redact-secret · Report
Organization auth token
sntrys_ prefixed organization auth token.
Research record
2 events in the review history: 1 observed, 1 reviewed. Latest: observed on 2026-09-24 by automation, project maintainer. Project-maintained review is not independent validation. The family record at this release.
Format
What it looks like
- Descriptive pattern
^sntrys_eyJ[A-Za-z0-9+/]{26,}={0,2}_[A-Za-z0-9+/]{43}$
Parts are shown as recorded. Evidence classes belong to the facts below; no class is assigned to a part.
Format facts
Provider documented ·
mutable-property-source· current · observed 2026-09-24Documentation for the one property varied in legacy twin fixtures (sntrys_ + base64(JSON facts) + _ + 43-character standard-base64 secret): Un-probeable record lifted 2026-09-24 (#207): Sentry's own generator and RFC 0091 (provider code on github.com; not yet accepted as documentation, so the tier stays T2) fix the sntrys_ prefix, the eyJ JSON marker, exactly two _ delimiters and a 43-character standard-base64 secret. Twins mutate one of those properties.
- getsentry/sentry @ master: src/sentry/utils/security/orgauthtoken_token.pyprovider-documentation · last read 2026-09-24 · latest outcome read · supports Un-probeable record lifted 2026-09-24 (#207): Sentry's own generator and RFC 0091 (provider code on github.com; not yet accepted as documentation, so the tier stays T2) fix the sntrys_ prefix, the eyJ JSON marker, exactly two _ delimiters and a 43-character standard-base64 secret. Twins mutate one of those properties.
Tool corroborated ·
tool-corroboration· current · observed 2026-09-22Pinned scanner rules are consistent with the contract grammar (2 artifacts: gitleaks 8.30.1; trufflehog 3.97.4).
- gitleaks/gitleaks @ v8.30.1: config/gitleaks.tomlscanner-rule-source · last read 2026-10-04 · latest outcome read · supports gitleaks 8.30.1: gitleaks.toml
- trufflesecurity/trufflehog @ v3.97.4: pkg/detectors/sentryorgtoken/sentryorgtoken.goscanner-rule-source · last read 2026-09-22 · latest outcome read · supports trufflehog 3.97.4: sentryorgtoken/sentryorgtoken
Provider documented ·
field-structure· current · observed 2026-09-22structure: sntrys_ + base64 of a JSON facts object (hence eyJ) + _ + secret; exactly two _
- getsentry/rfcs @ main: text/0091-ci-upload-tokens.mdprovider-sdk-source · last read 2026-09-22 · latest outcome read · supports Sentry's merged RFC on github.com; whether it meets the provider-source bar is an open maintainer decision
- getsentry/sentry @ master: src/sentry/utils/security/orgauthtoken_token.pyprovider-documentation · last read 2026-09-24 · latest outcome read · supports structure: sntrys_ + base64 of a JSON facts object (hence eyJ) + _ + secret; exactly two _
Provider documented ·
field-payload-alphabet· current · observed 2026-09-22payload alphabet: standard base64 (+ and /) with its = padding kept; never base64url
- getsentry/sentry @ master: src/sentry/utils/security/orgauthtoken_token.pyprovider-documentation · last read 2026-09-24 · latest outcome read · supports payload alphabet: standard base64 (+ and /) with its = padding kept; never base64url
Provider documented ·
field-secret· current · observed 2026-09-22secret: 32 random bytes as standard base64 with padding stripped: exactly 43 characters, no -, _ or =
- getsentry/sentry-cli @ master: src/utils/auth_tokenprovider-sdk-source · last read 2026-09-22 · latest outcome read · supports secret: 32 random bytes as standard base64 with padding stripped: exactly 43 characters, no -, _ or =
- getsentry/sentry @ master: src/sentry/utils/security/orgauthtoken_token.pyprovider-documentation · last read 2026-09-24 · latest outcome read · supports secret: 32 random bytes as standard base64 with padding stripped: exactly 43 characters, no -, _ or =
Unresolved ·
field-payload-keys· current · observed 2026-09-22payload keys: iat, url, region_url, org in that order; url may be null or empty on self-hosted installs
- github.com/redact-secret/redact-secret/issues/658third-party-writeup · last read 2026-09-22 · latest outcome read · supports payload keys: iat, url, region_url, org in that order; url may be null or empty on self-hosted installs
Unresolved ·
dossier-research· current · observed 2026-09-24Legacy dossier research (verdict ready, tier T2) cited 4 sources; the dossier does not attribute sources to individual properties.
- getsentry/rfcs @ 6bdc964983762d614dfc9127d669d15ce521be3f: text/0091-ci-upload-tokens.mdprovider-documentation · last read 2026-09-24 · latest outcome read · supports Cited by the legacy dossier research for this family
- getsentry/sentry-cli @ c880db5fc6b69378b62310b7fdbd74637bcd5fb4: src/utils/auth_token/org_auth_token.rsother · last read 2026-09-24 · latest outcome read · supports Cited by the legacy dossier research for this family
- getsentry/sentry @ d4aa9756a10f576272b95437231c9dd32546e514: src/sentry/utils/security/orgauthtoken_token.pyprovider-sdk-source · last read 2026-10-03 · latest outcome unchanged · supports Cited by the legacy dossier research for this family
- redact-secret/redact-secret @ 8b6a5fde52ecb4dfce13f09c7a947062d21483c7: docs/audits/evidence/658/README.mdproject-research-note · last read 2026-09-24 · latest outcome read · supports Final research evidence recorded by the legacy dossier
Open questions
No open question is recorded for this revision.
Benchmark dossier notes
- Shape
sntrys_, a base64-encoded JSON payload startingeyJ(standard base64 with any=padding kept), a second_, then a 43-character secret (b64encode(token_bytes(32))with=stripped). The parser requires exactly two_. Seven measured tokens have payloads of 96 to 152 characters and totals of 147 to 203, including self-hosted tokens withurlnull or empty.- Basis
- T2. RFC 0091 in
getsentry/rfcsstates the static prefix and thePREFIX_FACTS_SECRETstructure; the secret recipe is an "implementation detail". Generator (orgauthtoken_token.py) andsentry-cliconfirm it. Claims of a Base64URL alphabet or fixed total length in other tools are contradicted by the generator; the base64url question is settled by Sentry's own code. - Issuance
- not attempted; no freshly issued token checked.
- Contract in core
- detector-families.md; evidence #658 record.
In this benchmark
- Fixtures
- 40
- Left readable
- 0
- Redacted too much
- 0
- False alarms
- 0
40 fixtures: 18 expect a redaction, 22 must stay quiet. See every row
| Evidence level | Fixtures | Left readable | Too much | False alarms |
|---|---|---|---|---|
| T2Tool-corroborated | 33 | 0 | 0 | 0 |
| T3Project policy | 7 | 0 | 0 | 0 |
Every scanner on the same fixtures
In run order. Counts are what each scanner recorded on this family's fixtures, whichever rules it has; a scanner with no rule for the family has nothing to report on it.
| Scanner | Fixtures | Left readable | Too much | False alarms |
|---|---|---|---|---|
| flare-redactRuntime library · 1.6.1 · Published npm package · secrets-only (pii, generic_assignment disabled) · JavaScript engineNo rule maps to it | 40 | 18 | 0 | 1 |
| gitleaksRepository scanner · 8.30.1 · Directory scan · default rules1 rule targets it | 40 | 11 | 2 | 0 |
| redact-secretProduct measured here · 0.1.0-beta.14 · Published npm package · default detectors1 detector mapped | 40 | 0 | 0 | 0 |
| trufflehogRepository scanner · 3.97.4 · Filesystem scan · verification disabled1 rule targets it | 40 | 18 | 0 | 0 |
Benchmark dossier questions
- Open caveat
- Nothing on a Sentry web domain states it; RFC 0091 (github.com, header still says draft) and Sentry code do. Whether a provider-authored RFC counts as T1 is an open maintainer ruling.
Looks like it, but isn't
- Collisions
- the contract's
eyJanchor and{26,}payload floor are looser than every observed token, deliberately, to keepurl-less payloads.
Scanner rules for this family
| Scanner | Rule | What the rule matches |
|---|---|---|
| gitleaks · rules 8.30.1 | sentry-org-token | sntrys_eyJ... Base64 payload |
| trufflehog · rules 3.97.4 | sentryorgtoken | sntrys_eyJ + 197 characters |
No rule maps to this family in flare-redact, openredaction.
Fixtures in this family
| Fixture | Kind and evidence | redact-secret |
|---|---|---|
sentry-org-auth-token-actions-envsentry · documented-format-literal | Must redactT2 · Tool-corroborated | Redacted |
sentry-org-auth-token-bomsentry · multibyte-text-offsets | Must redactT2 · Tool-corroborated | Redacted |
sentry-org-auth-token-dockerfile-envsentry · documented-format-literal | Must redactT2 · Tool-corroborated | Redacted |
sentry-org-auth-token-dsn-public-idsentry · public-identifier | Must not flagT2 · Tool-corroborated | Quiet |
sentry-org-auth-token-envsentry · documented-format-literal | Must redactT2 · Tool-corroborated | Redacted |
sentry-org-auth-token-jsonsentry · structured-text-value | Must redactT2 · Tool-corroborated | Redacted |
sentry-org-auth-token-markdownsentry · markdown-and-comment-value | Must redactT2 · Tool-corroborated | Redacted |
sentry-org-auth-token-next-configsentry · documented-format-literal | Must redactT2 · Tool-corroborated | Redacted |
sentry-org-auth-token-no-final-newlinesentry · value-at-input-edges | Must redactT2 · Tool-corroborated | Redacted |
sentry-org-auth-token-org-token-baresentry · documented-format-literal | Must redactT2 · Tool-corroborated | Redacted |
sentry-org-auth-token-org-token-quotedsentry · documented-format-literal | Must redactT2 · Tool-corroborated | Redacted |
sentry-org-auth-token-org-token-unicode-crlfsentry · documented-format-literal | Must redactT2 · Tool-corroborated | Redacted |
sentry-org-auth-token-pythonsentry · source-code-string-literal | Must redactT2 · Tool-corroborated | Redacted |
sentry-org-auth-token-sentry-clisentry · documented-format-literal | Must redactT2 · Tool-corroborated | Redacted |
sentry-org-auth-token-sentry-propertiessentry · documented-format-literal | Must redactT2 · Tool-corroborated | Redacted |
sentry-org-auth-token-sentryclircsentry · documented-format-literal | Must redactT2 · Tool-corroborated | Redacted |
sentry-org-auth-token-single-quotessentry · quoted-value-extent | Must redactT2 · Tool-corroborated | Redacted |
sentry-org-auth-token-tomlsentry · structured-text-value | Must redactT2 · Tool-corroborated | Redacted |
sentry-org-auth-token-yamlsentry · structured-text-value | Must redactT2 · Tool-corroborated | Redacted |
sentry-org-auth-token-actions-secret-referencesentry · templated-reference | Must not flagT3 · Project policy | Quiet |
sentry-org-auth-token-decoded-facts-encoded-valuesentry · benign-encoded-value | Must not flagT2 · Tool-corroborated | Quiet |
sentry-org-auth-token-docs-ellipsis-placeholdersentry · documentation-placeholder | Must not flagT3 · Project policy | Quiet |
sentry-org-auth-token-dotted-delimiter-twinsentry · boundary-violation | Must not flagT2 · Tool-corroborated · twin | Quiet |
sentry-org-auth-token-json-marker-twinsentry · prefix-near-miss | Must not flagT2 · Tool-corroborated · twin | Quiet |
sentry-org-auth-token-label-prosesentry · benign-lookalike | Must not flagT3 · Project policy | Quiet |
sentry-org-auth-token-masksentry · benign-lookalike | Must not flagT3 · Project policy | Quiet |
sentry-org-auth-token-missing-delimiter-twinsentry · boundary-violation | Must not flagT2 · Tool-corroborated · twin | Quiet |
sentry-org-auth-token-missing-json-markersentry · benign-lookalike | Must not flagT2 · Tool-corroborated | Quiet |
sentry-org-auth-token-missing-payload-in-prose-near-misssentry · format-near-miss | Must not flagT2 · Tool-corroborated | Quiet |
sentry-org-auth-token-missing-secret-in-log-near-misssentry · format-near-miss | Must not flagT2 · Tool-corroborated | Quiet |
sentry-org-auth-token-org-project-public-idsentry · public-identifier | Must not flagT2 · Tool-corroborated | Quiet |
sentry-org-auth-token-prefix-twinsentry · prefix-near-miss | Must not flagT2 · Tool-corroborated · twin | Quiet |
sentry-org-auth-token-referencesentry · benign-lookalike | Must not flagT3 · Project policy | Quiet |
sentry-org-auth-token-scope-note-prosesentry · prose-mention | Must not flagT3 · Project policy | Quiet |
sentry-org-auth-token-short-secret-ci-twinsentry · wrong-length | Must not flagT2 · Tool-corroborated · twin | Quiet |
sentry-org-auth-token-short-secret-twinsentry · wrong-length | Must not flagT2 · Tool-corroborated · twin | Quiet |
sentry-org-auth-token-short-signaturesentry · benign-lookalike | Must not flagT2 · Tool-corroborated | Quiet |
sentry-org-auth-token-urlsafe-payload-twinsentry · wrong-alphabet | Must not flagT2 · Tool-corroborated · twin | Quiet |
sentry-org-auth-token-urlsafe-secret-twinsentry · wrong-alphabet | Must not flagT2 · Tool-corroborated · twin | Quiet |
sentry-org-auth-token-your-token-here-placeholdersentry · documentation-placeholder | Must not flagT3 · Project policy | Quiet |
Sources
Documentation and code
- github.com/getsentry/rfcs/blob/6bdc964983762d614dfc9127d669d15ce521be3f/text/0091-ci-upload-tokens.md
- github.com/getsentry/sentry/blob/d4aa9756a10f576272b95437231c9dd32546e514/src/sentry/utils/security/orgauthtoken_token.py
- github.com/getsentry/sentry-cli/blob/c880db5fc6b69378b62310b7fdbd74637bcd5fb4/src/utils/auth_token/org_auth_token.rs
Research log
- redact-secret/redact-secret#658Research issue
- Final evidence, pinned to a commit/redact-secret/redact-secret/blob/8b6a5fde52ecb4dfce13f09c7a947062d21483c7/docs/audits/evidence/658/README.md