redact-secret · Report
Legacy API key (bare UUID)
Legacy bare-UUID API key, identical in shape to Pinecone key/project/service-account ids; recognized only beside a same-line Pinecone API-key identifier.
Research record
4 events in the review history: 3 observed, 1 reviewed. Latest: observed on 2026-10-03 by automation, project maintainer. Project-maintained review is not independent validation. The family record at this release.
Format
What it looks like
Shape not recorded.
Format facts
Provider documented ·
mutable-property-source· current · observed 2026-09-24Documentation for the one property varied in legacy twin fixtures (Api-Key header and PINECONE_API_KEY): the provider documents the API key as sent in the Api-Key header and read from PINECONE_API_KEY; it states no key grammar. The context twins keep the UUID and replace that identifier with a Pinecone project/index/database/service-account id name, whose values the Admin API documents as UUIDs
- docs.pinecone.io/reference/api/authenticationprovider-documentation · last read 2026-09-29 · latest outcome read · supports the provider documents the API key as sent in the Api-Key header and read from PINECONE_API_KEY; it states no key grammar. The context twins keep the UUID and replace that identifier with a Pinecone project/index/database/service-account id name, whose values the Admin API documents as UUIDs
Tool corroborated ·
field-value-shape· current · observed 2026-09-24value shape: bare UUID [0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}
- docs.gitguardian.com/secrets-detection/secrets-detection-engine/detectors/specifics/pinecone_api_keyscanner-rule-source · last read 2026-09-24 · latest outcome read · supports value shape: bare UUID [0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}
- betterleaks/betterleaks @ main: cmd/generate/config/rules/pinecone.goscanner-rule-source · last read 2026-09-24 · latest outcome read · supports pinecone-api-key.1, keyword-gated, medium confidence
Provider documented ·
field-supported-context· current · observed 2026-09-24supported context: same-line Pinecone API-key identifier or Api-Key header to a pinecone.io host
- docs.pinecone.io/reference/api/authenticationprovider-documentation · last read 2026-09-29 · latest outcome read · supports Api-Key header and PINECONE_API_KEY env var
- www.pinecone.io/blog/global-api/provider-documentation · last read 2026-09-24 · latest outcome read · supports legacy pinecone.init(api_key, environment) pairing
Unresolved ·
field-issuance-status· current · observed 2026-09-24issuance status: undated switch from UUID to pcsk_; current validity of UUID keys unknown
- docs.pinecone.io/release-notes/2026other · last read 2026-09-24 · latest outcome read · supports issuance status: undated switch from UUID to pcsk_; current validity of UUID keys unknown
Project policy ·
legacy-contract-tier· current · observed 2026-09-24The legacy contract records this grammar as project masking policy (tier T3), not as a provider format.
Source not recorded.
Unresolved ·
dossier-research· current · observed 2026-09-29Legacy dossier research (verdict ready, tier T2) cited 2 sources; the dossier does not attribute sources to individual properties.
- docs.pinecone.io/reference/api/authenticationprovider-documentation · last read 2026-09-29 · latest outcome read · supports Cited by the legacy dossier research for this family
- redact-secret/redact-secret @ 378581770a87751d72e27529796c4f790649fd00: docs/audits/evidence/1012/confirm-only.mdproject-research-note · last read 2026-09-29 · latest outcome read · supports Final research evidence recorded by the legacy dossier
Unresolved ·
taxonomy-sources· current · observed 2026-09-29The legacy taxonomy lists 1 source for this family. The taxonomy records no date; the dossier researchedAt is used as the observed-at date.
- docs.pinecone.io/reference/api/authenticationprovider-documentation · last read 2026-09-29 · latest outcome read · supports Listed as a source for this family in the legacy taxonomy
Open questions
No open question is recorded for this revision.
Benchmark dossier notes
- Shape
- a lowercase
8-4-4-4-12hex UUID, used before thepcsk_form and paired with anenvironment. Only betterleaks, Kingfisher and GitGuardian describe it; none is pinned, and no provider source states it. It is lexically identical to Pinecone key, project and service-account ids. - Basis
- T2, tools only. The authentication page documents the
Api-Keyheader andPINECONE_API_KEYbut not the shape. - Issuance
- not possible to test; nothing indicates the console still issues UUID keys, and whether they still authenticate is unknown.
- Contract in core
- a legacy UUID is claimed only when it is the value assigned to a Pinecone API-key name on the same line (accepted 2026-09-24 decision, linked from detector-families.md); a bare UUID stays unclaimed. Issue #702 raised the question for this family.
In this benchmark
- Fixtures
- 48
- Left readable
- 0
- Redacted too much
- 0
- False alarms
- 0
48 fixtures: 36 must stay quiet, 12 record project policy. See every row
| Evidence level | Fixtures | Left readable | Too much | False alarms |
|---|---|---|---|---|
| T1Provider-documented | 3 | 0 | 0 | 0 |
| T3Project policy | 45 | 0 | 0 | 0 |
Every scanner on the same fixtures
In run order. Counts are what each scanner recorded on this family's fixtures, whichever rules it has; a scanner with no rule for the family has nothing to report on it.
| Scanner | Fixtures | Left readable | Too much | False alarms |
|---|---|---|---|---|
| flare-redactRuntime library · 1.6.1 · Published npm package · secrets-only (pii, generic_assignment disabled) · JavaScript engineNo rule maps to it | 48 | 12 | 0 | 0 |
| gitleaksRepository scanner · 8.30.1 · Directory scan · default rulesNo rule maps to it | 48 | 0 | 0 | 0 |
| redact-secretProduct measured here · 0.1.0-beta.14 · Published npm package · default detectorsNo detector mapped | 48 | 0 | 0 | 0 |
| trufflehogRepository scanner · 3.97.4 · Filesystem scan · verification disabledNo rule maps to it | 48 | 12 | 0 | 0 |
Benchmark dossier questions
- Open caveat
- No provider source states the UUID shape (unpinned tools only) and no new legacy key can be issued; it is claimable only beside a Pinecone API-key name, never as a bare value.
Looks like it, but isn't
- Collisions
- every other UUID in Pinecone output. A UUID under an id-named key (
PINECONE_PROJECT_ID,X-Project-Id,indexId) is not a key.
Scanner rules for this family
No peer rule maps to this family
None of the reviewed peer scanners has a rule that can match a credential of this family.
None mapped
Fixtures in this family
| Fixture | Kind and evidence | redact-secret |
|---|---|---|
pinecone-api-key-legacy-actions-envpinecone · documented-format-literal | Project policyT3 · Project policy | Redacted |
pinecone-api-key-legacy-api-key-headerpinecone · documented-format-literal | Project policyT3 · Project policy | Redacted |
pinecone-api-key-legacy-compose-envpinecone · documented-format-literal | Project policyT3 · Project policy | Redacted |
pinecone-api-key-legacy-dotenvpinecone · documented-format-literal | Project policyT3 · Project policy | Redacted |
pinecone-api-key-legacy-exportpinecone · documented-format-literal | Project policyT3 · Project policy | Redacted |
pinecone-api-key-legacy-langchainpinecone · documented-format-literal | Project policyT3 · Project policy | Redacted |
pinecone-api-key-legacy-legacy-initpinecone · documented-format-literal | Project policyT3 · Project policy | Redacted |
pinecone-api-key-legacy-n8n-credentialpinecone · documented-format-literal | Project policyT3 · Project policy | Redacted |
pinecone-api-key-legacy-shell-keypinecone · documented-format-literal | Project policyT3 · Project policy | Redacted |
pinecone-api-key-legacy-terraform-outputpinecone · documented-format-literal | Project policyT3 · Project policy | Redacted |
pinecone-api-key-legacy-ts-legacy-initpinecone · documented-format-literal | Project policyT3 · Project policy | Redacted |
pinecone-api-key-legacy-yaml-configpinecone · documented-format-literal | Project policyT3 · Project policy | Redacted |
pinecone-api-key-legacy-actions-env-identifier-twinpinecone · missing-context-marker | Must not flagT3 · Project policy · twin | Quiet |
pinecone-api-key-legacy-actions-secret-referencepinecone · templated-reference | Must not flagT3 · Project policy | Quiet |
pinecone-api-key-legacy-admin-key-object-public-idpinecone · public-identifier | Must not flagT1 · Provider-documented | Quiet |
pinecone-api-key-legacy-api-key-header-identifier-twinpinecone · missing-context-marker | Must not flagT3 · Project policy · twin | Quiet |
pinecone-api-key-legacy-base64-environment-encoded-valuepinecone · benign-encoded-value | Must not flagT3 · Project policy | Quiet |
pinecone-api-key-legacy-base64-host-encoded-valuepinecone · benign-encoded-value | Must not flagT3 · Project policy | Quiet |
pinecone-api-key-legacy-compose-env-identifier-twinpinecone · missing-context-marker | Must not flagT3 · Project policy · twin | Quiet |
pinecone-api-key-legacy-database-id-public-idpinecone · public-identifier | Must not flagT3 · Project policy | Quiet |
pinecone-api-key-legacy-dotenv-identifier-twinpinecone · missing-context-marker | Must not flagT3 · Project policy · twin | Quiet |
pinecone-api-key-legacy-empty-assignment-near-misspinecone · format-near-miss | Must not flagT3 · Project policy | Quiet |
pinecone-api-key-legacy-empty-header-near-misspinecone · format-near-miss | Must not flagT3 · Project policy | Quiet |
pinecone-api-key-legacy-empty-string-near-misspinecone · format-near-miss | Must not flagT3 · Project policy | Quiet |
pinecone-api-key-legacy-env-reference-referencepinecone · templated-reference | Must not flagT3 · Project policy | Quiet |
pinecone-api-key-legacy-export-identifier-twinpinecone · missing-context-marker | Must not flagT3 · Project policy · twin | Quiet |
pinecone-api-key-legacy-header-note-prosepinecone · prose-mention | Must not flagT3 · Project policy | Quiet |
pinecone-api-key-legacy-langchain-identifier-twinpinecone · missing-context-marker | Must not flagT3 · Project policy · twin | Quiet |
pinecone-api-key-legacy-legacy-init-identifier-twinpinecone · missing-context-marker | Must not flagT3 · Project policy · twin | Quiet |
pinecone-api-key-legacy-migration-note-prosepinecone · prose-mention | Must not flagT3 · Project policy | Quiet |
pinecone-api-key-legacy-n8n-credential-identifier-twinpinecone · missing-context-marker | Must not flagT3 · Project policy · twin | Quiet |
pinecone-api-key-legacy-none-argument-near-misspinecone · format-near-miss | Must not flagT3 · Project policy | Quiet |
pinecone-api-key-legacy-process-env-referencepinecone · templated-reference | Must not flagT3 · Project policy | Quiet |
pinecone-api-key-legacy-project-id-public-idpinecone · public-identifier | Must not flagT1 · Provider-documented | Quiet |
pinecone-api-key-legacy-rotation-note-prosepinecone · prose-mention | Must not flagT3 · Project policy | Quiet |
pinecone-api-key-legacy-sdk-environ-referencepinecone · templated-reference | Must not flagT3 · Project policy | Quiet |
pinecone-api-key-legacy-sdk-repr-mask-placeholderpinecone · documentation-placeholder | Must not flagT3 · Project policy | Quiet |
pinecone-api-key-legacy-service-account-id-public-idpinecone · public-identifier | Must not flagT1 · Provider-documented | Quiet |
pinecone-api-key-legacy-sha256-index-name-encoded-valuepinecone · benign-encoded-value | Must not flagT3 · Project policy | Quiet |
pinecone-api-key-legacy-shell-key-identifier-twinpinecone · missing-context-marker | Must not flagT3 · Project policy · twin | Quiet |
pinecone-api-key-legacy-terraform-output-identifier-twinpinecone · missing-context-marker | Must not flagT3 · Project policy · twin | Quiet |
pinecone-api-key-legacy-ts-legacy-init-identifier-twinpinecone · missing-context-marker | Must not flagT3 · Project policy · twin | Quiet |
pinecone-api-key-legacy-url-encoded-host-encoded-valuepinecone · benign-encoded-value | Must not flagT3 · Project policy | Quiet |
pinecone-api-key-legacy-uuid-note-prosepinecone · prose-mention | Must not flagT3 · Project policy | Quiet |
pinecone-api-key-legacy-x-uuid-placeholderpinecone · documentation-placeholder | Must not flagT3 · Project policy | Quiet |
pinecone-api-key-legacy-yaml-config-identifier-twinpinecone · missing-context-marker | Must not flagT3 · Project policy · twin | Quiet |
pinecone-api-key-legacy-your-api-key-placeholderpinecone · documentation-placeholder | Must not flagT3 · Project policy | Quiet |
pinecone-api-key-legacy-zero-uuid-placeholderpinecone · documentation-placeholder | Must not flagT3 · Project policy | Quiet |
Sources
Documentation and code
- docs.pinecone.io/reference/api/authentication
Research log
- redact-secret/redact-secret-benchmarks#228Research issue
- redact-secret/redact-secret-benchmarks#253Research issue
- redact-secret/redact-secret#726Research issue
- redact-secret/redact-secret#702Research issue
- redact-secret/redact-secret#1012Research issue
- Final evidence, pinned to a commit/redact-secret/redact-secret/blob/378581770a87751d72e27529796c4f790649fd00/docs/audits/evidence/1012/confirm-only.md