Skip to content
Benchmarks

redact-secret · Report

Logfire token (pylf_v)

pylf_v<n>_<region>_ + an optional organization UUID + an alphanumeric body.

  • Pydantic
  • Detectors: pydantic-logfire-token
  • Run 2026-10-07
  • Mode published · redact-secret 0.1.0-beta.14
  • Dossier verdictReady
  • Dossier evidence levelT1 · Provider-documented
  • Dossier researched2026-09-30
Registered in the product at the 3b1a5aa re-pin (redact-secret PR #1227, unreleased), with a benchmark contract and a seeded corpus (#583, `beta8-583f`); the claim stays provisional until the conformance and arrival gates and the open ruling questions settle. Not a support claim. Handoff pydantic-logfire.md (READY; the body floor is the Q7 policy).

Research record

From credential-evidence snapshot-2026.10.06.4 · records at 77ce761 · schema 1.8.0. It describes the research on the format, not what any scanner or the product does, and not a support status.
  • Review stateNot recorded
  • Format revisionNot recorded
  • ResearchNot recorded
  • ResearchedNot recorded

No research record for this family

snapshot-2026.10.06.4 has no family record for pydantic:logfire-token, so its review state, format revision and format facts are not recorded here.

Not recorded

Format

Provider format research from credential-evidence snapshot-2026.10.06.4 · records at 77ce761 · schema 1.8.0.

Format not recorded

No format contract is recorded for this family in the pinned release.

Not recorded

Benchmark dossier notes

From the provider dossier, as written. The evidence level above says how well the format is backed; a fact the dossier does not record is not shown.
Shape
pylf_v<n>_<region>_ + an optional organization UUID (8-4-4-4-12 hex, v2 API keys) + an alphanumeric body, [A-Za-z0-9] with a policy floor of 20; every provider fixture and one third-party rule use 44.
Basis
T1 lexical grammar under R1 (two provider SDK parsers) and R2 (the provider scrubber's pylf_v\d+_ rule). No provider source states a body width, so the floor of 20 is a policy (Q7, non-blocking) recorded in policy-body-floor, never T1; no fixture asserts silence below it. Write, read, API and AI Gateway keys are one family and one finding type.
Issuance
not attempted; the handoff records an optional structure-only check (version, region, organization id and its hex case, body length, alphabet) that would not change the contract.
Contract in core
detector-families.md (the detector pydantic-logfire-token is registered on main, redact-secret#1106, unreleased). The benchmark contract and corpus are authored in benchmarks/lib/beta8/583f.ts and fixtures/generated/beta8/583f.mjs.

In this benchmark

Fixture rows on the current run. Counts are for redact-secret in published · redact-secret 0.1.0-beta.14 mode.

No fixtures in this family yet

Nothing in the corpus targets it, so nothing is measured and no coverage is claimed.

Not measured

Looks like it, but isn't

Values the dossier records as resembling this credential without being one.
Collisions
pylf_v1_us_... and masked pylf_v1_us_0kYhc**** placeholders, the scrubber pattern pylf_v\d+_ in config text, logfire-us hostnames, legacy unprefixed tokens (out of scope), and the scanner-only v3/v4 80-byte shapes.

Scanner rules for this family

Mapped by hand (reviewed 2026-09-30) from each scanner's pinned rule file, never from what a scanner found on the fixtures.

No peer rule maps to this family

None of the reviewed peer scanners has a rule that can match a credential of this family.

None mapped

0 of 0 rows

No fixtures in this family yet

Nothing in the corpus targets it, so nothing is measured and no coverage is claimed.

Not measured

Sources

Researched 2026-09-30.

Documentation and code

  • github.com/redact-secret/redact-secret/blob/3b1a5aa9935c57416a026a44f45501fd41ffeac8/docs/audits/evidence/1014/pydantic-logfire.md
  • github.com/pydantic/logfire/blob/a413dc789002d35cbc3b1a281e0d936c0930762e/logfire-sdk/logfire/_internal/auth.py#L36-L41
  • github.com/pydantic/pydantic-ai/blob/b2e37b94a275084716c820065e8c912809daed7c/pydantic_ai_slim/pydantic_ai/providers/gateway.py#L407-L418

Research log