product does, and not a support status.
  • Review stateDraft, not reviewed
  • Format revision1 · proposed, none current
  • ResearchRejected
  • Researched2026-09-29

2 events in the review history: 1 observed, 1 reviewed. Latest: observed on 2026-09-29 by automation, project maintainer. Project-maintained review is not independent validation. The family record at this release.

Format

Provider format research from credential-evidence snapshot-2026.10.06.4 · records at 77ce761 · schema 1.8.0.

What it looks like

Shape not recorded.

Format facts

Open questions

No open question is recorded for this revision.

Benchmark dossier notes

From the provider dossier, as written. The evidence level above says how well the format is backed; a fact the dossier does not record is not shown.
Shape
Unprefixed UUID-pattern token, 36 characters including hyphens (8-4-4-4-12 hex groups). Called "legacy" in the 2021 announcements and "classic" from 2025.
Contract in core
none for a bare UUID. npm-token claims npm_ + exactly 36 [A-Za-z0-9] only; NPM_TOKEN=<uuid> and authToken=<uuid> give a contextual finding, and the .npmrc keys above are contextual names since #1024. Living spec: detector-families.md.

In this benchmark

Fixture rows on the current run. Counts are for redact-secret in published · redact-secret 0.1.0-beta.14 mode.

No fixtures in this family yet

Nothing in the corpus targets it, so nothing is measured and no coverage is claimed.

Not measured

Scanner rules for this family

Mapped by hand (reviewed 2026-09-30) from each scanner's pinned rule file, never from what a scanner found on the fixtures.
Peer scanner rules that target this family
ScannerRuleWhat the rule matches
trufflehog · rules 3.97.4npmtokennpm keyword + a UUID

No rule maps to this family in flare-redact, gitleaks, openredaction.

0 of 0 rows

No fixtures in this family yet

Nothing in the corpus targets it, so nothing is measured and no coverage is claimed.

Not measured

Sources

Researched 2026-09-29.

Documentation and code

  • github.blog/changelog/2021-09-23-npm-has-a-new-access-token-format/
  • github.blog/security/announcing-npms-new-access-token-format/
  • github.blog/changelog/2025-11-05-npm-security-update-classic-token-creation-disabled-and-granular-token-changes/
  • github.blog/changelog/2025-12-09-npm-classic-tokens-revoked-session-based-auth-and-cli-token-management-now-available/
  • docs.npmjs.com/about-access-tokens
  • github.com/Yelp/detect-secrets/blob/5e141933554a0b74e7341841f318be21e895339c/detect_secrets/plugins/npm.py
  • github.com/trufflesecurity/trufflehog/blob/48b58d3bf3f02ba17bf23b87f095499bc80c6fd7/pkg/detectors/npmtoken/npmtoken.go
  • github.com/gitleaks/gitleaks/blob/b58d3f102cf3a2c84cb7f923d05c25c9b1aed84b/cmd/generate/config/rules/npm.go
  • docs.gitguardian.com/secrets-detection/secrets-detection-engine/detectors/specifics/npm_token
  • docs.github.com/en/code-security/secret-scanning/introduction/supported-secret-scanning-patterns

Research log

Other npm families