Skip to content
Benchmarks

redact-secret · Report

Personal access token (sgp_)

sgp_ + an optional instance identifier + 40 lowercase hex.

  • Sourcegraph
  • Detectors: sourcegraph-token
  • Run 2026-10-07
  • Mode published · redact-secret 0.1.0-beta.14
  • Dossier verdictReady
  • Dossier evidence levelT1 · Provider-documented
  • Dossier researched2026-09-30
Registered in the product at the 3b1a5aa re-pin (redact-secret PR #1214, unreleased), with a benchmark contract and a seeded corpus (#583, `beta8-583c`); the claim stays provisional until the conformance and arrival gates and the open ruling questions settle. Not a support claim. Handoff sourcegraph.md (READY for sgp_).

Research record

From credential-evidence snapshot-2026.10.06.4 · records at 77ce761 · schema 1.8.0. It describes the research on the format, not what any scanner or the product does, and not a support status.
  • Review stateNot recorded
  • Format revisionNot recorded
  • ResearchNot recorded
  • ResearchedNot recorded

No research record for this family

snapshot-2026.10.06.4 has no family record for sourcegraph:access-token, so its review state, format revision and format facts are not recorded here.

Not recorded

Format

Provider format research from credential-evidence snapshot-2026.10.06.4 · records at 77ce761 · schema 1.8.0.

Format not recorded

No format contract is recorded for this family in the pinned release.

Not recorded

Benchmark dossier notes

From the provider dossier, as written. The evidence level above says how well the format is backed; a fact the dossier does not record is not shown.
Shape
sgp_ + an optional instance identifier (local, 16 hex issued, or any alphanumeric run per the 2025-11 validator) + _ + exactly 40 hex (the generator emits lower case; both validators accept either case).
Basis
T1 (provider generator and validator, R1 and R9). READY for sgp_. The benchmark contract and seeded corpus are authored (#583, slice c): positives in the #860 contexts and the provider-native contexts (Authorization: token, MCP env block, src login, CI env), one-property twins (body length, alphabet, separator, prefix case, boundary) and benign, public-id, placeholder and reference controls. Unclaimed (T0, no assertion): an identifier over 32 bytes (detector policy cap), sgph_ and sgd_ + 64 hex (Cody Gateway).
Issuance
not attempted; the handoff records no issuance gate.
Contract in core
detector-families.md (the detector is registered on main, redact-secret#1103, unreleased). The benchmark contract is benchmarks/lib/beta8/583c.ts (T1, sourcegraph-token), with the corpus in fixtures/generated/beta8/583c.mjs. Pinned peers (trufflehog sourcegraph, gitleaks sourcegraph-access-token) read a 16-hex or local identifier and a bare 40-hex; lag on an alphanumeric identifier is measured, not assumed.

In this benchmark

Fixture rows on the current run. Counts are for redact-secret in published · redact-secret 0.1.0-beta.14 mode.

No fixtures in this family yet

Nothing in the corpus targets it, so nothing is measured and no coverage is claimed.

Not measured

Looks like it, but isn't

Values the dossier records as resembling this credential without being one.
Collisions
the bare 40-hex legacy token and git SHAs (a git-SHA control sits in the corpus), sgp_ placeholders in src help text; see the handoff's excluded shapes.

Scanner rules for this family

Mapped by hand (reviewed 2026-09-30) from each scanner's pinned rule file, never from what a scanner found on the fixtures.
Peer scanner rules that target this family
ScannerRuleWhat the rule matches
gitleaks · rules 8.30.1sourcegraph-access-tokensgp_ (optionally with a 16-hex or local instance identifier) + 40 hex, or a bare 40 hex
trufflehog · rules 3.97.4sourcegraphsgp_ (optionally with a 16-hex or local instance identifier) + 40 hex, or a bare 40 hex

No rule maps to this family in flare-redact, openredaction.

0 of 0 rows

No fixtures in this family yet

Nothing in the corpus targets it, so nothing is measured and no coverage is claimed.

Not measured

Sources

Researched 2026-09-30.

Documentation and code

  • github.com/redact-secret/redact-secret/blob/3b1a5aa9935c57416a026a44f45501fd41ffeac8/docs/audits/evidence/1014/sourcegraph.md
  • github.com/sourcegraph/sourcegraph-public-snapshot/blob/c864f15af264f0f456a6d8a83290b5c940715349/internal/accesstoken/personal_access_token.go#L13-L48

Research log