redact-secret · Report
Secret API key
sk- prefixed secret API key, including project- and service-account-scoped variants (sk-proj-, sk-svcacct-).
Research record
2 events in the review history: 1 observed, 1 reviewed. Latest: observed on 2026-09-23 by automation, project maintainer. Project-maintained review is not independent validation. The family record at this release.
Format
What it looks like
- Descriptive pattern
^sk-(?:[A-Za-z0-9]{20}T3BlbkFJ[A-Za-z0-9]{20}|(?:proj|svcacct)-[A-Za-z0-9_-]{74}T3BlbkFJ[A-Za-z0-9_-]{74})$
Parts are shown as recorded. Evidence classes belong to the facts below; no class is assigned to a part.
Format facts
Tool corroborated ·
tool-corroboration· current · observed 2026-09-23Pinned scanner rules are consistent with the contract grammar (2 artifacts: gitleaks 8.30.1; trufflehog 3.97.4).
- gitleaks/gitleaks @ v8.30.1: config/gitleaks.tomlscanner-rule-source · last read 2026-10-04 · latest outcome read · supports gitleaks 8.30.1: gitleaks.toml
- trufflesecurity/trufflehog @ v3.97.4: pkg/detectors/openai/openai.goscanner-rule-source · last read 2026-09-23 · latest outcome read · supports trufflehog 3.97.4: openai/openai
Tool corroborated ·
dossier-research· current · observed 2026-09-23Legacy dossier research (verdict ready, tier T2) cited 3 sources; the dossier does not attribute sources to individual properties.
- community.openai.com/t/1118492/2issue-or-discussion · last read 2026-09-23 · latest outcome read · supports Cited by the legacy dossier research for this family
- openai/codex @ 418199f6ade4f9018b1f0b455a685387a811ad2e: codex-rs/network-proxy/src/credential_broker/providers/openai.rsprovider-sdk-source · last read 2026-09-29 · latest outcome read · supports Cited by the legacy dossier research for this family · #L13-L23
- redact-secret/redact-secret @ 8b6a5fde52ecb4dfce13f09c7a947062d21483c7: docs/audits/evidence/657/README.mdproject-research-note · last read 2026-09-23 · latest outcome read · supports Final research evidence recorded by the legacy dossier
Provider documented ·
provider-key-kinds· current · observed 2026-10-04OpenAI documentation distinguishes API keys (standard keys for application requests, including project keys that are user-owned or owned by a service account, and legacy user API keys) from Admin API keys, which are created separately and cannot be used for non-administration endpoints. This establishes the functional distinction only; no page read states a prefix, marker, length or alphabet for any of them.
- API reference overview (authentication)provider-documentation · last read 2026-10-04 · latest outcome read · supports Create credentials: a standard API key for application requests, an Admin API key for Administration endpoints; Authentication: access through a legacy user API key is mentioned. · #authentication
- API reference: Administration overviewprovider-documentation · last read 2026-10-04 · latest outcome read · supports Admin API keys cannot be used for non-administration endpoints.
- Production best practices (API keys)provider-documentation · last read 2026-10-04 · latest outcome read · supports API Key Governance distinguishes service-account keys from user-owned project keys; guidance on project API keys, expiration and rotation.
- Manage service accounts with Terraformprovider-documentation · last read 2026-10-04 · latest outcome read · supports A service account is a nonhuman identity owned by a project, and its API keys are created through the Administration API.
Provider documented ·
provider-public-identifiers-and-redaction· current · observed 2026-10-04In OpenAI's API reference, a project API key resource carries an id (shown as key_abc), the owning project is identified by an id (proj_abc) and a service account by an id (svc_acct_abc); these identifiers are referenced in endpoints. The full key value is returned only by the creation response, and retrieval of an existing project API key returns a redacted_value (shown as sk-abc...def). This documents the identifier and redacted-display roles; it does not state a grammar for those identifiers.
- API reference: Retrieve project API keyprovider-documentation · last read 2026-10-04 · latest outcome read · supports ProjectAPIKey: id is the identifier referenced in API endpoints; redacted_value is the redacted value of the API key; example key_abc and sk-abc...def.
- API reference: Create project service accountprovider-documentation · last read 2026-10-04 · latest outcome read · supports Create project service account example response: service account id svc_acct_abc, key id key_abc, project proj_abc, key value shown once at creation.
- Manage service accounts with Terraformprovider-documentation · last read 2026-10-04 · latest outcome read · supports The full API-key value is available only in the create response; later project API-key retrieval returns a redacted value.
Provider documented ·
provider-example-value-not-contract-shaped· current · observed 2026-10-04The API reference's service-account creation example shows a key value of the form sk- followed by 18 letters and digits (sk-abcdefghijklmnop123), with no T3BlbkFJ marker and a body far shorter than any width in the descriptive pattern. The page presents it as an illustrative example response; this record does not infer from it that real keys lack the marker or have that length, nor that the value is safe to ignore.
- API reference: Create project service accountprovider-documentation · last read 2026-10-04 · latest outcome read · supports Example response api_key.value shown as sk-abcdefghijklmnop123.
Provider documented ·
provider-key-lifecycle-controls· current · observed 2026-10-04OpenAI's API key safety guidance (Help Center, read 2026-10-04) says project keys can be created with an expiration date after which requests from them are rejected, administrators can enforce a maximum key lifetime at the organization or project level, keys must not be deployed in client-side environments, and workload identity federation can replace a long-lived key with a short-lived access token. It states no prefix, marker, length or alphabet for any key; a missing format statement on this page is not evidence about the key shape.
- Best Practices for API Key Safetyprovider-documentation · last read 2026-10-04 · latest outcome read · supports Project keys can be created with an expiration date after which requests from those keys will be rejected; administrators can enforce a maximum API key lifetime at the organization or project level; never deploy the key in client-side environments; workload identity federation exchanges a trusted identity for a short-lived OpenAI access token. · #2-create-api-keys-with-an-expiration-date-and-establish-a-key-rotation-process
Open questions
No open question is recorded for this revision.
Benchmark dossier notes
- Shape
- prefixes
sk-proj-(project),sk-svcacct-(service account) and legacysk-, with the public watermarkT3BlbkFJbetween two segments. Namespaced keys measure 74/74 (164 or 167 characters in community reports); 58/58 and a 20/20 earlysk-proj-generation are older. Alphabet[A-Za-z0-9_-], no checksum documented.sk-None-andsk-service-appear in community sources only and are in no contract. - Basis
- none reaches T1, so the verdict is
readyat T2 (tool-corroborated contract), not T1. #657 records the T1 hunt as NOT FOUND, exhaustive as of 2026-09-23: an OpenAI-staff post on community.openai.com namessk-proj-(forum class) and provider code inopenai/codexnames the prefixes and the watermark (code, not a provider document). Lengths and alphabet come from gitleaks 8.30.1 and public-code measurements. - Issuance
- not attempted. The #657 web-search pass lists structural checks for a project key, two service-account keys and an optional admin key.
- Contract in core
- detector-families.md. #552 records that the frozen contract deliberately excludes shapes such as marker-less 48-byte bodies. #948 later made an off-grammar value under a provider-named variable such as
OPENAI_API_KEY=a generic finding.
In this benchmark
- Fixtures
- 47
- Left readable
- 0
- Redacted too much
- 0
- False alarms
- 0
47 fixtures: 13 expect a redaction, 25 must stay quiet, 9 record project policy. See every row
| Evidence level | Fixtures | Left readable | Too much | False alarms |
|---|---|---|---|---|
| T2Tool-corroborated | 30 | 0 | 0 | 0 |
| T3Project policy | 15 | 0 | 0 | 0 |
| T0Pending review | 2 | 0 | 0 | 0 |
Every scanner on the same fixtures
In run order. Counts are what each scanner recorded on this family's fixtures, whichever rules it has; a scanner with no rule for the family has nothing to report on it.
| Scanner | Fixtures | Left readable | Too much | False alarms |
|---|---|---|---|---|
| flare-redactRuntime library · 1.6.1 · Published npm package · secrets-only (pii, generic_assignment disabled) · JavaScript engine1 rule targets it | 47 | 8 | 0 | 6 |
| gitleaksRepository scanner · 8.30.1 · Directory scan · default rules1 rule targets it | 47 | 9 | 0 | 0 |
| redact-secretProduct measured here · 0.1.0-beta.14 · Published npm package · default detectors1 detector mapped | 47 | 0 | 0 | 0 |
| trufflehogRepository scanner · 3.97.4 · Filesystem scan · verification disabled1 rule targets it | 47 | 9 | 0 | 3 |
Benchmark dossier questions
- Open caveat
- No provider-domain page states prefix, marker, length or alphabet, so T1 is unreachable; the shipped contract stays a tool-corroborated T2 shape. Needs issued keys (steps in the #657 web-search pass).
Looks like it, but isn't
- Collisions
sk-ant-(Anthropic) andsk-or-(OpenRouter) share thesk-start. OpenAI staff saysk-proj-keys "work just like the previoussk-keys". A bare vendor-prefixed value is a separate lower-confidence layer (#552 update, ADR 2026-09-21).
Scanner rules for this family
| Scanner | Rule | What the rule matches |
|---|---|---|
| flare-redact · rules 1.6.1 | openai_key | sk- or sk-proj- + 20-64 characters |
| gitleaks · rules 8.30.1 | openai-api-key | sk-proj-, sk-svcacct- or sk-admin- with the T3BlbkFJ marker |
| openredaction · rules 1.1.5 | OPENAI_API_KEY | sk-proj- + 100-200 or sk- + 48-52 characters |
| trufflehog · rules 3.97.4 | openai | sk- with the T3BlbkFJ marker |
Fixtures in this family
| Fixture | Kind and evidence | redact-secret |
|---|---|---|
openai-token-alphabet-twinopenai · wrong-alphabet | Must not flagT2 · Tool-corroborated · twin | Quiet |
openai-token-compose-short-twinopenai · wrong-length | Must not flagT2 · Tool-corroborated · twin | Quiet |
openai-token-dash-identifier-embeddingopenai · benign-lookalike | Must not flagT2 · Tool-corroborated | Quiet |
openai-token-envopenai · documented-format-literal | Must redactT2 · Tool-corroborated | Redacted |
openai-token-legacy-plain-twinopenai · boundary-violation | Must not flagT2 · Tool-corroborated · twin | Quiet |
openai-token-legacy-unicode-crlf-twinopenai · boundary-violation | Must not flagT2 · Tool-corroborated · twin | Quiet |
openai-token-mcp-server-envopenai · documented-format-literal | Must redactT2 · Tool-corroborated | Redacted |
openai-token-proj-plainopenai · documented-format-literal | Must redactT2 · Tool-corroborated | Redacted |
openai-token-proj-plain-twinopenai · wrong-length | Must not flagT2 · Tool-corroborated · twin | Quiet |
openai-token-proj-unicode-crlfopenai · documented-format-literal | Must redactT2 · Tool-corroborated | Redacted |
openai-token-proj-unicode-crlf-twinopenai · wrong-length | Must not flagT2 · Tool-corroborated · twin | Quiet |
openai-token-python-clientopenai · documented-format-literal | Must redactT2 · Tool-corroborated | Redacted |
openai-token-shape-1-bareopenai · documented-format-literal | Project policyT3 · Project policy | Redacted |
openai-token-shape-1-quotedopenai · documented-format-literal | Project policyT3 · Project policy | Redacted |
openai-token-shape-1-unicode-crlfopenai · documented-format-literal | Project policyT3 · Project policy | Redacted |
openai-token-shape-2-bareopenai · documented-format-literal | Project policyT3 · Project policy | Redacted |
openai-token-shape-2-quotedopenai · documented-format-literal | Project policyT3 · Project policy | Redacted |
openai-token-shape-2-unicode-crlfopenai · documented-format-literal | Project policyT3 · Project policy | Redacted |
openai-token-shape-3-bareopenai · documented-format-literal | Project policyT3 · Project policy | Redacted |
openai-token-shape-3-quotedopenai · documented-format-literal | Project policyT3 · Project policy | Redacted |
openai-token-shape-3-unicode-crlfopenai · documented-format-literal | Project policyT3 · Project policy | Redacted |
openai-token-shell-exportopenai · documented-format-literal | Must redactT2 · Tool-corroborated | Redacted |
openai-token-svcacct-plainopenai · documented-format-literal | Must redactT2 · Tool-corroborated | Redacted |
openai-token-svcacct-unicode-crlfopenai · documented-format-literal | Must redactT2 · Tool-corroborated | Redacted |
openai-token-trailing-identifier-embeddingopenai · benign-lookalike | Must not flagT2 · Tool-corroborated | Quiet |
openai-token-actions-envopenai · documented-format-literal | Must redactT2 · Tool-corroborated | Redacted |
openai-token-actions-secret-referenceopenai · templated-reference | Must not flagT3 · Project policy | Quiet |
openai-token-compose-alphabet-twinopenai · wrong-alphabet | Must not flagT2 · Tool-corroborated · twin | Quiet |
openai-token-compose-envopenai · documented-format-literal | Must redactT2 · Tool-corroborated | Redacted |
openai-token-docs-template-placeholderopenai · documentation-placeholder | Must not flagT3 · Project policy | Quiet |
openai-token-leading-identifier-embeddingopenai · benign-lookalike | Must not flagT2 · Tool-corroborated | Quiet |
openai-token-legacy-plainopenai · documented-format-literal | Must redactT2 · Tool-corroborated | Redacted |
openai-token-legacy-unicode-crlfopenai · documented-format-literal | Must redactT2 · Tool-corroborated | Redacted |
openai-token-maskopenai · benign-lookalike | Must not flagT3 · Project policy | Quiet |
openai-token-org-and-project-ids-public-idopenai · public-identifier | Must not flagT2 · Tool-corroborated | Quiet |
openai-token-prefix-onlyopenai · benign-lookalike | Must not flagT2 · Tool-corroborated | Quiet |
openai-token-prefix-twinopenai · prefix-near-miss | Must not flagT2 · Tool-corroborated · twin | Quiet |
openai-token-project-keys-note-proseopenai · prose-mention | Must not flagT3 · Project policy | Quiet |
openai-token-python-env-referenceopenai · templated-reference | Must not flagT3 · Project policy | Quiet |
openai-token-raw-requestopenai · documented-format-literal | Must redactT2 · Tool-corroborated | Redacted |
openai-token-referenceopenai · benign-lookalike | Must not flagT3 · Project policy | Quiet |
openai-token-response-ids-public-idopenai · public-identifier | Must not flagT2 · Tool-corroborated | Quiet |
openai-token-short-bodyopenai · benign-lookalike | Must not flagT2 · Tool-corroborated | Quiet |
openai-token-svcacct-plain-twinopenai · unsettled-evidence-input | Pending reviewT0 · Pending · twin | Unscored |
openai-token-svcacct-unicode-crlf-twinopenai · unsettled-evidence-input | Pending reviewT0 · Pending · twin | Unscored |
openai-token-truncated-log-near-missopenai · format-near-miss | Must not flagT2 · Tool-corroborated | Quiet |
openai-token-wheel-checksum-encoded-valueopenai · benign-encoded-value | Must not flagT2 · Tool-corroborated | Quiet |
Sources
Documentation and code
- community.openai.com/t/1118492/2
- github.com/openai/codex/blob/418199f6ade4f9018b1f0b455a685387a811ad2e/codex-rs/network-proxy/src/credential_broker/providers/openai.rs#L13-L23
Research log
- redact-secret/redact-secret#657Research issue
- redact-secret/redact-secret#552Research issue
- redact-secret/redact-secret#948Research issue
- Final evidence, pinned to a commit/redact-secret/redact-secret/blob/8b6a5fde52ecb4dfce13f09c7a947062d21483c7/docs/audits/evidence/657/README.md