redact-secret · Report
Management API key
sk-or-mgmt- prefixed management (formerly provisioning) key for the /api/v1/keys routes; cannot call completion endpoints. Body length and alphabet are undocumented.
Research record
What blocks the research
- Issuance-gatedThe prefix itself is contested (provider statements say sk-or-mgmt-, three first-hand users say sk-or-v1-) and no body grammar exists; needs one management key measured (free, structure only).
2 events in the review history: 1 observed, 1 reviewed. Latest: observed on 2026-09-29 by automation, project maintainer. Project-maintained review is not independent validation. The family record at this release.
Format
What it looks like
Shape not recorded.
Format facts
Unresolved ·
dossier-research· current · observed 2026-09-29Legacy dossier research (verdict issuance-gated, tier T0) cited 8 sources; the dossier does not attribute sources to individual properties.
- github.com/disler/inkwell-agent-sandboxes-and-software-factory/issues/3issue-or-discussion · last read 2026-09-29 · latest outcome read · supports Cited by the legacy dossier research for this family
- kljensen/openrouter-keymaster @ d54808de2de0df4fae0367a2680ab71379643642: crates/core/src/redaction.rsother · last read 2026-09-29 · latest outcome read · supports Cited by the legacy dossier research for this family · #L20-L25
- OpenRouterTeam/docs @ 9e4172882651f7a85099a3054d120e66ef850715: guides/overview/terraform.mdxother · last read 2026-09-29 · latest outcome read · supports Cited by the legacy dossier research for this family · #L41
- OpenRouterTeam/docs @ 9e4172882651f7a85099a3054d120e66ef850715: guides/features/guardrails/secret-formats.mdxother · last read 2026-09-29 · latest outcome read · supports Cited by the legacy dossier research for this family · #L36
- github.com/OpenRouterTeam/terraform-provider-openrouter/pull/253issue-or-discussion · last read 2026-09-29 · latest outcome read · supports Cited by the legacy dossier research for this family
- OpenRouterTeam/terraform-provider-openrouter @ 7fd0e341dc9c638333952e8e4159c198b7028d91: README.mdother · last read 2026-09-29 · latest outcome read · supports Cited by the legacy dossier research for this family · #L39
- redact-secret/redact-secret @ 378581770a87751d72e27529796c4f790649fd00: docs/audits/evidence/1012/openrouter-management-api-key.mdproject-research-note · last read 2026-09-29 · latest outcome read · supports Final research evidence recorded by the legacy dossier
- zaydiscold/hydra @ cf1926f166be543f3af93a4d50b2bc548d6b6409: server/services/key-utils.jsother · last read 2026-09-29 · latest outcome read · supports Cited by the legacy dossier research for this family · #L4-L6
Unresolved ·
taxonomy-sources· current · observed 2026-09-29The legacy taxonomy lists 2 sources for this family. The taxonomy records no date; the dossier researchedAt is used as the observed-at date.
- github.com/OpenRouterTeam/terraform-provider-openrouterprovider-documentation · last read 2026-09-29 · latest outcome read · supports Listed as a source for this family in the legacy taxonomy
- openrouter.ai/docs/guides/overview/auth/management-api-keysprovider-documentation · last read 2026-09-29 · latest outcome read · supports Listed as a source for this family in the legacy taxonomy
Open questions
No open question is recorded for this revision.
Benchmark dossier notes
- Shape
- prefix
sk-or-mgmt-, stated only on the Terraform provider page and its README and by one staff statement. Body length, alphabet and any embedded version or checksum are not documented anywhere found. Three independent first-hand users report that their live management keys startsk-or-v1-like inference keys; if that is right, management keys aresk-or-v1-+ 64 lowercase hex, theopenrouter:api-keycontract already covers them and no separate family is needed. - Basis
- - provider docs (R4, prefix claim): OpenRouterTeam/docs
terraform.mdx, 2026-09-02, "Management API key ... which starts withsk-or-mgmt-..."; the terraform provider README (first seen 2026-07-17) repeats it as a placeholder. - provider staff statement (R3, prefix, as of 2026-08-25): terraform-provider-openrouter PR #253, "Management keys are a distinct credential with their own prefix,sk-or-mgmt-..." (the author's profile names @OpenRouterTeam). - provider docs (T1, for inference keys only): OpenRouter's own secret-scanning page statessk-or-v1-+ 64 lowercase hex and has no management-key row. - contradicting first-hand reports (independent, 2026-04-03, 2026-08-10, 2026-08-24): hydra's key utilities ("OR management keys use sk-or-v1- prefix, NOT sk-or-mgmt-"), a report in the inkwell sandboxes repository ("Both key types have the samesk-or-v1-...prefix. I confirmed this on my own account") and openrouter-keymaster's redaction module. A format change after 2026-08-24 is possible but unproven. - peer rule: osv-scalibrsk-or-v[0-9]+-[A-Za-z0-9_-]{20,}would not matchsk-or-mgmt-. No other peer scanner has ansk-or-mgmtrule; 111 code-search hits are docs, placeholders and prefix checks. - GitGuardian says one detector covers provisioning keys, which conflicts with thesk-or-mgmt-prefix. - Issuance
- free at
/settings/management-keys, shown once, optional expiry fixed at creation; not attempted. The #1012 check: create one key with the shortest expiry and record the exact prefix, total length, body alphabet (lowercase hex only?) and thatGET /api/v1/keyreports it as a management key; then delete it. - Contract in core
- unclaimed per the #726 record (detector-families.md). If the keys are
sk-or-v1-they are redacted under the inference type (the role is not lexically visible); ifsk-or-mgmt-, only in named and Bearer contexts.
In this benchmark
No fixtures in this family yet
Nothing in the corpus targets it, so nothing is measured and no coverage is claimed.
Not measured
Benchmark dossier questions
- Blocked by
- The prefix itself is contested (provider statements say sk-or-mgmt-, three first-hand users say sk-or-v1-) and no body grammar exists; needs one management key measured (free, structure only).
Looks like it, but isn't
- Collisions
- shares the
sk-or-stem with inference keys. A real secret, so it is never a benign control foropenrouter:api-key.
Scanner rules for this family
No peer rule maps to this family
None of the reviewed peer scanners has a rule that can match a credential of this family.
None mapped
No fixtures in this family yet
Nothing in the corpus targets it, so nothing is measured and no coverage is claimed.
Not measured
Sources
Documentation and code
- openrouter.ai/docs/guides/overview/auth/management-api-keys
- github.com/OpenRouterTeam/terraform-provider-openrouter
- github.com/OpenRouterTeam/docs/blob/9e4172882651f7a85099a3054d120e66ef850715/guides/overview/terraform.mdx#L41
- github.com/OpenRouterTeam/terraform-provider-openrouter/blob/7fd0e341dc9c638333952e8e4159c198b7028d91/README.md#L39
- github.com/OpenRouterTeam/terraform-provider-openrouter/pull/253
- github.com/OpenRouterTeam/docs/blob/9e4172882651f7a85099a3054d120e66ef850715/guides/features/guardrails/secret-formats.mdx#L36
- github.com/zaydiscold/hydra/blob/cf1926f166be543f3af93a4d50b2bc548d6b6409/server/services/key-utils.js#L4-L6
- github.com/disler/inkwell-agent-sandboxes-and-software-factory/issues/3
- github.com/kljensen/openrouter-keymaster/blob/d54808de2de0df4fae0367a2680ab71379643642/crates/core/src/redaction.rs#L20-L25
Research log
- redact-secret/redact-secret-benchmarks#220Research issue
- redact-secret/redact-secret#726Research issue
- redact-secret/redact-secret#1012Research issue
- Final evidence, pinned to a commit/redact-secret/redact-secret/blob/378581770a87751d72e27529796c4f790649fd00/docs/audits/evidence/1012/openrouter-management-api-key.md