Skip to content
Benchmarks

redact-secret · Report

API key

pplx--prefixed API key; the 48-character alphanumeric body is tool-corroborated, not provider-stated.

  • Perplexity
  • Detectors: perplexity-api-key
  • Run 2026-10-07
  • Mode published · redact-secret 0.1.0-beta.14
  • Dossier verdictReady
  • Dossier evidence levelT2 · Tool-corroborated
  • Dossier researched2026-09-24
Registry detector perplexity-api-key since redact-secret#730 (registry pinned at f2082ab); graduated from a Beta.8 arrival family (#212, research #226), contract in benchmarks/lib/beta8/212.ts.

Research record

From credential-evidence snapshot-2026.10.06.4 · records at 77ce761 · schema 1.8.0. It describes the research on the format, not what any scanner or the product does, and not a support status.
  • Review stateDraft, not reviewed
  • Format revision1 · current
  • ResearchResearched
  • Researched2026-09-24

4 events in the review history: 3 observed, 1 reviewed. Latest: observed on 2026-10-03 by automation, project maintainer. Project-maintained review is not independent validation. The family record at this release.

Format

Provider format research from credential-evidence snapshot-2026.10.06.4 · records at 77ce761 · schema 1.8.0.

What it looks like

Descriptive pattern
^pplx-[A-Za-z0-9]{48}$

Parts are shown as recorded. Evidence classes belong to the facts below; no class is assigned to a part.

Format facts

  • Unresolved · tool-corroboration · current · observed 2026-09-24

    Pinned scanner rules are consistent with the contract grammar (1 artifact: gitleaks 8.30.1).

  • Provider documented · field-prefix · current · observed 2026-09-24

    prefix: pplx- (lowercase, one dash)

  • Tool corroborated · field-body-length · current · observed 2026-09-24

    body length: exactly 48 characters after the prefix (53 total) (Tool-corroborated, not provider-stated. flare-redact perplexity_key uses {40,60}; the 47/49 twins record the peer difference, not a provider exclusion.)

  • Unresolved · field-body-alphabet · current · observed 2026-09-24

    body alphabet: [A-Za-z0-9] (No provider statement; the official pplx CLI accepts any printable ASCII.)

  • Unresolved · field-analytics-key-and-mcp-oauth-token-shapes · current · observed 2026-09-24

    analytics-key and MCP OAuth token shapes: undocumented; may or may not share pplx-

  • Unresolved · field-checksum-embedded-project-id-historical-versions · current · observed 2026-09-24

    checksum, embedded project id, historical versions: none documented; pre-2025-04 and pre-2026-04 key shapes unknown

  • Unresolved · dossier-research · current · observed 2026-09-24

    Legacy dossier research (verdict ready, tier T2) cited 2 sources; the dossier does not attribute sources to individual properties.

  • Unresolved · taxonomy-sources · current · observed 2026-09-24

    The legacy taxonomy lists 1 source for this family. The taxonomy records no date; the dossier researchedAt is used as the observed-at date.

Open questions

No open question is recorded for this revision.

Benchmark dossier notes

From the provider dossier, as written. The evidence level above says how well the format is backed; a fact the dossier does not record is not shown.
Shape
prefix pplx- followed by 48 letters and digits (53 in total). The provider's rotation docs show a pplx- value but with an obviously shortened body, and never state a length or alphabet. Gitleaks (2025-04) and osv-scalibr say exactly 48 alphanumeric; flare-redact allows 40 to 60; one redaction rule allows 10 or more with _ and -. The official CLI validates only that a key is non-empty printable ASCII.
Basis
T2. The prefix is provider documentation; the body is scanner rules. No provider staff statement on length was found.
Issuance
not attempted; a project may need billing set up first. The console checklist is in benchmarks#226.
Contract in core
detector-families.md (frozen in the #726 record, implemented under #730).

In this benchmark

Fixture rows on the current run. Counts are for redact-secret in published · redact-secret 0.1.0-beta.14 mode.
Fixtures
41
Left readable
0
Redacted too much
0
False alarms
0

41 fixtures: 18 expect a redaction, 23 must stay quiet. See every row

redact-secret fixture counts by evidence level
Evidence levelFixturesLeft readableToo muchFalse alarms
T1Provider-documented2000
T2Tool-corroborated29000
T3Project policy10000

Every scanner on the same fixtures

In run order. Counts are what each scanner recorded on this family's fixtures, whichever rules it has; a scanner with no rule for the family has nothing to report on it.

Counts per scanner on this family's fixtures
ScannerFixturesLeft readableToo muchFalse alarms
flare-redactRuntime library · 1.6.1 · Published npm package · secrets-only (pii, generic_assignment disabled) · JavaScript engine1 rule targets it41032
gitleaksRepository scanner · 8.30.1 · Directory scan · default rules1 rule targets it41001
redact-secretProduct measured here · 0.1.0-beta.14 · Published npm package · default detectors1 detector mapped41000
trufflehogRepository scanner · 3.97.4 · Filesystem scan · verification disabledNo rule maps to it411800

Benchmark dossier questions

Things the sources do not settle. They are listed so nobody reads them as settled.
Open caveat
The provider shows the pplx- prefix but no length or alphabet; the 48-character alphanumeric body is scanner-only and two of the scanners likely share lineage (checklist in benchmarks#226).

Looks like it, but isn't

Values the dossier records as resembling this credential without being one.
Collisions
model ids (pplx-7b-online, pplx-embed-v1-4b), package and command names (pplx-cli, pplx-api), hostnames such as pplx-res.cloudinary.com and *.pplx.app, and an OpenRouter key stored under PERPLEXITY_API_KEY. GitGuardian marks the type "not prefixed", which contradicts the other sources.

Scanner rules for this family

Mapped by hand (reviewed 2026-09-30) from each scanner's pinned rule file, never from what a scanner found on the fixtures.
Peer scanner rules that target this family
ScannerRuleWhat the rule matches
flare-redact · rules 1.6.1perplexity_keypplx- + 40-60 characters
gitleaks · rules 8.30.1perplexity-api-keypplx- + 48 alphanumerics

No rule maps to this family in openredaction, trufflehog.

41 of 41 rows

Fixtures in this family

41 rows, redact-secret's outcome on each. Rows that need a look come first (0), then the rest in corpus order. Choose "Every scanner" to see each scanner's outcome for the same rows.
Fixtures in API key
FixtureKind and evidenceredact-secret
perplexity-api-key-actions-envperplexity · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
perplexity-api-key-bearer-curlperplexity · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
perplexity-api-key-chat-messageperplexity · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
perplexity-api-key-cli-credentialsperplexity · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
perplexity-api-key-compose-envperplexity · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
perplexity-api-key-curl-chatperplexity · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
perplexity-api-key-debug-logperplexity · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
perplexity-api-key-dotenvperplexity · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
perplexity-api-key-key-shape-bareperplexity · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
perplexity-api-key-key-shape-quotedperplexity · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
perplexity-api-key-key-shape-unicode-crlfperplexity · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
perplexity-api-key-long-body-twinperplexity · wrong-lengthMust not flagT3 · Project policy · twinQuiet
perplexity-api-key-mcp-configperplexity · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
perplexity-api-key-pplx-exportperplexity · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
perplexity-api-key-python-clientperplexity · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
perplexity-api-key-revoke-payloadperplexity · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
perplexity-api-key-secret-printperplexity · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
perplexity-api-key-short-body-twinperplexity · wrong-lengthMust not flagT2 · Tool-corroborated · twinQuiet
perplexity-api-key-short-body-twin-wrong-lengthperplexity · wrong-lengthMust not flagT2 · Tool-corroborated · twinQuiet
perplexity-api-key-twin-base-dotenvperplexity · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
perplexity-api-key-twin-base-pythonperplexity · documented-format-literalMust redactT2 · Tool-corroboratedRedacted
perplexity-api-key-base-url-and-name-public-idperplexity · public-identifierMust not flagT3 · Project policyQuiet
perplexity-api-key-base64-model-encoded-valueperplexity · benign-encoded-valueMust not flagT1 · Provider-documentedQuiet
perplexity-api-key-docs-placeholder-placeholderperplexity · documentation-placeholderMust not flagT3 · Project policyQuiet
perplexity-api-key-embedding-model-public-idperplexity · public-identifierMust not flagT1 · Provider-documentedQuiet
perplexity-api-key-env-reference-referenceperplexity · templated-referenceMust not flagT3 · Project policyQuiet
perplexity-api-key-inner-dash-twinperplexity · wrong-alphabetMust not flagT2 · Tool-corroborated · twinQuiet
perplexity-api-key-key-guidance-proseperplexity · prose-mentionMust not flagT3 · Project policyQuiet
perplexity-api-key-label-proseperplexity · benign-lookalikeMust not flagT3 · Project policyQuiet
perplexity-api-key-maskperplexity · benign-lookalikeMust not flagT3 · Project policyQuiet
perplexity-api-key-masked-display-placeholderperplexity · documentation-placeholderMust not flagT3 · Project policyQuiet
perplexity-api-key-missing-dash-twinperplexity · boundary-violationMust not flagT2 · Tool-corroborated · twinQuiet
perplexity-api-key-package-name-near-missperplexity · format-near-missMust not flagT2 · Tool-corroboratedQuiet
perplexity-api-key-prefix-letter-twinperplexity · prefix-near-missMust not flagT2 · Tool-corroborated · twinQuiet
perplexity-api-key-prefix-onlyperplexity · benign-lookalikeMust not flagT2 · Tool-corroboratedQuiet
perplexity-api-key-prefix-only-near-missperplexity · format-near-missMust not flagT2 · Tool-corroboratedQuiet
perplexity-api-key-referenceperplexity · benign-lookalikeMust not flagT3 · Project policyQuiet
perplexity-api-key-sdk-environ-referenceperplexity · templated-referenceMust not flagT3 · Project policyQuiet
perplexity-api-key-short-bodyperplexity · benign-lookalikeMust not flagT2 · Tool-corroboratedQuiet
perplexity-api-key-underscore-delimiter-twinperplexity · boundary-violationMust not flagT2 · Tool-corroborated · twinQuiet
perplexity-api-key-uppercase-prefix-twinperplexity · prefix-near-missMust not flagT2 · Tool-corroborated · twinQuiet

Sources

Researched 2026-09-24.

Documentation and code

Research log