redact-secret · Report
Logfire token (pylf_v)
pylf_v<n>_<region>_ + an optional organization UUID + an alphanumeric body.
Research record
No research record for this family
snapshot-2026.10.06.4 has no family record for pydantic:logfire-token, so its review state, format revision and format facts are not recorded here.
Not recorded
Format
Format not recorded
No format contract is recorded for this family in the pinned release.
Not recordedBenchmark dossier notes
- Shape
pylf_v<n>_<region>_+ an optional organization UUID (8-4-4-4-12 hex, v2 API keys) + an alphanumeric body,[A-Za-z0-9]with a policy floor of 20; every provider fixture and one third-party rule use 44.- Basis
- T1 lexical grammar under R1 (two provider SDK parsers) and R2 (the provider scrubber's
pylf_v\d+_rule). No provider source states a body width, so the floor of 20 is a policy (Q7, non-blocking) recorded inpolicy-body-floor, never T1; no fixture asserts silence below it. Write, read, API and AI Gateway keys are one family and one finding type. - Issuance
- not attempted; the handoff records an optional structure-only check (version, region, organization id and its hex case, body length, alphabet) that would not change the contract.
- Contract in core
- detector-families.md (the detector
pydantic-logfire-tokenis registered onmain, redact-secret#1106, unreleased). The benchmark contract and corpus are authored inbenchmarks/lib/beta8/583f.tsandfixtures/generated/beta8/583f.mjs.
In this benchmark
No fixtures in this family yet
Nothing in the corpus targets it, so nothing is measured and no coverage is claimed.
Not measured
Looks like it, but isn't
- Collisions
pylf_v1_us_...and maskedpylf_v1_us_0kYhc****placeholders, the scrubber patternpylf_v\d+_in config text,logfire-ushostnames, legacy unprefixed tokens (out of scope), and the scanner-only v3/v4 80-byte shapes.
Scanner rules for this family
No peer rule maps to this family
None of the reviewed peer scanners has a rule that can match a credential of this family.
None mapped
No fixtures in this family yet
Nothing in the corpus targets it, so nothing is measured and no coverage is claimed.
Not measured
Sources
Documentation and code
- github.com/redact-secret/redact-secret/blob/3b1a5aa9935c57416a026a44f45501fd41ffeac8/docs/audits/evidence/1014/pydantic-logfire.md
- github.com/pydantic/logfire/blob/a413dc789002d35cbc3b1a281e0d936c0930762e/logfire-sdk/logfire/_internal/auth.py#L36-L41
- github.com/pydantic/pydantic-ai/blob/b2e37b94a275084716c820065e8c912809daed7c/pydantic_ai_slim/pydantic_ai/providers/gateway.py#L407-L418
Research log
- redact-secret/redact-secret#1014Research issue
- redact-secret/redact-secret#1106Research issue
- redact-secret/redact-secret-benchmarks#583Research issue
- Final evidence, pinned to a commit/redact-secret/redact-secret/blob/3b1a5aa9935c57416a026a44f45501fd41ffeac8/docs/audits/evidence/1014/pydantic-logfire.md