Skip to content
Benchmarks

redact-secret · Report

Legacy API key (bare UUID)

Legacy bare-UUID API key, identical in shape to Pinecone key/project/service-account ids; recognized only beside a same-line Pinecone API-key identifier.

  • Pinecone
  • Detectors: none mapped
  • Run 2026-10-07
  • Mode published · redact-secret 0.1.0-beta.14
  • Dossier verdictReady
  • Dossier evidence levelT2 · Tool-corroborated
  • Dossier researched2026-09-29
Beta.8 context-gated arrival family pinecone-api-key-legacy (#212, research #228); the UUID shape is corroborated by unpinned tools only. Owned by the product pinecone-api-key detector since product main 2420e80 (redact-secret#766 and its ADR 2026-09-24-claim-a-legacy-pinecone-uuid-key-only-under-its-api-key-name): the UUID is redacted at high confidence under a Pinecone API-key name (PINECONE_API_KEY, pinecone_api_key, PINECONE_KEY, or api_key/apiKey/Api-Key on a line naming pinecone), and a bare UUID stays unclaimed. The detector reports it with the same pinecone_api_key finding type as pcsk_, so detectors stays empty: mapping the family to pinecone-api-key would merge it into that contract (#253).

Research record

From credential-evidence snapshot-2026.10.06.4 · records at 77ce761 · schema 1.8.0. It describes the research on the format, not what any scanner or the product does, and not a support status.
  • Review stateDraft, not reviewed
  • Format revision1 · current
  • ResearchResearched
  • Researched2026-09-29

4 events in the review history: 3 observed, 1 reviewed. Latest: observed on 2026-10-03 by automation, project maintainer. Project-maintained review is not independent validation. The family record at this release.

Format

Provider format research from credential-evidence snapshot-2026.10.06.4 · records at 77ce761 · schema 1.8.0.

What it looks like

Shape not recorded.

Format facts

  • Provider documented · mutable-property-source · current · observed 2026-09-24

    Documentation for the one property varied in legacy twin fixtures (Api-Key header and PINECONE_API_KEY): the provider documents the API key as sent in the Api-Key header and read from PINECONE_API_KEY; it states no key grammar. The context twins keep the UUID and replace that identifier with a Pinecone project/index/database/service-account id name, whose values the Admin API documents as UUIDs

    • docs.pinecone.io/reference/api/authenticationprovider-documentation · last read 2026-09-29 · latest outcome read · supports the provider documents the API key as sent in the Api-Key header and read from PINECONE_API_KEY; it states no key grammar. The context twins keep the UUID and replace that identifier with a Pinecone project/index/database/service-account id name, whose values the Admin API documents as UUIDs
  • Tool corroborated · field-value-shape · current · observed 2026-09-24

    value shape: bare UUID [0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}

  • Provider documented · field-supported-context · current · observed 2026-09-24

    supported context: same-line Pinecone API-key identifier or Api-Key header to a pinecone.io host

  • Unresolved · field-issuance-status · current · observed 2026-09-24

    issuance status: undated switch from UUID to pcsk_; current validity of UUID keys unknown

    • docs.pinecone.io/release-notes/2026other · last read 2026-09-24 · latest outcome read · supports issuance status: undated switch from UUID to pcsk_; current validity of UUID keys unknown
  • Project policy · legacy-contract-tier · current · observed 2026-09-24

    The legacy contract records this grammar as project masking policy (tier T3), not as a provider format.

    Source not recorded.

  • Unresolved · dossier-research · current · observed 2026-09-29

    Legacy dossier research (verdict ready, tier T2) cited 2 sources; the dossier does not attribute sources to individual properties.

  • Unresolved · taxonomy-sources · current · observed 2026-09-29

    The legacy taxonomy lists 1 source for this family. The taxonomy records no date; the dossier researchedAt is used as the observed-at date.

Open questions

No open question is recorded for this revision.

Benchmark dossier notes

From the provider dossier, as written. The evidence level above says how well the format is backed; a fact the dossier does not record is not shown.
Shape
a lowercase 8-4-4-4-12 hex UUID, used before the pcsk_ form and paired with an environment. Only betterleaks, Kingfisher and GitGuardian describe it; none is pinned, and no provider source states it. It is lexically identical to Pinecone key, project and service-account ids.
Basis
T2, tools only. The authentication page documents the Api-Key header and PINECONE_API_KEY but not the shape.
Issuance
not possible to test; nothing indicates the console still issues UUID keys, and whether they still authenticate is unknown.
Contract in core
a legacy UUID is claimed only when it is the value assigned to a Pinecone API-key name on the same line (accepted 2026-09-24 decision, linked from detector-families.md); a bare UUID stays unclaimed. Issue #702 raised the question for this family.

In this benchmark

Fixture rows on the current run. Counts are for redact-secret in published · redact-secret 0.1.0-beta.14 mode.
Fixtures
48
Left readable
0
Redacted too much
0
False alarms
0

48 fixtures: 36 must stay quiet, 12 record project policy. See every row

redact-secret fixture counts by evidence level
Evidence levelFixturesLeft readableToo muchFalse alarms
T1Provider-documented3000
T3Project policy45000

Every scanner on the same fixtures

In run order. Counts are what each scanner recorded on this family's fixtures, whichever rules it has; a scanner with no rule for the family has nothing to report on it.

Counts per scanner on this family's fixtures
ScannerFixturesLeft readableToo muchFalse alarms
flare-redactRuntime library · 1.6.1 · Published npm package · secrets-only (pii, generic_assignment disabled) · JavaScript engineNo rule maps to it481200
gitleaksRepository scanner · 8.30.1 · Directory scan · default rulesNo rule maps to it48000
redact-secretProduct measured here · 0.1.0-beta.14 · Published npm package · default detectorsNo detector mapped48000
trufflehogRepository scanner · 3.97.4 · Filesystem scan · verification disabledNo rule maps to it481200

Benchmark dossier questions

Things the sources do not settle. They are listed so nobody reads them as settled.
Open caveat
No provider source states the UUID shape (unpinned tools only) and no new legacy key can be issued; it is claimable only beside a Pinecone API-key name, never as a bare value.

Looks like it, but isn't

Values the dossier records as resembling this credential without being one.
Collisions
every other UUID in Pinecone output. A UUID under an id-named key (PINECONE_PROJECT_ID, X-Project-Id, indexId) is not a key.

Scanner rules for this family

Mapped by hand (reviewed 2026-09-30) from each scanner's pinned rule file, never from what a scanner found on the fixtures.

No peer rule maps to this family

None of the reviewed peer scanners has a rule that can match a credential of this family.

None mapped

48 of 48 rows

Fixtures in this family

48 rows, redact-secret's outcome on each. Rows that need a look come first (0), then the rest in corpus order. Choose "Every scanner" to see each scanner's outcome for the same rows.
Fixtures in Legacy API key (bare UUID)
FixtureKind and evidenceredact-secret
pinecone-api-key-legacy-actions-envpinecone · documented-format-literalProject policyT3 · Project policyRedacted
pinecone-api-key-legacy-api-key-headerpinecone · documented-format-literalProject policyT3 · Project policyRedacted
pinecone-api-key-legacy-compose-envpinecone · documented-format-literalProject policyT3 · Project policyRedacted
pinecone-api-key-legacy-dotenvpinecone · documented-format-literalProject policyT3 · Project policyRedacted
pinecone-api-key-legacy-exportpinecone · documented-format-literalProject policyT3 · Project policyRedacted
pinecone-api-key-legacy-langchainpinecone · documented-format-literalProject policyT3 · Project policyRedacted
pinecone-api-key-legacy-legacy-initpinecone · documented-format-literalProject policyT3 · Project policyRedacted
pinecone-api-key-legacy-n8n-credentialpinecone · documented-format-literalProject policyT3 · Project policyRedacted
pinecone-api-key-legacy-shell-keypinecone · documented-format-literalProject policyT3 · Project policyRedacted
pinecone-api-key-legacy-terraform-outputpinecone · documented-format-literalProject policyT3 · Project policyRedacted
pinecone-api-key-legacy-ts-legacy-initpinecone · documented-format-literalProject policyT3 · Project policyRedacted
pinecone-api-key-legacy-yaml-configpinecone · documented-format-literalProject policyT3 · Project policyRedacted
pinecone-api-key-legacy-actions-env-identifier-twinpinecone · missing-context-markerMust not flagT3 · Project policy · twinQuiet
pinecone-api-key-legacy-actions-secret-referencepinecone · templated-referenceMust not flagT3 · Project policyQuiet
pinecone-api-key-legacy-admin-key-object-public-idpinecone · public-identifierMust not flagT1 · Provider-documentedQuiet
pinecone-api-key-legacy-api-key-header-identifier-twinpinecone · missing-context-markerMust not flagT3 · Project policy · twinQuiet
pinecone-api-key-legacy-base64-environment-encoded-valuepinecone · benign-encoded-valueMust not flagT3 · Project policyQuiet
pinecone-api-key-legacy-base64-host-encoded-valuepinecone · benign-encoded-valueMust not flagT3 · Project policyQuiet
pinecone-api-key-legacy-compose-env-identifier-twinpinecone · missing-context-markerMust not flagT3 · Project policy · twinQuiet
pinecone-api-key-legacy-database-id-public-idpinecone · public-identifierMust not flagT3 · Project policyQuiet
pinecone-api-key-legacy-dotenv-identifier-twinpinecone · missing-context-markerMust not flagT3 · Project policy · twinQuiet
pinecone-api-key-legacy-empty-assignment-near-misspinecone · format-near-missMust not flagT3 · Project policyQuiet
pinecone-api-key-legacy-empty-header-near-misspinecone · format-near-missMust not flagT3 · Project policyQuiet
pinecone-api-key-legacy-empty-string-near-misspinecone · format-near-missMust not flagT3 · Project policyQuiet
pinecone-api-key-legacy-env-reference-referencepinecone · templated-referenceMust not flagT3 · Project policyQuiet
pinecone-api-key-legacy-export-identifier-twinpinecone · missing-context-markerMust not flagT3 · Project policy · twinQuiet
pinecone-api-key-legacy-header-note-prosepinecone · prose-mentionMust not flagT3 · Project policyQuiet
pinecone-api-key-legacy-langchain-identifier-twinpinecone · missing-context-markerMust not flagT3 · Project policy · twinQuiet
pinecone-api-key-legacy-legacy-init-identifier-twinpinecone · missing-context-markerMust not flagT3 · Project policy · twinQuiet
pinecone-api-key-legacy-migration-note-prosepinecone · prose-mentionMust not flagT3 · Project policyQuiet
pinecone-api-key-legacy-n8n-credential-identifier-twinpinecone · missing-context-markerMust not flagT3 · Project policy · twinQuiet
pinecone-api-key-legacy-none-argument-near-misspinecone · format-near-missMust not flagT3 · Project policyQuiet
pinecone-api-key-legacy-process-env-referencepinecone · templated-referenceMust not flagT3 · Project policyQuiet
pinecone-api-key-legacy-project-id-public-idpinecone · public-identifierMust not flagT1 · Provider-documentedQuiet
pinecone-api-key-legacy-rotation-note-prosepinecone · prose-mentionMust not flagT3 · Project policyQuiet
pinecone-api-key-legacy-sdk-environ-referencepinecone · templated-referenceMust not flagT3 · Project policyQuiet
pinecone-api-key-legacy-sdk-repr-mask-placeholderpinecone · documentation-placeholderMust not flagT3 · Project policyQuiet
pinecone-api-key-legacy-service-account-id-public-idpinecone · public-identifierMust not flagT1 · Provider-documentedQuiet
pinecone-api-key-legacy-sha256-index-name-encoded-valuepinecone · benign-encoded-valueMust not flagT3 · Project policyQuiet
pinecone-api-key-legacy-shell-key-identifier-twinpinecone · missing-context-markerMust not flagT3 · Project policy · twinQuiet
pinecone-api-key-legacy-terraform-output-identifier-twinpinecone · missing-context-markerMust not flagT3 · Project policy · twinQuiet
pinecone-api-key-legacy-ts-legacy-init-identifier-twinpinecone · missing-context-markerMust not flagT3 · Project policy · twinQuiet
pinecone-api-key-legacy-url-encoded-host-encoded-valuepinecone · benign-encoded-valueMust not flagT3 · Project policyQuiet
pinecone-api-key-legacy-uuid-note-prosepinecone · prose-mentionMust not flagT3 · Project policyQuiet
pinecone-api-key-legacy-x-uuid-placeholderpinecone · documentation-placeholderMust not flagT3 · Project policyQuiet
pinecone-api-key-legacy-yaml-config-identifier-twinpinecone · missing-context-markerMust not flagT3 · Project policy · twinQuiet
pinecone-api-key-legacy-your-api-key-placeholderpinecone · documentation-placeholderMust not flagT3 · Project policyQuiet
pinecone-api-key-legacy-zero-uuid-placeholderpinecone · documentation-placeholderMust not flagT3 · Project policyQuiet

Sources

Researched 2026-09-29.

Documentation and code

Research log

Other Pinecone families