redact-secret · Report
Management API token (SSWS)
00-prefixed 42-character API token sent as Authorization: SSWS; recognized beside the SSWS scheme or a same-line okta keyword.
Research record
3 events in the review history: 2 observed, 1 reviewed. Latest: observed on 2026-09-29 by automation, project maintainer. Project-maintained review is not independent validation. The family record at this release.
Format
What it looks like
- Descriptive pattern
^00[A-Za-z0-9_-]{40}$
Parts are shown as recorded. Evidence classes belong to the facts below; no class is assigned to a part.
Format facts
Provider documented ·
mutable-property-source· current · observed 2026-09-23Documentation for the one property varied in legacy twin fixtures (SSWS authorization example): the guide states "Authorization: SSWS 00QCjAl4MlV-WPXM...0HmjFx-vbGua", establishing the SSWS scheme and a value that begins with the literal 00. It backs a prefix twin only; the 40-byte body length and its alphabet stay tool-corroborated and the positive tier is unchanged
- developer.okta.com/docs/guides/create-an-api-token/main/provider-documentation · last read 2026-09-29 · latest outcome read · supports the guide states "Authorization: SSWS 00QCjAl4MlV-WPXM...0HmjFx-vbGua", establishing the SSWS scheme and a value that begins with the literal 00. It backs a prefix twin only; the 40-byte body length and its alphabet stay tool-corroborated and the positive tier is unchanged
Tool corroborated ·
tool-corroboration· current · observed 2026-09-23Pinned scanner rules are consistent with the contract grammar (2 artifacts: gitleaks 8.30.1; trufflehog 3.97.4).
- gitleaks/gitleaks @ v8.30.1: config/gitleaks.tomlscanner-rule-source · last read 2026-10-04 · latest outcome read · supports gitleaks 8.30.1: gitleaks.toml
- trufflesecurity/trufflehog @ v3.97.4: pkg/detectors/okta/okta.goscanner-rule-source · last read 2026-09-23 · latest outcome read · supports trufflehog 3.97.4: okta/okta
Tool corroborated ·
dossier-research· current · observed 2026-09-29Legacy dossier research (verdict ready, tier T2) cited 5 sources; the dossier does not attribute sources to individual properties.
- developer.okta.com/docs/guides/create-an-api-token/main/provider-documentation · last read 2026-09-29 · latest outcome read · supports Cited by the legacy dossier research for this family
- okta/okta-developer-docs @ 8aff3329cb8e651d2182ce6dcd5ebd303b42a690: packages/@okta/vuepress-site/books/api-security/api-keys/other-options/index.mdprovider-documentation · last read 2026-09-29 · latest outcome read · supports Cited by the legacy dossier research for this family · #L18
- okta/okta-developer-docs @ ae696b9f70cd1bca21f640f4ad3bbdff461279ff: packages/%40okta/vuepress-site/docs/guides/oie-upgrade-api-sdk-to-oie-sdk/main/index.mdprovider-documentation · last read 2026-09-29 · latest outcome read · supports Cited by the legacy dossier research for this family
- okta/okta-management-openapi-spec @ 74fcd17fad54332caee96ebbb11fd7f203b03e4f: dist/current/management-dev-noEnums-minimal.yamlprovider-documentation · last read 2026-09-29 · latest outcome read · supports Cited by the legacy dossier research for this family · #L60548
- redact-secret/redact-secret @ add1188fed9993723c59fbce8c867086b9d2049a: docs/audits/evidence/1013/okta-api-token.mdproject-research-note · last read 2026-09-29 · latest outcome read · supports Final research evidence recorded by the legacy dossier
Unresolved ·
taxonomy-sources· current · observed 2026-09-29The legacy taxonomy lists 1 source for this family. The taxonomy records no date; the dossier researchedAt is used as the observed-at date.
- developer.okta.com/docs/guides/create-an-api-token/main/provider-documentation · last read 2026-09-29 · latest outcome read · supports Listed as a source for this family in the legacy taxonomy
Open questions
No open question is recorded for this revision.
Benchmark dossier notes
- Shape
- literal
00then 40 characters, 42 in total. Alphabet: TruffleHog and Nosey Parker use[A-Za-z0-9_-]; gitleaks and betterleaks also allow=. Of 52 distinct non-placeholder public candidates, 47 were 42 characters, none contained=, and_and-were both common. Okta's own migration guide shows an unelided value of00+ 40[A-Za-z0-9](recorded in the benchmarks empirical observations, not in a core thread; the core threads show only the elided example). - Basis
- T2. Provider prose shows the
SSWSscheme and the leading00only (no length, no alphabet), but Okta's own repositories hold three dated, distinct full-length examples, all00+ 40 alphanumeric: the OIE-upgrade guide, the management OpenAPI spec (2025-01 to 2026-03) and an API-security book page (2019) (redact-secret#1013). A 2019 devforum answer says "always 42 characters" and gives^00[a-zA-Z0-9\-\_]{40}$; its author's staff status is not confirmed on the forum. Both 2023 items the benchmark ledger records come from one devforum thread (2023-09-21): an Okta team reply, "You should not assume a set structure for Okta's API tokens" (the same reply says there are no plans to change it), and a customer's[A-Za-z0-9-]reading whose own regex admits_. gitleaks'=comes from its genericAlphaNumericExtendedhelper (PR #1599), not from Okta evidence; no Okta example contains=. GitGuardian records the detector asPrefixed: False, which classifies its detector rather than the tokens. Okta does not appear in GitHub's secret-scanning partner list. - Issuance
- UI only (the Okta API cannot create SSWS tokens); a free developer org works. The #694 hands-on checklist (total length, leading
00, alphabet classes, header, checksum) has no recorded result. - Contract in core
- detector-families.md; detector added by redact-secret#315. No frozen evidence folder exists for #694.
In this benchmark
- Fixtures
- 40
- Left readable
- 0
- Redacted too much
- 0
- False alarms
- 0
40 fixtures: 16 expect a redaction, 24 must stay quiet. See every row
| Evidence level | Fixtures | Left readable | Too much | False alarms |
|---|---|---|---|---|
| T2Tool-corroborated | 32 | 0 | 0 | 0 |
| T3Project policy | 8 | 0 | 0 | 0 |
Every scanner on the same fixtures
In run order. Counts are what each scanner recorded on this family's fixtures, whichever rules it has; a scanner with no rule for the family has nothing to report on it.
| Scanner | Fixtures | Left readable | Too much | False alarms |
|---|---|---|---|---|
| flare-redactRuntime library · 1.6.1 · Published npm package · secrets-only (pii, generic_assignment disabled) · JavaScript engineNo rule maps to it | 40 | 16 | 0 | 0 |
| gitleaksRepository scanner · 8.30.1 · Directory scan · default rules1 rule targets it | 40 | 6 | 0 | 3 |
| redact-secretProduct measured here · 0.1.0-beta.14 · Published npm package · default detectors1 detector mapped | 40 | 0 | 0 | 0 |
| trufflehogRepository scanner · 3.97.4 · Filesystem scan · verification disabled1 rule targets it | 40 | 12 | 0 | 0 |
Benchmark dossier questions
- Open caveat
- Okta states no grammar in prose and its 2023 staff answer says not to assume a structure; three provider examples agree on
00+ 40. READY-T2 once Q-OK accepts the four bounded dispositions; no issuance is required (an optional check could only close the_question).
Looks like it, but isn't
- Collisions
00is not a distinctive prefix; a value is claimed beside theSSWSscheme or a same-lineoktakeyword. TruffleHog gates on an Okta tenant domain.
Scanner rules for this family
| Scanner | Rule | What the rule matches |
|---|---|---|
| gitleaks · rules 8.30.1 | okta-access-token | okta keyword + 00 + 40 characters |
| trufflehog · rules 3.97.4 | okta | .okta domain + 00 + 40 characters |
No rule maps to this family in flare-redact, openredaction.
Fixtures in this family
| Fixture | Kind and evidence | redact-secret |
|---|---|---|
okta-api-token-actions-envokta · documented-format-literal | Must redactT2 · Tool-corroborated | Redacted |
okta-api-token-compose-envokta · documented-format-literal | Must redactT2 · Tool-corroborated | Redacted |
okta-api-token-curl-sswsokta · documented-format-literal | Must redactT2 · Tool-corroborated | Redacted |
okta-api-token-envokta · documented-format-literal | Must redactT2 · Tool-corroborated | Redacted |
okta-api-token-keyword-context-bareokta · documented-format-literal | Must redactT2 · Tool-corroborated | Redacted |
okta-api-token-keyword-context-bare-twinokta · wrong-alphabet | Must not flagT2 · Tool-corroborated · twin | Quiet |
okta-api-token-keyword-context-quotedokta · documented-format-literal | Must redactT2 · Tool-corroborated | Redacted |
okta-api-token-keyword-context-quoted-twinokta · wrong-alphabet | Must not flagT2 · Tool-corroborated · twin | Quiet |
okta-api-token-keyword-context-unicode-crlfokta · documented-format-literal | Must redactT2 · Tool-corroborated | Redacted |
okta-api-token-keyword-context-unicode-crlf-twinokta · wrong-alphabet | Must not flagT2 · Tool-corroborated · twin | Quiet |
okta-api-token-node-clientokta · documented-format-literal | Must redactT2 · Tool-corroborated | Redacted |
okta-api-token-raw-requestokta · documented-format-literal | Must redactT2 · Tool-corroborated | Redacted |
okta-api-token-request-logokta · documented-format-literal | Must redactT2 · Tool-corroborated | Redacted |
okta-api-token-settings-jsonokta · documented-format-literal | Must redactT2 · Tool-corroborated | Redacted |
okta-api-token-shell-exportokta · documented-format-literal | Must redactT2 · Tool-corroborated | Redacted |
okta-api-token-ssws-header-bareokta · documented-format-literal | Must redactT2 · Tool-corroborated | Redacted |
okta-api-token-ssws-header-quotedokta · documented-format-literal | Must redactT2 · Tool-corroborated | Redacted |
okta-api-token-ssws-header-unicode-crlfokta · documented-format-literal | Must redactT2 · Tool-corroborated | Redacted |
okta-api-token-tfvarsokta · documented-format-literal | Must redactT2 · Tool-corroborated | Redacted |
okta-api-token-actions-secret-referenceokta · templated-reference | Must not flagT3 · Project policy | Quiet |
okta-api-token-api-token-listing-public-idokta · public-identifier | Must not flagT2 · Tool-corroborated | Quiet |
okta-api-token-cli-checksum-encoded-valueokta · benign-encoded-value | Must not flagT2 · Tool-corroborated | Quiet |
okta-api-token-docs-template-placeholderokta · documentation-placeholder | Must not flagT3 · Project policy | Quiet |
okta-api-token-label-proseokta · benign-lookalike | Must not flagT3 · Project policy | Quiet |
okta-api-token-maskokta · benign-lookalike | Must not flagT3 · Project policy | Quiet |
okta-api-token-masked-console-placeholderokta · documentation-placeholder | Must not flagT3 · Project policy | Quiet |
okta-api-token-postman-variable-referenceokta · templated-reference | Must not flagT3 · Project policy | Quiet |
okta-api-token-prefix-onlyokta · benign-lookalike | Must not flagT2 · Tool-corroborated | Quiet |
okta-api-token-public-idokta · benign-lookalike | Must not flagT2 · Tool-corroborated | Quiet |
okta-api-token-referenceokta · benign-lookalike | Must not flagT3 · Project policy | Quiet |
okta-api-token-rotation-note-proseokta · prose-mention | Must not flagT3 · Project policy | Quiet |
okta-api-token-short-bodyokta · benign-lookalike | Must not flagT2 · Tool-corroborated | Quiet |
okta-api-token-short-token-near-missokta · format-near-miss | Must not flagT2 · Tool-corroborated | Quiet |
okta-api-token-ssws-header-bare-twinokta · wrong-length | Must not flagT2 · Tool-corroborated · twin | Quiet |
okta-api-token-ssws-header-prefix-bare-twinokta · prefix-near-miss | Must not flagT2 · Tool-corroborated · twin | Quiet |
okta-api-token-ssws-header-prefix-quoted-twinokta · prefix-near-miss | Must not flagT2 · Tool-corroborated · twin | Quiet |
okta-api-token-ssws-header-prefix-unicode-crlf-twinokta · prefix-near-miss | Must not flagT2 · Tool-corroborated · twin | Quiet |
okta-api-token-ssws-header-quoted-twinokta · wrong-length | Must not flagT2 · Tool-corroborated · twin | Quiet |
okta-api-token-ssws-header-unicode-crlf-twinokta · wrong-length | Must not flagT2 · Tool-corroborated · twin | Quiet |
okta-api-token-user-and-group-ids-public-idokta · public-identifier | Must not flagT2 · Tool-corroborated | Quiet |
Sources
Documentation and code
- developer.okta.com/docs/guides/create-an-api-token/main/
- github.com/okta/okta-developer-docs/blob/ae696b9f70cd1bca21f640f4ad3bbdff461279ff/packages/%40okta/vuepress-site/docs/guides/oie-upgrade-api-sdk-to-oie-sdk/main/index.md
- github.com/okta/okta-management-openapi-spec/blob/74fcd17fad54332caee96ebbb11fd7f203b03e4f/dist/current/management-dev-noEnums-minimal.yaml#L60548
- github.com/okta/okta-developer-docs/blob/8aff3329cb8e651d2182ce6dcd5ebd303b42a690/packages/@okta/vuepress-site/books/api-security/api-keys/other-options/index.md#L18
Research log
- redact-secret/redact-secret#694Research issue
- redact-secret/redact-secret#315Research issue
- redact-secret/redact-secret#1013Research issue
- Final evidence, pinned to a commit/redact-secret/redact-secret/blob/add1188fed9993723c59fbce8c867086b9d2049a/docs/audits/evidence/1013/okta-api-token.md