Skip to content
Benchmarks

redact-secret · Report

Management API key

sk-or-mgmt- prefixed management (formerly provisioning) key for the /api/v1/keys routes; cannot call completion endpoints. Body length and alphabet are undocumented.

  • OpenRouter
  • Detectors: none mapped
  • Run 2026-10-07
  • Mode published · redact-secret 0.1.0-beta.14
  • Dossier verdictIssuance-gated
  • Dossier evidence levelT0 · Pending
  • Dossier researched2026-09-29
Unsupported and unclaimed (#208, research #220): a real secret, but no body grammar is published and no product detector, contract or fixture targets it. It is never used as a benign control of openrouter:api-key.

Research record

From credential-evidence snapshot-2026.10.06.4 · records at 77ce761 · schema 1.8.0. It describes the research on the format, not what any scanner or the product does, and not a support status.
  • Review stateDraft, not reviewed
  • Format revision1 · proposed, none current
  • ResearchResearched
  • Researched2026-09-29

What blocks the research

  • Issuance-gatedThe prefix itself is contested (provider statements say sk-or-mgmt-, three first-hand users say sk-or-v1-) and no body grammar exists; needs one management key measured (free, structure only).

2 events in the review history: 1 observed, 1 reviewed. Latest: observed on 2026-09-29 by automation, project maintainer. Project-maintained review is not independent validation. The family record at this release.

Format

Provider format research from credential-evidence snapshot-2026.10.06.4 · records at 77ce761 · schema 1.8.0.

What it looks like

Shape not recorded.

Format facts

Open questions

No open question is recorded for this revision.

Benchmark dossier notes

From the provider dossier, as written. The evidence level above says how well the format is backed; a fact the dossier does not record is not shown.
Shape
prefix sk-or-mgmt-, stated only on the Terraform provider page and its README and by one staff statement. Body length, alphabet and any embedded version or checksum are not documented anywhere found. Three independent first-hand users report that their live management keys start sk-or-v1- like inference keys; if that is right, management keys are sk-or-v1- + 64 lowercase hex, the openrouter:api-key contract already covers them and no separate family is needed.
Basis
- provider docs (R4, prefix claim): OpenRouterTeam/docs terraform.mdx, 2026-09-02, "Management API key ... which starts with sk-or-mgmt-..."; the terraform provider README (first seen 2026-07-17) repeats it as a placeholder. - provider staff statement (R3, prefix, as of 2026-08-25): terraform-provider-openrouter PR #253, "Management keys are a distinct credential with their own prefix, sk-or-mgmt-..." (the author's profile names @OpenRouterTeam). - provider docs (T1, for inference keys only): OpenRouter's own secret-scanning page states sk-or-v1- + 64 lowercase hex and has no management-key row. - contradicting first-hand reports (independent, 2026-04-03, 2026-08-10, 2026-08-24): hydra's key utilities ("OR management keys use sk-or-v1- prefix, NOT sk-or-mgmt-"), a report in the inkwell sandboxes repository ("Both key types have the same sk-or-v1-... prefix. I confirmed this on my own account") and openrouter-keymaster's redaction module. A format change after 2026-08-24 is possible but unproven. - peer rule: osv-scalibr sk-or-v[0-9]+-[A-Za-z0-9_-]{20,} would not match sk-or-mgmt-. No other peer scanner has an sk-or-mgmt rule; 111 code-search hits are docs, placeholders and prefix checks. - GitGuardian says one detector covers provisioning keys, which conflicts with the sk-or-mgmt- prefix.
Issuance
free at /settings/management-keys, shown once, optional expiry fixed at creation; not attempted. The #1012 check: create one key with the shortest expiry and record the exact prefix, total length, body alphabet (lowercase hex only?) and that GET /api/v1/key reports it as a management key; then delete it.
Contract in core
unclaimed per the #726 record (detector-families.md). If the keys are sk-or-v1- they are redacted under the inference type (the role is not lexically visible); if sk-or-mgmt-, only in named and Bearer contexts.

In this benchmark

Fixture rows on the current run. Counts are for redact-secret in published · redact-secret 0.1.0-beta.14 mode.

No fixtures in this family yet

Nothing in the corpus targets it, so nothing is measured and no coverage is claimed.

Not measured

Benchmark dossier questions

Things the sources do not settle. They are listed so nobody reads them as settled.
Blocked by
The prefix itself is contested (provider statements say sk-or-mgmt-, three first-hand users say sk-or-v1-) and no body grammar exists; needs one management key measured (free, structure only).

Looks like it, but isn't

Values the dossier records as resembling this credential without being one.
Collisions
shares the sk-or- stem with inference keys. A real secret, so it is never a benign control for openrouter:api-key.

Scanner rules for this family

Mapped by hand (reviewed 2026-09-30) from each scanner's pinned rule file, never from what a scanner found on the fixtures.

No peer rule maps to this family

None of the reviewed peer scanners has a rule that can match a credential of this family.

None mapped

0 of 0 rows

No fixtures in this family yet

Nothing in the corpus targets it, so nothing is measured and no coverage is claimed.

Not measured

Sources

Researched 2026-09-29.

Documentation and code

  • openrouter.ai/docs/guides/overview/auth/management-api-keys
  • github.com/OpenRouterTeam/terraform-provider-openrouter
  • github.com/OpenRouterTeam/docs/blob/9e4172882651f7a85099a3054d120e66ef850715/guides/overview/terraform.mdx#L41
  • github.com/OpenRouterTeam/terraform-provider-openrouter/blob/7fd0e341dc9c638333952e8e4159c198b7028d91/README.md#L39
  • github.com/OpenRouterTeam/terraform-provider-openrouter/pull/253
  • github.com/OpenRouterTeam/docs/blob/9e4172882651f7a85099a3054d120e66ef850715/guides/features/guardrails/secret-formats.mdx#L36
  • github.com/zaydiscold/hydra/blob/cf1926f166be543f3af93a4d50b2bc548d6b6409/server/services/key-utils.js#L4-L6
  • github.com/disler/inkwell-agent-sandboxes-and-software-factory/issues/3
  • github.com/kljensen/openrouter-keymaster/blob/d54808de2de0df4fae0367a2680ab71379643642/crates/core/src/redaction.rs#L20-L25

Research log

Other OpenRouter families