redact-secret · Report
Organization access token (polar_oat_)
polar_oat_ + exactly 43 [A-Za-z0-9] (37 random + a 6-character base62 CRC32); the checksum corroborates only and never rejects (policy).
Research record
Format revisions
- Revision 1
polar:organization-access-token@1current · draft, not reviewed · superseded by @2 · the family's current revision - Revision 2
polar:organization-access-token@2proposed · draft, not reviewed · supersedes @1
8 events in the review history: 2 authored, 5 observed, 1 reviewed. Latest: authored on 2026-10-05 by automation, project maintainer. Project-maintained review is not independent validation. The family record at this release.
Format
What it looks like
- Descriptive pattern
^polar_oat_[A-Za-z0-9]{43}$
Parts are shown as recorded. Evidence classes belong to the facts below; no class is assigned to a part.
Format facts
Provider documented ·
provider-source· current · observed 2026-09-29polarsource/polar server/polar/kit/crypto.py (6a4f2f6; current since 80fae7f, 2025-01-02): 37 characters of ascii_letters + digits, then the CRC32 of those 37 bytes in base62 (0-9A-Za-z digit order) zero-padded to 6; organization_access_token/service.py (polar_oat_, added 2025-02-05 in 4639cb7, after the checksum era began); re-checked 2026-09-29: polar_oat_ + exactly 43 [A-Za-z0-9] (37 random + 6 checksum), 53 in all; one era
- polarsource/polar @ 6a4f2f6d6083ef503cd23cb7f432ab2c60515973: server/polar/kit/crypto.pyprovider-documentation · last read 2026-10-03 · latest outcome unchanged · supports polar_oat_ + exactly 43 [A-Za-z0-9] (37 random + 6 checksum), 53 in all; one era · #L11-L32
Provider documented ·
field-prefix· current · observed 2026-09-29prefix: polar_oat_
- polarsource/polar @ 6a4f2f6d6083ef503cd23cb7f432ab2c60515973: server/polar/organization_access_token/service.pyprovider-sdk-source · last read 2026-10-03 · latest outcome unchanged · supports prefix: polar_oat_ · #L42
Provider documented ·
field-alphabet· current · observed 2026-09-29alphabet: [A-Za-z0-9] (ascii_letters + digits, and a base62 checksum)
- github.com/polarsource/polar/commit/4639cb7efdprovider-sdk-source · last read 2026-10-03 · latest outcome unchanged · supports added 2025-02-05, after the 2025-01-02 checksum era began
- polarsource/polar @ 6a4f2f6d6083ef503cd23cb7f432ab2c60515973: server/polar/kit/crypto.pyprovider-documentation · last read 2026-10-03 · latest outcome unchanged · supports alphabet: [A-Za-z0-9] (ascii_letters + digits, and a base62 checksum) · #L11-L32
- github.com/redact-secret/redact-secret/issues/860issue-or-discussion · last read 2026-09-29 · latest outcome read · supports R9: provider code dated by its history · #issuecomment-5880547337
Provider documented ·
field-body-length· current · observed 2026-09-29body-length: exactly 43 characters after the prefix
- polarsource/polar @ 6a4f2f6d6083ef503cd23cb7f432ab2c60515973: server/polar/kit/crypto.pyprovider-documentation · last read 2026-10-03 · latest outcome unchanged · supports era 2: 37 + 6; era 1: token_urlsafe() of 32 bytes, 43 unpadded · #L11-L32
Unresolved ·
field-boundary· current · observed 2026-09-29boundary: a token glued to an identifier on either side ([A-Za-z0-9_-]) is not claimed (Handoff boundary decision, not a provider statement.)
- redact-secret/redact-secret @ 4f220ea000b58fa2e0e431ad88dea4eccb393fb0: docs/audits/evidence/1014/polar.mdprovider-documentation · last read 2026-09-29 · latest outcome read · supports implementation notes
Provider documented ·
field-transport· current · observed 2026-09-29transport: POLAR_ACCESS_TOKEN sent as Authorization: Bearer; Polar(access_token=...) and new Polar({ accessToken })
- redact-secret/redact-secret @ 4f220ea000b58fa2e0e431ad88dea4eccb393fb0: docs/audits/evidence/1014/polar.mdprovider-documentation · last read 2026-09-29 · latest outcome read · supports role and blast radius; test axes
Provider documented ·
field-webhook-secret· current · observed 2026-09-29webhook-secret: Polar webhook secrets are whsec_ + 43 from the same generator; stripe-token already reports whsec_ as a Stripe webhook signing secret (Not this family: Polar cannot claim a prefix Stripe owns (misattributed, still redacted). A whsec_ value is authored neither as a positive nor as a control.)
- polarsource/polar @ 6a4f2f6d6083ef503cd23cb7f432ab2c60515973: server/polar/kit/crypto.pyprovider-documentation · last read 2026-10-03 · latest outcome unchanged · supports webhook-secret: Polar webhook secrets are whsec_ + 43 from the same generator; stripe-token already reports whsec_ as a Stripe webhook signing secret · #L11-L32
- redact-secret/redact-secret @ 4f220ea000b58fa2e0e431ad88dea4eccb393fb0: docs/audits/evidence/1014/polar.mdprovider-documentation · last read 2026-09-29 · latest outcome read · supports excluded shapes
Provider documented ·
field-public-and-short-lived-siblings· current · observed 2026-09-29public-and-short-lived-siblings: polar_ci_ is a public OAuth client id (Q5); polar_c_/polar_cl_ checkout client secrets are handed to the browser; session, authorization-code and verification tokens are short-lived (polar_ci_ and polar_c_ values are benign controls; the short-lived credential prefixes are authored neither way (a later extension may claim them).)
- polarsource/polar @ 6a4f2f6d6083ef503cd23cb7f432ab2c60515973: server/polar/oauth2/constants.pyprovider-sdk-source · last read 2026-10-03 · latest outcome unchanged · supports public-and-short-lived-siblings: polar_ci_ is a public OAuth client id (Q5); polar_c_/polar_cl_ checkout client secrets are handed to the browser; session, authorization-code and verification tokens are short-lived · #L5-L16
- redact-secret/redact-secret @ 4f220ea000b58fa2e0e431ad88dea4eccb393fb0: docs/audits/evidence/1014/README.mdprovider-documentation · last read 2026-09-29 · latest outcome read · supports Q5 · #ruling-questions-for-the-maintainer
- redact-secret/redact-secret @ 4f220ea000b58fa2e0e431ad88dea4eccb393fb0: docs/audits/evidence/1014/polar.mdprovider-documentation · last read 2026-09-29 · latest outcome read · supports excluded shapes
Tool corroborated ·
field-peer-lag· current · observed 2026-09-29peer-lag: no Polar rule in trufflehog 3.97.4 or gitleaks 8.30.1: both lag on every positive. betterleaks (unpinned, not measured here) uses polar_(oat|pat|at)_[A-Za-z0-9_-]{20,100}, which is wider on length and misses polar_rt_, polar_cs_ and polar_crt_
- gitleaks/gitleaks @ v8.30.1: config/gitleaks.tomlscanner-rule-source · last read 2026-10-04 · latest outcome read · supports no polar rule
- redact-secret/redact-secret @ 4f220ea000b58fa2e0e431ad88dea4eccb393fb0: docs/audits/evidence/1014/polar.mdprovider-documentation · last read 2026-09-29 · latest outcome read · supports tier rationale: betterleaks is looser and not used
- trufflesecurity/trufflehog @ v3.97.4: pkg/detectorsscanner-rule-source · last read 2026-09-29 · latest outcome read · supports no polar detector directory at the pinned version
Provider documented ·
field-checksum· current · observed 2026-09-29checksum: the last 6 body bytes are the CRC32 of the first 37 in base62 (0-9A-Za-z digit order), zero-padded
- polarsource/polar @ 6a4f2f6d6083ef503cd23cb7f432ab2c60515973: server/polar/kit/crypto.pyprovider-documentation · last read 2026-10-03 · latest outcome unchanged · supports checksum: the last 6 body bytes are the CRC32 of the first 37 in base62 (0-9A-Za-z digit order), zero-padded · #L11-L32
Unresolved ·
field-policy-checksum· current · observed 2026-09-29policy-checksum: POLICY, not T1: the checksum is corroboration only and never rejects a shape-valid match (Positives carry both a matching and a mismatching checksum; no twin or control asserts silence on a checksum failure.)
- redact-secret/redact-secret @ 4f220ea000b58fa2e0e431ad88dea4eccb393fb0: docs/audits/evidence/1014/README.mdprovider-documentation · last read 2026-09-29 · latest outcome read · supports Q1: checksum post-checks, open · #ruling-questions-for-the-maintainer
- redact-secret/redact-secret @ 4f220ea000b58fa2e0e431ad88dea4eccb393fb0: docs/audits/evidence/1014/polar.mdprovider-documentation · last read 2026-09-29 · latest outcome read · supports overlap and output policy: without Q1 the lexical grammar alone is the contract
Unresolved ·
listed-references· current · observed 2026-09-29The legacy contract lists 15 references without stating which property each supports.
- github.com/polarsource/polar/commit/4639cb7efdprovider-sdk-source · last read 2026-10-03 · latest outcome unchanged · supports Listed as a reference by the legacy contract
- github.com/polarsource/polar/commit/80fae7fc98provider-sdk-source · last read 2026-10-03 · latest outcome unchanged · supports Listed as a reference by the legacy contract
- polarsource/polar @ 6a4f2f6d6083ef503cd23cb7f432ab2c60515973: server/polar/kit/crypto.pyprovider-documentation · last read 2026-10-03 · latest outcome unchanged · supports Listed as a reference by the legacy contract · #L11-L32
- polarsource/polar @ 6a4f2f6d6083ef503cd23cb7f432ab2c60515973: server/polar/personal_access_token/service.pyprovider-sdk-source · last read 2026-10-03 · latest outcome unchanged · supports Listed as a reference by the legacy contract
- polarsource/polar @ 6a4f2f6d6083ef503cd23cb7f432ab2c60515973: server/polar/organization_access_token/service.pyprovider-sdk-source · last read 2026-10-03 · latest outcome unchanged · supports Listed as a reference by the legacy contract · #L42
- polarsource/polar @ 6a4f2f6d6083ef503cd23cb7f432ab2c60515973: server/polar/oauth2/constants.pyprovider-sdk-source · last read 2026-10-03 · latest outcome unchanged · supports Listed as a reference by the legacy contract · #L5-L16
- redact-secret/redact-secret @ 4f220ea000b58fa2e0e431ad88dea4eccb393fb0: docs/audits/evidence/1014/README.mdprovider-documentation · last read 2026-09-29 · latest outcome read · supports Listed as a reference by the legacy contract · #ruling-questions-for-the-maintainer
- redact-secret/redact-secret @ 4f220ea000b58fa2e0e431ad88dea4eccb393fb0: docs/audits/evidence/1014/README.mdprovider-documentation · last read 2026-09-29 · latest outcome read · supports Listed as a reference by the legacy contract
- github.com/redact-secret/redact-secret/issues/1014issue-or-discussion · last read 2026-09-29 · latest outcome read · supports Listed as a reference by the legacy contract · #issuecomment-5900447820
- github.com/redact-secret/redact-secret/issues/1014issue-or-discussion · last read 2026-09-29 · latest outcome read · supports Listed as a reference by the legacy contract
- redact-secret/redact-secret @ 4f220ea000b58fa2e0e431ad88dea4eccb393fb0: docs/audits/evidence/1014/polar.mdprovider-documentation · last read 2026-09-29 · latest outcome read · supports Listed as a reference by the legacy contract
- github.com/redact-secret/redact-secret/issues/860issue-or-discussion · last read 2026-09-29 · latest outcome read · supports Listed as a reference by the legacy contract · #issuecomment-5852413851
- github.com/redact-secret/redact-secret/issues/860issue-or-discussion · last read 2026-09-29 · latest outcome read · supports Listed as a reference by the legacy contract · #issuecomment-5880547337
- github.com/redact-secret/redact-secret-benchmarks/issues/528issue-or-discussion · last read 2026-09-29 · latest outcome read · supports Listed as a reference by the legacy contract
- github.com/redact-secret/redact-secret/issues/1020issue-or-discussion · last read 2026-09-29 · latest outcome read · supports Listed as a reference by the legacy contract
Provider documented ·
dossier-research· current · observed 2026-09-29Legacy dossier research (verdict ready, tier T1) cited 3 sources; the dossier does not attribute sources to individual properties.
- polarsource/polar @ 6a4f2f6d6083ef503cd23cb7f432ab2c60515973: server/polar/kit/crypto.pyprovider-documentation · last read 2026-10-03 · latest outcome unchanged · supports Cited by the legacy dossier research for this family · #L11-L32
- polarsource/polar @ 6a4f2f6d6083ef503cd23cb7f432ab2c60515973: server/polar/organization_access_token/service.pyprovider-sdk-source · last read 2026-10-03 · latest outcome unchanged · supports Cited by the legacy dossier research for this family · #L42
- redact-secret/redact-secret @ 378581770a87751d72e27529796c4f790649fd00: docs/audits/evidence/1014/polar.mdproject-research-note · last read 2026-09-29 · latest outcome read · supports Final research evidence recorded by the legacy dossier
Provider documented ·
taxonomy-sources· current · observed 2026-09-29The legacy taxonomy lists 2 sources for this family. The taxonomy records no date; the dossier researchedAt is used as the observed-at date.
- polarsource/polar @ 6a4f2f6d6083ef503cd23cb7f432ab2c60515973: server/polar/kit/crypto.pyprovider-documentation · last read 2026-10-03 · latest outcome unchanged · supports Listed as a source for this family in the legacy taxonomy · #L11-L32
- redact-secret/redact-secret @ 4f220ea000b58fa2e0e431ad88dea4eccb393fb0: docs/audits/evidence/1014/polar.mdprovider-documentation · last read 2026-09-29 · latest outcome read · supports Listed as a source for this family in the legacy taxonomy
Open questions
No open question is recorded for this revision.
Benchmark dossier notes
- Shape
polar_oat_+ exactly 43[A-Za-z0-9]: 37 random, then the CRC32 of those 37 in base62, zero-padded to 6.- Basis
- T1 under R1 and R9 from the provider server code; the service postdates the 2025-01-02 checksum era, so there is one era. The checksum corroborates only and never rejects (policy; ruling Q1 open).
- Issuance
- not attempted; the grammar is T1 from provider sources, so no key is needed.
- Contract in core
- detector-families.md (row on
main; the Beta.12 detector, redact-secret#1020, merged in redact-secret#1039 and is unreleased).
In this benchmark
- Fixtures
- 38
- Left readable
- 0
- Redacted too much
- 0
- False alarms
- 0
38 fixtures: 17 expect a redaction, 21 must stay quiet. See every row
| Evidence level | Fixtures | Left readable | Too much | False alarms |
|---|---|---|---|---|
| T1Provider-documented | 25 | 0 | 0 | 0 |
| T3Project policy | 8 | 0 | 0 | 0 |
| T0Pending review | 5 | 0 | 0 | 0 |
Every scanner on the same fixtures
In run order. Counts are what each scanner recorded on this family's fixtures, whichever rules it has; a scanner with no rule for the family has nothing to report on it.
| Scanner | Fixtures | Left readable | Too much | False alarms |
|---|---|---|---|---|
| flare-redactRuntime library · 1.6.1 · Published npm package · secrets-only (pii, generic_assignment disabled) · JavaScript engineNo rule maps to it | 38 | 16 | 1 | 0 |
| gitleaksRepository scanner · 8.30.1 · Directory scan · default rulesNo rule maps to it | 38 | 7 | 0 | 0 |
| redact-secretProduct measured here · 0.1.0-beta.14 · Published npm package · default detectors1 detector mapped | 38 | 0 | 0 | 0 |
| trufflehogRepository scanner · 3.97.4 · Filesystem scan · verification disabledNo rule maps to it | 38 | 17 | 0 | 0 |
Looks like it, but isn't
- Collisions
whsec_webhook secrets come from the same generator butstripe-tokenowns the prefix (misattributed, still redacted);polar_ci_is a public client id (Q5).
Scanner rules for this family
No peer rule maps to this family
None of the reviewed peer scanners has a rule that can match a credential of this family.
None mapped
Fixtures in this family
| Fixture | Kind and evidence | redact-secret |
|---|---|---|
polar-token-bare-prosepolar · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
polar-token-bearer-headerpolar · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
polar-token-chat-pastepolar · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
polar-token-checksum-mismatch-dotenvpolar · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
polar-token-checksum-mismatch-logpolar · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
polar-token-dotenvpolar · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
polar-token-exportpolar · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
polar-token-json-api-keypolar · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
polar-token-json-tokenpolar · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
polar-token-key-shape-barepolar · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
polar-token-key-shape-quotedpolar · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
polar-token-key-shape-unicode-crlfpolar · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
polar-token-mcp-envpolar · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
polar-token-python-sdkpolar · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
polar-token-sdk-kwargpolar · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
polar-token-ts-sdkpolar · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
polar-token-x-api-key-headerpolar · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
polar-token-actions-secret-referencepolar · templated-reference | Must not flagT3 · Project policy | Quiet |
polar-token-body-42-twinpolar · wrong-length | Must not flagT1 · Provider-documented · twin | Quiet |
polar-token-body-44-twinpolar · unsettled-evidence-input | Pending reviewT0 · Pending · twin | Unscored |
polar-token-ellipsis-placeholderpolar · documentation-placeholder | Must not flagT3 · Project policy | Quiet |
polar-token-env-reference-referencepolar · templated-reference | Must not flagT3 · Project policy | Quiet |
polar-token-hyphen-in-body-twinpolar · wrong-alphabet | Must not flagT1 · Provider-documented · twin | Quiet |
polar-token-identifier-name-public-idpolar · public-identifier | Must not flagT1 · Provider-documented | Quiet |
polar-token-label-prosepolar · benign-lookalike | Must not flagT3 · Project policy | Quiet |
polar-token-leading-glue-twinpolar · unsettled-evidence-input | Pending reviewT0 · Pending · twin | Unscored |
polar-token-maskpolar · benign-lookalike | Must not flagT3 · Project policy | Quiet |
polar-token-oauth-client-id-public-idpolar · unsettled-evidence-input | Pending reviewT0 · Pending | Unscored |
polar-token-prefix-onlypolar · benign-lookalike | Must not flagT1 · Provider-documented | Quiet |
polar-token-referencepolar · benign-lookalike | Must not flagT3 · Project policy | Quiet |
polar-token-short-bodypolar · benign-lookalike | Must not flagT1 · Provider-documented | Quiet |
polar-token-token-guidance-prosepolar · prose-mention | Must not flagT3 · Project policy | Quiet |
polar-token-trailing-hyphen-twinpolar · unsettled-evidence-input | Pending reviewT0 · Pending · twin | Unscored |
polar-token-trailing-underscore-twinpolar · unsettled-evidence-input | Pending reviewT0 · Pending · twin | Unscored |
polar-token-truncated-near-misspolar · format-near-miss | Must not flagT1 · Provider-documented | Quiet |
polar-token-underscore-in-body-twinpolar · wrong-alphabet | Must not flagT1 · Provider-documented · twin | Quiet |
polar-token-uppercase-prefix-twinpolar · prefix-near-miss | Must not flagT1 · Provider-documented · twin | Quiet |
polar-token-x-run-placeholderpolar · documentation-placeholder | Must not flagT3 · Project policy | Quiet |
Sources
Documentation and code
- github.com/polarsource/polar/blob/6a4f2f6d6083ef503cd23cb7f432ab2c60515973/server/polar/kit/crypto.py#L11-L32
- github.com/redact-secret/redact-secret/blob/4f220ea000b58fa2e0e431ad88dea4eccb393fb0/docs/audits/evidence/1014/polar.md
- github.com/polarsource/polar/blob/6a4f2f6d6083ef503cd23cb7f432ab2c60515973/server/polar/organization_access_token/service.py#L42
Research log
- redact-secret/redact-secret#1014Research issue
- redact-secret/redact-secret#1020Research issue
- redact-secret/redact-secret#1039Research issue
- redact-secret/redact-secret-benchmarks#528Research issue
- Final evidence, pinned to a commit/redact-secret/redact-secret/blob/378581770a87751d72e27529796c4f790649fd00/docs/audits/evidence/1014/polar.md