redact-secret · Report
Collection access key
PMAT- followed by 26 characters; a read-only key for one collection's JSON, shared through the collection URL's access_key parameter.
Research record
3 events in the review history: 2 observed, 1 reviewed. Latest: observed on 2026-09-25 by automation, project maintainer. Project-maintained review is not independent validation. The family record at this release.
Format
What it looks like
- Descriptive pattern
^PMAT-[A-Z0-9]{26}$
Parts are shown as recorded. Evidence classes belong to the facts below; no class is assigned to a part.
Format facts
Provider documented ·
mutable-property-source· current · observed 2026-09-24Documentation for the one property varied in legacy twin fixtures (masked PMAT- collection access key): Postman documents the collection access key as a read-only credential for one collection's JSON (Share via API), valid for 60 days of inactivity, and renders it masked as PMAT- followed by asterisks and four trailing characters (26 in all). It states no alphabet. Twins mutate the prefix, its delimiter or the body length
- learning.postman.com/api-docs/api-reference/collection-access-keys/get-collection-access-keysprovider-documentation · last read 2026-09-25 · latest outcome read · supports Postman documents the collection access key as a read-only credential for one collection's JSON (Share via API), valid for 60 days of inactivity, and renders it masked as PMAT- followed by asterisks and four trailing characters (26 in all). It states no alphabet. Twins mutate the prefix, its delimiter or the body length
Unresolved ·
tool-corroboration· current · observed 2026-09-24Pinned scanner rules are consistent with the contract grammar (1 artifact: GitLab secret-detection-rules).
- gitlab.com/gitlab-org/security-products/secret-detection/secret-detection-rules/-/blob/e1c7e83815a7e55cc1514dd59d4e56459e39cbfb/rules/mit/postman/postman.tomlscanner-rule-source · last read 2026-09-25 · latest outcome read · supports GitLab secret-detection-rules: PostmanCollectionAccessKey
Provider documented ·
field-credential· current · observed 2026-09-24credential: read-only collection access key, 60-day inactivity expiry, shared via the collection JSON URL
- learning.postman.com/docs/developer/postman-api/authentication/provider-documentation · last read 2026-09-25 · latest outcome read · supports credential: read-only collection access key, 60-day inactivity expiry, shared via the collection JSON URL
- learning.postman.com/docs/collaborating-in-postman/sharing/provider-documentation · last read 2026-09-25 · latest outcome read · supports credential: read-only collection access key, 60-day inactivity expiry, shared via the collection JSON URL
Provider documented ·
field-prefix· current · observed 2026-09-24prefix: PMAT-
- learning.postman.com/api-docs/api-reference/collection-access-keys/get-collection-access-keysprovider-documentation · last read 2026-09-25 · latest outcome read · supports masked display
Unresolved ·
field-body-length· current · observed 2026-09-24body length: exactly 26 characters (The provider's masked display (asterisks + 4) counts to 26, which agrees but is not a statement.)
- gitlab.com/gitlab-org/security-products/secret-detection/secret-detection-rules/-/blob/e1c7e83815a7e55cc1514dd59d4e56459e39cbfb/rules/mit/postman/postman.tomlscanner-rule-source · last read 2026-09-25 · latest outcome read · supports body length: exactly 26 characters
Unresolved ·
field-body-alphabet· current · observed 2026-09-24body alphabet: [A-Z0-9] (One tool only; the product accepts lowercase too. No case twin.)
- gitlab.com/gitlab-org/security-products/secret-detection/secret-detection-rules/-/blob/e1c7e83815a7e55cc1514dd59d4e56459e39cbfb/rules/mit/postman/postman.tomlscanner-rule-source · last read 2026-09-25 · latest outcome read · supports body alphabet: [A-Z0-9]
Unresolved ·
field-ulid-body· current · observed 2026-09-24ULID body: the body may be a ULID (26 Crockford base32 characters with a timestamp prefix): every example in GitLab's rule has that shape (Not claimed. Positives use the rule's wider [A-Z0-9]{26}; no fixture asserts silence on a non-ULID body.)
- gitlab.com/gitlab-org/security-products/secret-detection/secret-detection-rules/-/blob/e1c7e83815a7e55cc1514dd59d4e56459e39cbfb/rules/mit/postman/postman.tomlscanner-rule-source · last read 2026-09-25 · latest outcome read · supports rule examples; not copied into any fixture
Unresolved ·
listed-references· current · observed 2026-09-24The legacy contract lists 3 references without stating which property each supports.
- docs.github.com/en/code-security/secret-scanning/introduction/supported-secret-scanning-patternsprovider-documentation · last read 2026-10-05 · latest outcome read · supports Listed as a reference by the legacy contract
- learning.postman.com/docs/developer/postman-api/authentication/provider-documentation · last read 2026-09-25 · latest outcome read · supports Listed as a reference by the legacy contract
- learning.postman.com/docs/collaborating-in-postman/sharing/provider-documentation · last read 2026-09-25 · latest outcome read · supports Listed as a reference by the legacy contract
Tool corroborated ·
dossier-research· current · observed 2026-09-25Legacy dossier research (verdict ready, tier T2) cited 4 sources; the dossier does not attribute sources to individual properties.
- redact-secret/redact-secret @ 8b6a5fde52ecb4dfce13f09c7a947062d21483c7: docs/audits/evidence/582/README.mdproject-research-note · last read 2026-09-25 · latest outcome read · supports Final research evidence recorded by the legacy dossier
- gitlab.com/gitlab-org/security-products/secret-detection/secret-detection-rules/-/blob/e1c7e83815a7e55cc1514dd59d4e56459e39cbfb/rules/mit/postman/postman.tomlscanner-rule-source · last read 2026-09-25 · latest outcome read · supports Cited by the legacy dossier research for this family
- learning.postman.com/docs/collaborating-in-postman/sharing/provider-documentation · last read 2026-09-25 · latest outcome read · supports Cited by the legacy dossier research for this family
- learning.postman.com/api-docs/api-reference/collection-access-keys/get-collection-access-keysprovider-documentation · last read 2026-09-25 · latest outcome read · supports Cited by the legacy dossier research for this family
Unresolved ·
taxonomy-sources· current · observed 2026-09-25The legacy taxonomy lists 1 source for this family. The taxonomy records no date; the dossier researchedAt is used as the observed-at date.
- learning.postman.com/docs/collaborating-in-postman/sharing/provider-documentation · last read 2026-09-25 · latest outcome read · supports Listed as a source for this family in the legacy taxonomy
Open questions
No open question is recorded for this revision.
Benchmark dossier notes
- Shape
PMAT-followed by 26 characters. Postman renders a masked key with a four-character tail and a 26-character count, valid 60 days after last use, and states no alphabet.- Basis
- T2. The uppercase
[A-Z0-9]body comes from GitLab's secret detection rule alone (pinned above); the product accepts either case. GitHub's partner list haspostman_collection_keybesidepostman_api_key. - Issuance
- collection sharing in Postman, or the collection access keys API. Not attempted.
- Contract in core
- detector-families.md (
postman_collection_access_key, always redacted). #700 asked whetherPMAT-was its own family or an unsupported form; it is now a registry detector.
In this benchmark
- Fixtures
- 42
- Left readable
- 0
- Redacted too much
- 0
- False alarms
- 0
42 fixtures: 18 expect a redaction, 24 must stay quiet. See every row
| Evidence level | Fixtures | Left readable | Too much | False alarms |
|---|---|---|---|---|
| T2Tool-corroborated | 33 | 0 | 0 | 0 |
| T3Project policy | 9 | 0 | 0 | 0 |
Every scanner on the same fixtures
In run order. Counts are what each scanner recorded on this family's fixtures, whichever rules it has; a scanner with no rule for the family has nothing to report on it.
| Scanner | Fixtures | Left readable | Too much | False alarms |
|---|---|---|---|---|
| flare-redactRuntime library · 1.6.1 · Published npm package · secrets-only (pii, generic_assignment disabled) · JavaScript engineNo rule maps to it | 42 | 18 | 0 | 0 |
| gitleaksRepository scanner · 8.30.1 · Directory scan · default rulesNo rule maps to it | 42 | 4 | 0 | 0 |
| redact-secretProduct measured here · 0.1.0-beta.14 · Published npm package · default detectors1 detector mapped | 42 | 0 | 0 | 0 |
| trufflehogRepository scanner · 3.97.4 · Filesystem scan · verification disabledNo rule maps to it | 42 | 18 | 0 | 0 |
Benchmark dossier questions
- Open caveat
- The PMAT- prefix and 26-character count are shown masked in provider docs; the uppercase alphanumeric body comes from GitLab's rule alone. No issued key observed.
Looks like it, but isn't
- Collisions
- the
access_keyquery parameter of a collection URL is where the value appears.PMAK-keys are distinct.
Scanner rules for this family
No peer rule maps to this family
None of the reviewed peer scanners has a rule that can match a credential of this family.
None mapped
Fixtures in this family
| Fixture | Kind and evidence | redact-secret |
|---|---|---|
postman-collection-access-key-actions-newmanpostman · documented-format-literal | Must redactT2 · Tool-corroborated | Redacted |
postman-collection-access-key-chat-sharepostman · documented-format-literal | Must redactT2 · Tool-corroborated | Redacted |
postman-collection-access-key-ci-logpostman · documented-format-literal | Must redactT2 · Tool-corroborated | Redacted |
postman-collection-access-key-compose-envpostman · documented-format-literal | Must redactT2 · Tool-corroborated | Redacted |
postman-collection-access-key-curl-collection-jsonpostman · documented-format-literal | Must redactT2 · Tool-corroborated | Redacted |
postman-collection-access-key-dotenvpostman · documented-format-literal | Must redactT2 · Tool-corroborated | Redacted |
postman-collection-access-key-exportpostman · documented-format-literal | Must redactT2 · Tool-corroborated | Redacted |
postman-collection-access-key-key-shape-barepostman · documented-format-literal | Must redactT2 · Tool-corroborated | Redacted |
postman-collection-access-key-key-shape-quotedpostman · documented-format-literal | Must redactT2 · Tool-corroborated | Redacted |
postman-collection-access-key-key-shape-unicode-crlfpostman · documented-format-literal | Must redactT2 · Tool-corroborated | Redacted |
postman-collection-access-key-newman-jsonpostman · documented-format-literal | Must redactT2 · Tool-corroborated | Redacted |
postman-collection-access-key-newman-runpostman · documented-format-literal | Must redactT2 · Tool-corroborated | Redacted |
postman-collection-access-key-share-configpostman · documented-format-literal | Must redactT2 · Tool-corroborated | Redacted |
postman-collection-access-key-share-outputpostman · documented-format-literal | Must redactT2 · Tool-corroborated | Redacted |
postman-collection-access-key-share-via-apipostman · documented-format-literal | Must redactT2 · Tool-corroborated | Redacted |
postman-collection-access-key-twin-base-dotenvpostman · documented-format-literal | Must redactT2 · Tool-corroborated | Redacted |
postman-collection-access-key-twin-base-exportpostman · documented-format-literal | Must redactT2 · Tool-corroborated | Redacted |
postman-collection-access-key-twin-base-urlpostman · documented-format-literal | Must redactT2 · Tool-corroborated | Redacted |
postman-collection-access-key-api-key-prefix-twinpostman · prefix-near-miss | Must not flagT2 · Tool-corroborated · twin | Quiet |
postman-collection-access-key-base64-uid-encoded-valuepostman · benign-encoded-value | Must not flagT2 · Tool-corroborated | Quiet |
postman-collection-access-key-collection-uid-public-idpostman · public-identifier | Must not flagT2 · Tool-corroborated | Quiet |
postman-collection-access-key-docs-placeholder-placeholderpostman · documentation-placeholder | Must not flagT3 · Project policy | Quiet |
postman-collection-access-key-document-code-near-misspostman · format-near-miss | Must not flagT2 · Tool-corroborated | Quiet |
postman-collection-access-key-env-reference-referencepostman · templated-reference | Must not flagT3 · Project policy | Quiet |
postman-collection-access-key-key-guidance-prosepostman · prose-mention | Must not flagT3 · Project policy | Quiet |
postman-collection-access-key-label-prosepostman · benign-lookalike | Must not flagT3 · Project policy | Quiet |
postman-collection-access-key-long-body-twinpostman · wrong-length | Must not flagT2 · Tool-corroborated · twin | Quiet |
postman-collection-access-key-long-body-twin-wrong-lengthpostman · wrong-length | Must not flagT2 · Tool-corroborated · twin | Quiet |
postman-collection-access-key-lowercase-prefix-twinpostman · prefix-near-miss | Must not flagT2 · Tool-corroborated · twin | Quiet |
postman-collection-access-key-maskpostman · benign-lookalike | Must not flagT3 · Project policy | Quiet |
postman-collection-access-key-masked-key-list-placeholderpostman · documentation-placeholder | Must not flagT3 · Project policy | Quiet |
postman-collection-access-key-postman-variable-referencepostman · templated-reference | Must not flagT3 · Project policy | Quiet |
postman-collection-access-key-prefix-onlypostman · benign-lookalike | Must not flagT2 · Tool-corroborated | Quiet |
postman-collection-access-key-prefix-only-near-misspostman · format-near-miss | Must not flagT2 · Tool-corroborated | Quiet |
postman-collection-access-key-public-share-link-public-idpostman · public-identifier | Must not flagT2 · Tool-corroborated | Quiet |
postman-collection-access-key-referencepostman · benign-lookalike | Must not flagT3 · Project policy | Quiet |
postman-collection-access-key-sharing-note-prosepostman · prose-mention | Must not flagT3 · Project policy | Quiet |
postman-collection-access-key-short-bodypostman · benign-lookalike | Must not flagT2 · Tool-corroborated | Quiet |
postman-collection-access-key-short-body-twinpostman · wrong-length | Must not flagT2 · Tool-corroborated · twin | Quiet |
postman-collection-access-key-short-body-twin-wrong-lengthpostman · wrong-length | Must not flagT2 · Tool-corroborated · twin | Quiet |
postman-collection-access-key-underscore-delimiter-twinpostman · boundary-violation | Must not flagT2 · Tool-corroborated · twin | Quiet |
postman-collection-access-key-underscore-delimiter-twin-boundary-violationpostman · boundary-violation | Must not flagT2 · Tool-corroborated · twin | Quiet |
Sources
Documentation and code
- learning.postman.com/docs/collaborating-in-postman/sharing/
- learning.postman.com/api-docs/api-reference/collection-access-keys/get-collection-access-keys
- gitlab.com/gitlab-org/security-products/secret-detection/secret-detection-rules/-/blob/e1c7e83815a7e55cc1514dd59d4e56459e39cbfb/rules/mit/postman/postman.toml
Research log
- redact-secret/redact-secret#582Research issue
- redact-secret/redact-secret#700Research issue
- redact-secret/redact-secret-benchmarks#259Research issue
- Final evidence, pinned to a commit/redact-secret/redact-secret/blob/8b6a5fde52ecb4dfce13f09c7a947062d21483c7/docs/audits/evidence/582/README.md