Skip to content
Benchmarks

redact-secret · Report

Service account token (ops_)

ops_ + the Base64url encoding of a serialized JSON object (so ops_eyJ), variable length; the 250-byte floor after the lead is project policy.

  • 1Password
  • Detectors: onepassword-service-account-token
  • Run 2026-10-07
  • Mode published · redact-secret 0.1.0-beta.14
  • Dossier verdictReady
  • Dossier evidence levelT1 · Provider-documented
  • Dossier researched2026-09-28
Registry detector onepassword-service-account-token since redact-secret#913 (registry pinned at 1127bf9); graduated from a Beta.11 arrival family (#436), contract in benchmarks/lib/beta8/436b.ts. T1 on provider documentation; gitleaks 8.30.1 has a rule, trufflehog 3.97.4 none.

Research record

From credential-evidence snapshot-2026.10.06.4 · records at 77ce761 · schema 1.8.0. It describes the research on the format, not what any scanner or the product does, and not a support status.
  • Review stateDraft, not reviewed
  • Format revision1 · current
  • ResearchResearched
  • Researched2026-09-28

3 events in the review history: 2 observed, 1 reviewed. Latest: observed on 2026-09-28 by automation, project maintainer. Project-maintained review is not independent validation. The family record at this release.

Format

Provider format research from credential-evidence snapshot-2026.10.06.4 · records at 77ce761 · schema 1.8.0.

What it looks like

Descriptive pattern
^ops_eyJ[A-Za-z0-9_-]{250,}={0,2}$

Parts are shown as recorded. Evidence classes belong to the facts below; no class is assigned to a part.

Format facts

Open questions

No open question is recorded for this revision.

Benchmark dossier notes

From the provider dossier, as written. The evidence level above says how well the format is backed; a fact the dossier does not record is not shown.
Shape
prefix ops_, then a Base64url body beginning eyJ (Base64 of a JSON object opening), variable length, optional = padding kept inside the span. The docs example is 634 characters; the observed range in the research is 634 to 870.
Basis
T1 from the provider page: the format "uses ops_ as the token prefix" and the rest is "Base64 URL encoded". The eyJ lead follows from that and from the docs example (R4, R5). The documented alphabet is Base64url, so the handoff uses [A-Za-z0-9_-] rather than the alphanumeric-only samples or gitleaks' standard-Base64 class. The 250-byte floor matches an existing gitleaks floor and is policy. Re-checked 2026-09-28.
Issuance
not attempted.
Contract in core
detector-families.md.

In this benchmark

Fixture rows on the current run. Counts are for redact-secret in published · redact-secret 0.1.0-beta.14 mode.
Fixtures
39
Left readable
0
Redacted too much
0
False alarms
0

39 fixtures: 16 expect a redaction, 23 must stay quiet. See every row

redact-secret fixture counts by evidence level
Evidence levelFixturesLeft readableToo muchFalse alarms
T1Provider-documented16000
T2Tool-corroborated15000
T3Project policy8000

Every scanner on the same fixtures

In run order. Counts are what each scanner recorded on this family's fixtures, whichever rules it has; a scanner with no rule for the family has nothing to report on it.

Counts per scanner on this family's fixtures
ScannerFixturesLeft readableToo muchFalse alarms
flare-redactRuntime library · 1.6.1 · Published npm package · secrets-only (pii, generic_assignment disabled) · JavaScript engineNo rule maps to it391510
gitleaksRepository scanner · 8.30.1 · Directory scan · default rules1 rule targets it391600
redact-secretProduct measured here · 0.1.0-beta.14 · Published npm package · default detectors1 detector mapped39000
trufflehogRepository scanner · 3.97.4 · Filesystem scan · verification disabledNo rule maps to it391600

Benchmark dossier questions

Things the sources do not settle. They are listed so nobody reads them as settled.
Open caveat
Length is variable by construction, with one T1 example; the minimum of 250 Base64url bytes after the prefix is project policy, not a provider fact.

Looks like it, but isn't

Values the dossier records as resembling this credential without being one.
Collisions
the Connect server token (OP_CONNECT_TOKEN) is a standard JWT. The Account Secret Key is a separate credential. op://vault/item/field secret references are not secrets.

Scanner rules for this family

Mapped by hand (reviewed 2026-09-30) from each scanner's pinned rule file, never from what a scanner found on the fixtures.
Peer scanner rules that target this family
ScannerRuleWhat the rule matches
gitleaks · rules 8.30.11password-service-account-tokenops_eyJ + Base64 body

No rule maps to this family in flare-redact, openredaction, trufflehog.

39 of 39 rows

Fixtures in this family

39 rows, redact-secret's outcome on each. Rows that need a look come first (0), then the rest in corpus order. Choose "Every scanner" to see each scanner's outcome for the same rows.
Fixtures in Service account token (ops_)
FixtureKind and evidenceredact-secret
onepassword-service-account-token-actions-envonepassword · documented-format-literalMust redactT1 · Provider-documentedRedacted
onepassword-service-account-token-bare-proseonepassword · documented-format-literalMust redactT1 · Provider-documentedRedacted
onepassword-service-account-token-bearer-headeronepassword · documented-format-literalMust redactT1 · Provider-documentedRedacted
onepassword-service-account-token-chat-pasteonepassword · documented-format-literalMust redactT1 · Provider-documentedRedacted
onepassword-service-account-token-dotenvonepassword · documented-format-literalMust redactT1 · Provider-documentedRedacted
onepassword-service-account-token-exportonepassword · documented-format-literalMust redactT1 · Provider-documentedRedacted
onepassword-service-account-token-json-api-keyonepassword · documented-format-literalMust redactT1 · Provider-documentedRedacted
onepassword-service-account-token-json-tokenonepassword · documented-format-literalMust redactT1 · Provider-documentedRedacted
onepassword-service-account-token-key-shape-bareonepassword · documented-format-literalMust redactT1 · Provider-documentedRedacted
onepassword-service-account-token-key-shape-quotedonepassword · documented-format-literalMust redactT1 · Provider-documentedRedacted
onepassword-service-account-token-key-shape-unicode-crlfonepassword · documented-format-literalMust redactT1 · Provider-documentedRedacted
onepassword-service-account-token-mcp-envonepassword · documented-format-literalMust redactT1 · Provider-documentedRedacted
onepassword-service-account-token-op-clionepassword · documented-format-literalMust redactT1 · Provider-documentedRedacted
onepassword-service-account-token-python-sdkonepassword · documented-format-literalMust redactT1 · Provider-documentedRedacted
onepassword-service-account-token-sdk-kwargonepassword · documented-format-literalMust redactT1 · Provider-documentedRedacted
onepassword-service-account-token-x-api-key-headeronepassword · documented-format-literalMust redactT1 · Provider-documentedRedacted
onepassword-service-account-token-account-and-vault-public-idonepassword · public-identifierMust not flagT2 · Tool-corroboratedQuiet
onepassword-service-account-token-actions-secret-referenceonepassword · templated-referenceMust not flagT3 · Project policyQuiet
onepassword-service-account-token-body-249-twinonepassword · wrong-lengthMust not flagT2 · Tool-corroborated · twinQuiet
onepassword-service-account-token-cache-digest-encoded-valueonepassword · benign-encoded-valueMust not flagT2 · Tool-corroboratedQuiet
onepassword-service-account-token-connect-jwt-twinonepassword · prefix-near-missMust not flagT2 · Tool-corroborated · twinQuiet
onepassword-service-account-token-ellipsis-placeholderonepassword · documentation-placeholderMust not flagT3 · Project policyQuiet
onepassword-service-account-token-hyphen-prefix-twinonepassword · boundary-violationMust not flagT2 · Tool-corroborated · twinQuiet
onepassword-service-account-token-label-proseonepassword · benign-lookalikeMust not flagT3 · Project policyQuiet
onepassword-service-account-token-leading-glue-twinonepassword · boundary-violationMust not flagT2 · Tool-corroborated · twinQuiet
onepassword-service-account-token-lowercase-j-twinonepassword · prefix-near-missMust not flagT2 · Tool-corroborated · twinQuiet
onepassword-service-account-token-maskonepassword · benign-lookalikeMust not flagT3 · Project policyQuiet
onepassword-service-account-token-masked-placeholderonepassword · documentation-placeholderMust not flagT3 · Project policyQuiet
onepassword-service-account-token-ops-identifiers-public-idonepassword · public-identifierMust not flagT2 · Tool-corroboratedQuiet
onepassword-service-account-token-padding-inside-body-twinonepassword · wrong-alphabetMust not flagT2 · Tool-corroborated · twinQuiet
onepassword-service-account-token-plus-in-body-twinonepassword · wrong-alphabetMust not flagT2 · Tool-corroborated · twinQuiet
onepassword-service-account-token-prefix-onlyonepassword · benign-lookalikeMust not flagT2 · Tool-corroboratedQuiet
onepassword-service-account-token-referenceonepassword · benign-lookalikeMust not flagT3 · Project policyQuiet
onepassword-service-account-token-secret-reference-referenceonepassword · templated-referenceMust not flagT3 · Project policyQuiet
onepassword-service-account-token-short-bodyonepassword · benign-lookalikeMust not flagT2 · Tool-corroboratedQuiet
onepassword-service-account-token-slash-in-body-twinonepassword · wrong-alphabetMust not flagT2 · Tool-corroborated · twinQuiet
onepassword-service-account-token-token-guidance-proseonepassword · prose-mentionMust not flagT3 · Project policyQuiet
onepassword-service-account-token-truncated-near-missonepassword · format-near-missMust not flagT2 · Tool-corroboratedQuiet
onepassword-service-account-token-uppercase-prefix-twinonepassword · prefix-near-missMust not flagT2 · Tool-corroborated · twinQuiet

Sources

Researched 2026-09-28.

Documentation and code

Research log